Skip to main content

Database

Browse 6,168 skills across 448 packs and 38 categories

Showing 4201–4260 of 6,168 skills
6,168 skills found

defense-evasion-testing

44L

Testing detection coverage through AMSI bypass, process injection, and living-off-the-land techniques for detection validation

Technology & EngineeringPentest Exploitation

initial-access

44L

Initial access techniques for authorized penetration tests including phishing, exposed services, and credential attacks

Technology & EngineeringPentest Exploitation

lateral-movement-techniques

44L

Lateral movement techniques for authorized assessments including pass-the-hash, WMI, PSExec, and RDP pivoting

Technology & EngineeringPentest Exploitation

payload-development

45L

Custom payload development for authorized assessments including AV/EDR testing and C2 framework usage

Technology & EngineeringPentest Exploitation

persistence-analysis

45L

Persistence mechanism testing for authorized assessments covering scheduled tasks, registry keys, services, and DLL side-loading

Technology & EngineeringPentest Exploitation

privilege-escalation-techniques

45L

Windows and Linux privilege escalation techniques for authorized penetration testing including kernel exploits, misconfigurations, and token abuse

Technology & EngineeringPentest Exploitation

ad-attack-paths

45L

Active Directory attack path analysis using BloodHound, Certify, and Rubeus for authorized security assessments

Technology & EngineeringPentest Infrastructure

attack-infrastructure

44L

Attack infrastructure setup including redirectors, domain fronting assessment, and phishing infrastructure for authorized engagements

Technology & EngineeringPentest Infrastructure

c2-framework

44L

Command and control framework setup and operation for authorized penetration tests with OPSEC considerations

Technology & EngineeringPentest Infrastructure

cloud-exploitation

44L

Cloud exploitation techniques for authorized assessments covering metadata abuse, SSRF to cloud, and IAM role assumption

Technology & EngineeringPentest Infrastructure

debrief-retesting

46L

Client debrief methodology, remediation validation, retest procedures, and knowledge transfer for penetration testing engagements

Technology & EngineeringPentest Infrastructure

report-writing

45L

Professional penetration test report writing covering executive summary, technical findings, risk ratings, and remediation guidance

Technology & EngineeringPentest Infrastructure

engagement-planning

47L

Rules of engagement definition, scope documentation, authorization validation, and legal compliance for penetration testing

Technology & EngineeringPentest Methodology

external-pentest

45L

External network penetration testing methodology aligned with PTES for authorized security assessments

Technology & EngineeringPentest Methodology

internal-pentest

44L

Internal network penetration testing and assumed breach methodology for authorized security assessments

Technology & EngineeringPentest Methodology

physical-pentest

44L

Physical penetration testing methodology including access control bypass, tailgating assessment, and social engineering for authorized engagements

Technology & EngineeringPentest Methodology

purple-team

44L

Purple team exercise methodology for cooperative adversary simulation and detection validation in authorized engagements

Technology & EngineeringPentest Methodology

red-team-operations

44L

Red team engagement methodology covering objective-based adversary simulation and stealth assessment for authorized operations

Technology & EngineeringPentest Methodology

web-app-pentest

46L

Web application penetration testing aligned with the OWASP Testing Guide for authorized security assessments

Technology & EngineeringPentest Methodology

wireless-pentest

44L

Wireless network penetration testing covering WPA/WPA2/WPA3 assessment and rogue access point detection for authorized engagements

Technology & EngineeringPentest Methodology

asn-ip-mapping

101L

ASN/IP range awareness, WHOIS lookups, and BGP route analysis for authorized security assessments

Technology & EngineeringRecon Agent

asset-discovery

98L

Asset discovery, DNS enumeration, and subdomain mapping for authorized security assessments

Technology & EngineeringRecon Agent

attack-surface-mapping

128L

External attack surface mapping, forgotten asset detection, and domain drift analysis for authorized assessments

Technology & EngineeringRecon Agent

certificate-analysis

130L

Certificate transparency analysis, SSL/TLS review, and cert chain validation for authorized assessments

Technology & EngineeringRecon Agent

osint-gathering

118L

Open source intelligence collection, data leak checks, and metadata extraction for authorized assessments

Technology & EngineeringRecon Agent

service-inventory

113L

Service inventory and technology fingerprinting for authorized security assessments

Technology & EngineeringRecon Agent

compliance-mapping

171L

Compliance framework alignment including CIS, NIST, ISO 27001, SOC 2, PCI DSS, and HIPAA

Technology & EngineeringReporting Agent

executive-summary

181L

Executive summary writing and non-technical security communication

Technology & EngineeringReporting Agent

findings-documentation

176L

Clear vulnerability findings documentation with reproducible steps and evidence handling

Technology & EngineeringReporting Agent

remediation-mapping

197L

Remediation mapping, fix prioritization, and timeline estimation

Technology & EngineeringReporting Agent

severity-scoring

185L

CVSS scoring, risk rating methodology, and business impact assessment

Technology & EngineeringReporting Agent

change-safety

179L

Change safety guardrails for security testing, do-not-touch asset protection, and rollback planning

Technology & EngineeringSafety Scope Guard

legal-authorization

169L

Legal authorization verification, rules of engagement compliance, and regulatory awareness for security testing

Technology & EngineeringSafety Scope Guard

proof-only-mode

152L

Non-destructive vulnerability validation, proof-of-concept without exploitation, and safe evidence collection

Technology & EngineeringSafety Scope Guard

rate-limiting-safety

152L

Safe testing rate limits, resource-aware scanning, and production disruption avoidance

Technology & EngineeringSafety Scope Guard

scope-enforcement

148L

Scope enforcement for penetration testing, authorized target validation, and boundary compliance

Technology & EngineeringSafety Scope Guard

awareness-gaps

192L

Security awareness gap assessment, training effectiveness measurement, and human risk quantification

Technology & EngineeringSocial Engineering Readiness

helpdesk-abuse

190L

Helpdesk abuse path identification, pretexting scenarios, and identity verification bypass testing

Technology & EngineeringSocial Engineering Readiness

phishing-simulation

175L

Phishing simulation campaign planning, pretext development, payload design, and metrics collection

Technology & EngineeringSocial Engineering Readiness

physical-security

210L

Physical security assessment, tailgating testing, badge cloning awareness, and facility access review

Technology & EngineeringSocial Engineering Readiness

process-weakness

184L

Business process weakness identification, verification flow testing, and social engineering attack path analysis

Technology & EngineeringSocial Engineering Readiness

awareness-program-design

56L

Build and measure security awareness programs with baseline assessments, simulated attacks, and behavior change metrics

Technology & EngineeringSocial Engineering

mfa-bypass-testing

54L

Test MFA resilience through authorized adversary-in-the-middle, push fatigue, and recovery code exposure assessments

Technology & EngineeringSocial Engineering

phishing-campaign-design

57L

Design and execute authorized phishing simulation campaigns with GoPhish and King Phisher

Technology & EngineeringSocial Engineering

physical-social-engineering

56L

Conduct authorized physical social engineering assessments including tailgating, impersonation, and USB drops

Technology & EngineeringSocial Engineering

pretexting

55L

Develop and deploy pretexts for authorized social engineering engagements using structured methodology

Technology & EngineeringSocial Engineering

smishing

55L

Design and execute authorized SMS phishing simulations with proper consent and opt-out controls

Technology & EngineeringSocial Engineering

social-engineering-reporting

56L

Report social engineering assessment findings with metrics, human factor analysis, and executive-ready remediation plans

Technology & EngineeringSocial Engineering

spear-phishing

54L

Execute targeted spear-phishing simulations for authorized red team engagements with OSINT-driven pretexts

Technology & EngineeringSocial Engineering

vishing

54L

Conduct authorized voice phishing assessments against helpdesks and personnel targets

Technology & EngineeringSocial Engineering

watering-hole-assessment

54L

Simulate watering hole attacks in controlled environments to test browser security and web filtering controls

Technology & EngineeringSocial Engineering

adversary-emulation

46L

Map adversary behaviors to ATT&CK, emulate tactics, and validate detection coverage

Technology & EngineeringThreat Intel Agent

ioc-management

46L

IOC collection, enrichment, scoring, lifecycle management, and sharing via STIX/TAXII

Technology & EngineeringThreat Intel Agent

malware-triage

47L

Static and behavioral malware triage, config extraction, family clustering, and sandbox analysis

Technology & EngineeringThreat Intel Agent

threat-actor-tracking

48L

Track threat actors, campaigns, infrastructure patterns, and targeting trends

Technology & EngineeringThreat Intel Agent

threat-landscape

46L

Threat landscape analysis, trend reporting, and strategic risk forecasting

Technology & EngineeringThreat Intel Agent

access-control

140L

Authorization testing, privilege escalation, and IDOR detection for authorized security assessments

Technology & EngineeringWeb Appsec Agent

api-security-testing

162L

API auth flows, rate limiting, schema validation, and GraphQL security testing for authorized assessments

Technology & EngineeringWeb Appsec Agent

auth-testing

144L

Authentication review, credential handling, and session management testing for authorized assessments

Technology & EngineeringWeb Appsec Agent

business-logic

165L

Business logic flaw detection, race conditions, and workflow bypass testing for authorized assessments

Technology & EngineeringWeb Appsec Agent