Database
Browse 6,168 skills across 448 packs and 38 categories
defense-evasion-testing
44LTesting detection coverage through AMSI bypass, process injection, and living-off-the-land techniques for detection validation
initial-access
44LInitial access techniques for authorized penetration tests including phishing, exposed services, and credential attacks
lateral-movement-techniques
44LLateral movement techniques for authorized assessments including pass-the-hash, WMI, PSExec, and RDP pivoting
payload-development
45LCustom payload development for authorized assessments including AV/EDR testing and C2 framework usage
persistence-analysis
45LPersistence mechanism testing for authorized assessments covering scheduled tasks, registry keys, services, and DLL side-loading
privilege-escalation-techniques
45LWindows and Linux privilege escalation techniques for authorized penetration testing including kernel exploits, misconfigurations, and token abuse
ad-attack-paths
45LActive Directory attack path analysis using BloodHound, Certify, and Rubeus for authorized security assessments
attack-infrastructure
44LAttack infrastructure setup including redirectors, domain fronting assessment, and phishing infrastructure for authorized engagements
c2-framework
44LCommand and control framework setup and operation for authorized penetration tests with OPSEC considerations
cloud-exploitation
44LCloud exploitation techniques for authorized assessments covering metadata abuse, SSRF to cloud, and IAM role assumption
debrief-retesting
46LClient debrief methodology, remediation validation, retest procedures, and knowledge transfer for penetration testing engagements
report-writing
45LProfessional penetration test report writing covering executive summary, technical findings, risk ratings, and remediation guidance
engagement-planning
47LRules of engagement definition, scope documentation, authorization validation, and legal compliance for penetration testing
external-pentest
45LExternal network penetration testing methodology aligned with PTES for authorized security assessments
internal-pentest
44LInternal network penetration testing and assumed breach methodology for authorized security assessments
physical-pentest
44LPhysical penetration testing methodology including access control bypass, tailgating assessment, and social engineering for authorized engagements
purple-team
44LPurple team exercise methodology for cooperative adversary simulation and detection validation in authorized engagements
red-team-operations
44LRed team engagement methodology covering objective-based adversary simulation and stealth assessment for authorized operations
web-app-pentest
46LWeb application penetration testing aligned with the OWASP Testing Guide for authorized security assessments
wireless-pentest
44LWireless network penetration testing covering WPA/WPA2/WPA3 assessment and rogue access point detection for authorized engagements
asn-ip-mapping
101LASN/IP range awareness, WHOIS lookups, and BGP route analysis for authorized security assessments
asset-discovery
98LAsset discovery, DNS enumeration, and subdomain mapping for authorized security assessments
attack-surface-mapping
128LExternal attack surface mapping, forgotten asset detection, and domain drift analysis for authorized assessments
certificate-analysis
130LCertificate transparency analysis, SSL/TLS review, and cert chain validation for authorized assessments
osint-gathering
118LOpen source intelligence collection, data leak checks, and metadata extraction for authorized assessments
service-inventory
113LService inventory and technology fingerprinting for authorized security assessments
compliance-mapping
171LCompliance framework alignment including CIS, NIST, ISO 27001, SOC 2, PCI DSS, and HIPAA
executive-summary
181LExecutive summary writing and non-technical security communication
findings-documentation
176LClear vulnerability findings documentation with reproducible steps and evidence handling
remediation-mapping
197LRemediation mapping, fix prioritization, and timeline estimation
severity-scoring
185LCVSS scoring, risk rating methodology, and business impact assessment
change-safety
179LChange safety guardrails for security testing, do-not-touch asset protection, and rollback planning
legal-authorization
169LLegal authorization verification, rules of engagement compliance, and regulatory awareness for security testing
proof-only-mode
152LNon-destructive vulnerability validation, proof-of-concept without exploitation, and safe evidence collection
rate-limiting-safety
152LSafe testing rate limits, resource-aware scanning, and production disruption avoidance
scope-enforcement
148LScope enforcement for penetration testing, authorized target validation, and boundary compliance
awareness-gaps
192LSecurity awareness gap assessment, training effectiveness measurement, and human risk quantification
helpdesk-abuse
190LHelpdesk abuse path identification, pretexting scenarios, and identity verification bypass testing
phishing-simulation
175LPhishing simulation campaign planning, pretext development, payload design, and metrics collection
physical-security
210LPhysical security assessment, tailgating testing, badge cloning awareness, and facility access review
process-weakness
184LBusiness process weakness identification, verification flow testing, and social engineering attack path analysis
awareness-program-design
56LBuild and measure security awareness programs with baseline assessments, simulated attacks, and behavior change metrics
mfa-bypass-testing
54LTest MFA resilience through authorized adversary-in-the-middle, push fatigue, and recovery code exposure assessments
phishing-campaign-design
57LDesign and execute authorized phishing simulation campaigns with GoPhish and King Phisher
physical-social-engineering
56LConduct authorized physical social engineering assessments including tailgating, impersonation, and USB drops
pretexting
55LDevelop and deploy pretexts for authorized social engineering engagements using structured methodology
smishing
55LDesign and execute authorized SMS phishing simulations with proper consent and opt-out controls
social-engineering-reporting
56LReport social engineering assessment findings with metrics, human factor analysis, and executive-ready remediation plans
spear-phishing
54LExecute targeted spear-phishing simulations for authorized red team engagements with OSINT-driven pretexts
vishing
54LConduct authorized voice phishing assessments against helpdesks and personnel targets
watering-hole-assessment
54LSimulate watering hole attacks in controlled environments to test browser security and web filtering controls
adversary-emulation
46LMap adversary behaviors to ATT&CK, emulate tactics, and validate detection coverage
ioc-management
46LIOC collection, enrichment, scoring, lifecycle management, and sharing via STIX/TAXII
malware-triage
47LStatic and behavioral malware triage, config extraction, family clustering, and sandbox analysis
threat-actor-tracking
48LTrack threat actors, campaigns, infrastructure patterns, and targeting trends
threat-landscape
46LThreat landscape analysis, trend reporting, and strategic risk forecasting
access-control
140LAuthorization testing, privilege escalation, and IDOR detection for authorized security assessments
api-security-testing
162LAPI auth flows, rate limiting, schema validation, and GraphQL security testing for authorized assessments
auth-testing
144LAuthentication review, credential handling, and session management testing for authorized assessments
business-logic
165LBusiness logic flaw detection, race conditions, and workflow bypass testing for authorized assessments