Loading...
Loading...
Found 103 Skills
Testing web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit authenticated user sessions during authorized security assessments.
Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.
Testing web applications for clickjacking vulnerabilities by assessing frame embedding controls and crafting proof-of-concept overlay attacks during authorized security assessments.
Use for authorized wireless security assessment including Wi-Fi capture, WPA handshake analysis, rogue AP detection research, and lab-only deauth testing.
Used for authorized security testing of desktop thick clients, covering local storage, update channels, IPC, traffic, and client-side trust boundaries.
Provide comprehensive techniques for testing REST, SOAP, and GraphQL APIs during bug bounty hunting and penetration testing engagements. Covers vulnerability discovery, authentication bypass, IDOR exploitation, and API-specific attack vectors.
Used for authorized multi-stage attack path planning and orchestration when a task covers reconnaissance, initial access, privilege escalation, lateral movement, or impact assessment. Route single-stage tasks directly to the corresponding specialist skill.