mirror of
https://github.com/Ed1s0nZ/CyberStrikeAI.git
synced 2026-08-01 16:38:48 +02:00
Add files via upload
This commit is contained in:
@@ -2,7 +2,8 @@
|
||||
name: active-directory-attack
|
||||
description: >-
|
||||
内网域攻击:BloodHound,Kerberoast,ADCS ESC1/ESC8,NTLM Relay,Coerce,DACL,DCSync,Zerologon/NoPac/PrintNightmare,mitm6,LLMNR,Linux内网。Use when attacking Active Directory, ADCS, NTLM relay, or internal domain.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## 内网域攻击
|
||||
|
||||
@@ -2,7 +2,8 @@
|
||||
name: ai-llm-app-attack
|
||||
description: >-
|
||||
AI/LLM应用攻击:提示注入,Agent工具滥用RCE,RAG投毒,MCP供应链,torch.load pickle RCE。Use when testing LLM apps, agents, RAG, MCP plugins, or AI model file risks.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## AI / LLM 应用攻击
|
||||
|
||||
@@ -2,7 +2,8 @@
|
||||
name: attack-surface-recon
|
||||
description: >-
|
||||
侦察/攻击面测绘:被动whois/amass/crt.sh/FOFA/Shodan,主动subfinder/httpx/naabu/katana/nuclei,DNS地域/CDN/Nginx catch-all/宝塔/UniApp指纹。开局第一动作,认知写入项目黑板。Use when starting recon, asset mapping, fingerprinting, or CDN/DNS bypass discovery.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## 侦察 / 攻击面测绘
|
||||
|
||||
@@ -2,7 +2,8 @@
|
||||
name: binary-mobile-reversing
|
||||
description: >-
|
||||
APK/EXE/二进制:UniApp/DCloud/Flutter逆向,证书固定绕过,导出组件,内存破坏exploit链,IoT固件。Use when reversing APK/EXE, UniApp/Flutter, native .so, or memory-corruption exploits.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## APK / EXE / 二进制逆向
|
||||
|
||||
@@ -2,7 +2,8 @@
|
||||
name: blockchain-contract-attack
|
||||
description: >-
|
||||
区块链/智能合约:Etherscan,slither/mythril,重入/访问控制/预言机/闪电贷,跨链桥,RPC暴露。Use when auditing smart contracts, DeFi, or blockchain attack surfaces.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## 区块链 / 智能合约
|
||||
|
||||
@@ -2,7 +2,8 @@
|
||||
name: capability-primitive-search
|
||||
description: >-
|
||||
能力原语+状态空间搜索:read/write/exec/ssrf等原语凑RCE等式A-F,低危映射,正反向搜索,跨域兑现。Use when no single RCE, chaining low-severity vulns, or deriving novel attack chains.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## 能力原语 + 状态空间搜索
|
||||
|
||||
@@ -2,7 +2,8 @@
|
||||
name: cloud-attack-methods
|
||||
description: >-
|
||||
云攻击:元数据API,S3/K8s,AWS/Azure/GCP身份提权,MinIO矩阵,阿里云FC,ChengZi SDK解密。Use when attacking cloud metadata, IAM, K8s, MinIO, Aliyun FC, or cloud post-ex.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## 云攻击手法
|
||||
|
||||
@@ -2,7 +2,8 @@
|
||||
name: component-vuln-intel
|
||||
description: >-
|
||||
联网情报收集:识别组件后必做CVE/搜索引擎/中文社区/GitHub PoC/资产引擎/即时情报/依赖扩展+受阻换路。Use when a framework/component/version is identified and must search before exploit.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## 联网情报收集(识别组件→立即全网搜;结果=线索/tentative,验证前不是 confirmed Fact)
|
||||
|
||||
@@ -2,7 +2,8 @@
|
||||
name: initial-access-phishing
|
||||
description: >-
|
||||
初始访问/钓鱼/社工:凭据喷洒,AiTM,设备码,OAuth同意钓鱼,载荷,vishing。Use when needing initial access, phishing, AiTM, device code, or social engineering.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## 初始访问 / 钓鱼 / 社工
|
||||
|
||||
@@ -6,7 +6,8 @@ description: >-
|
||||
(联网情报/Web/认证/服务端/源码/社工/后渗透/二进制/内网域/云/区块链/AI/无线/硬件)+0day+
|
||||
组合拳+代理自举。核心:全网搜不到洞时现场推导独属于目标的攻击链。本文件为套件索引。
|
||||
Use when starting a full-chain pentest engagement or needing the skill map for this suite.
|
||||
tags: [渗透测试, penetration-testing, 红队, autonomous]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队, autonomous]
|
||||
---
|
||||
|
||||
# 渗透测试Agent操作系统
|
||||
|
||||
@@ -4,7 +4,8 @@ description: >-
|
||||
CyberStrikeAI 项目黑板:跨会话 Fact 图(SQLite)+ upsert_project_fact/record_vulnerability
|
||||
边渗透边记录节奏、关系边 links、confidence、与多代理协调落库。Use when managing project
|
||||
facts, blackboard index, writing evidence, or avoiding context-loss after compression.
|
||||
tags: [渗透测试, penetration-testing, 红队, 项目黑板]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队, 项目黑板]
|
||||
---
|
||||
|
||||
# 项目黑板(与本产品对齐)
|
||||
|
||||
@@ -3,7 +3,8 @@ name: pentest-output-standards
|
||||
description: >-
|
||||
输出规范:中文分析,思维链,漏洞报告模板,负结果,黑板状态总览,改动台账,死锁突破。
|
||||
Use when reporting findings, maintaining change ledger, or formatting pentest output.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## 输出规范
|
||||
|
||||
@@ -3,7 +3,8 @@ name: pentest-verification
|
||||
description: >-
|
||||
验证铁律:搜索≠漏洞,confirmed Fact须证据,tentative表线索,禁止空泛推测,负结果也落库,
|
||||
想象力拉满+单步验证零容忍。Use when writing project facts, validating findings, or avoiding hallucination.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## 验证铁律(全系统最高规则,违反即幻觉)
|
||||
|
||||
@@ -2,7 +2,8 @@
|
||||
name: post-exploitation
|
||||
description: >-
|
||||
后渗透/提权+凭据破解+密码学:反弹shell,Linux/Windows提权,横向,隧道,免杀,C2持久化,hashcat/Padding Oracle/hash长度扩展。Use when post-exploitation, privilege escalation, lateral movement, or cracking crypto.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## 后渗透 / 提权 / 凭据破解 / 密码学
|
||||
|
||||
@@ -2,7 +2,8 @@
|
||||
name: proxy-tool-bootstrap
|
||||
description: >-
|
||||
自找代理+工具自举:SOCKS5/HTTP/Tor换路序列,工具Python自举,字典自生成,OOB基础设施。Use when blocked by 403/429/WAF/timeout, missing tools, or needing OOB confirmation.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## 自找代理 + 工具自举(被拦换路,没工具自己写)
|
||||
|
||||
@@ -2,7 +2,8 @@
|
||||
name: redteam-opsec
|
||||
description: >-
|
||||
OPSEC隐蔽作战纪律:IP黑名单绕过,速率时序,流量混淆,最小足迹,反取证,渐进暴露。Use when maintaining stealth, bypassing IP bans, or planning covert red-team ops.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## OPSEC / 隐蔽作战纪律(免杀 / 稳定 / 隐蔽)
|
||||
|
||||
@@ -2,7 +2,8 @@
|
||||
name: source-code-hunting
|
||||
description: >-
|
||||
源码狩猎:.git泄露,危险函数grep,JS RC4解混淆,semgrep/CodeQL,trufflehog,patch diff,供应链/CI。Use when hunting source leaks, secrets, JS deobfuscation, or supply-chain issues.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## 源码狩猎
|
||||
|
||||
@@ -2,7 +2,8 @@
|
||||
name: specialized-attack-playbooks
|
||||
description: >-
|
||||
专题实战利用:GoEdge私钥导出,灰产CDN取证,ARP MITM,CDN→S3 STS链,宝塔+UniApp,AI IDE API反代,OCS+MinIO;含references/scripts支持文件索引。Use when applying specialized playbooks for GoEdge, CDN, ARP MITM, BT Panel, OCS, MinIO.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## 专题实战利用(全内联)
|
||||
|
||||
@@ -2,7 +2,8 @@
|
||||
name: unlimited-attack-scope
|
||||
description: >-
|
||||
不设限原则:搜索/验证/串联/记录一切,全领域适用,被拦换路,不达不休。Use when reminding scope is unlimited across Web/APK/cloud/AI/wireless/social eng.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## 不设限原则
|
||||
|
||||
@@ -2,7 +2,8 @@
|
||||
name: web-attack-methods
|
||||
description: >-
|
||||
Web全栈攻击:SQLi/命令注入/SSTI/XSS/SSRF/NoSQL,认证JWT/OAuth/SAML,LFI/上传,Tomcat/WS/STOMP/XFF/PATH_INFO/CDN502/网宿JS挑战绕过。Use when testing Web injection, auth bypass, server-side, WAF/CDN bypass.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## Web 攻击手法(注入 / 认证 / 服务端 / 杂项 / CDN)
|
||||
|
||||
@@ -2,7 +2,8 @@
|
||||
name: wireless-hardware-attack
|
||||
description: >-
|
||||
无线/硬件:WiFi PMKID/WPS/Evil Twin,BLE,Zigbee,NFC,SDR,UART/JTAG/SPI,侧信道,故障注入。Use when attacking WiFi, BLE, RFID, SDR, or hardware interfaces.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## 无线 / 硬件攻击
|
||||
|
||||
@@ -2,7 +2,8 @@
|
||||
name: zero-day-discovery
|
||||
description: >-
|
||||
0day自主发现引擎:变体分析/补丁间隙/差分/Fuzzing/污点推理/N-day武器化/猎人思维。Use when public vulns not found and need to discover 0day or weaponize N-day.
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
metadata:
|
||||
tags: [渗透测试, penetration-testing, 红队]
|
||||
---
|
||||
|
||||
## 0day 自主发现引擎(全网搜不到漏洞时自己挖)
|
||||
|
||||
Reference in New Issue
Block a user