transilienceai/communitytools

infrastructure

Network infrastructure testing - port scanning, DNS attacks, MITM, VLAN hopping, IPv6, SMB/NetBIOS, sniffing, and DoS assessment.

Zobacz źródło
Oryginalny dokument Skill

Treść z repozytorium z zachowaniem nagłówków, przykładów, kodu, tabel, linków i obrazów.

Infrastructure

Test network infrastructure for vulnerabilities including network services, protocols, and perimeter security.

Techniques

TypeKey Vectors
Port ScanningSYN scan, UDP scan, service detection, OS fingerprinting
DNSZone transfers, cache poisoning, subdomain takeover, DNS rebinding
MITMARP spoofing, DNS spoofing, SSL stripping, LLMNR/NBT-NS poisoning
VLAN HoppingSwitch spoofing, double tagging
IPv6RA flooding, neighbor spoofing, tunneling attacks
SMB/NetBIOSNull sessions, relay attacks, enumeration
SniffingPacket capture, credential harvesting, protocol analysis
DoSResource exhaustion, amplification, application-layer
ICS/SCADAModbus TCP, PLC exploitation, coil/register manipulation, session hijacking
Space / CCSDSSatellite telecommand framing (Space Packet + TC Transfer Frame), APID/SCID/VCID routing, VCFC sequencing, CRC-16/CCITT, ASCII 0x%02x: command counters
UPnP / IoT / CPErootDesc/SCPD enumeration, vendor SOAP info disclosure (GetPassword), command injection via vendor actions, cross-action auth-key reuse
Hardware / EmbeddedLogic captures (Saleae .sal), CAN/UART decoding, side-channel password recovery, legacy CPU errata, i386 tools via docker

Workflow

  1. Network discovery and topology mapping
  2. Port scanning and service enumeration
  3. Protocol-specific vulnerability testing
  4. Network attack execution (authorized scope only)
  5. Evidence capture with packet captures and logs

Reference

Quickstart guides (per attack type):

  • reference/port-scanning-quickstart.md - Port scanning and service discovery
  • reference/dns-quickstart.md - DNS attacks and enumeration
  • reference/mitm-quickstart.md - Man-in-the-middle attacks
  • reference/vlan-hopping-quickstart.md - VLAN hopping techniques
  • reference/ipv6-quickstart.md - IPv6 attack vectors
  • reference/smb-netbios-quickstart.md - SMB/NetBIOS exploitation
  • reference/sniffing-quickstart.md - Network sniffing and capture
  • reference/dos-quickstart.md - DoS assessment
  • reference/ics-modbus-quickstart.md - ICS/SCADA Modbus PLC exploitation
  • reference/ccsds-space-telecommand-quickstart.md - Satellite CCSDS telecommand frame crafting (Space Packet + TC Transfer Frame)
  • reference/upnp-iot-quickstart.md - UPnP / IoT / CPE firmware web UI enumeration and exploitation
  • reference/hardware-embedded-quickstart.md - Logic captures, CAN/UART decoding, side-channel char-by-char recovery, legacy CPU bugs (6502), i386 tooling on ARM macOS

Scan techniques: reference/syn-scan.md, reference/udp-scan.md, reference/icmp-scan.md, reference/os-fingerprint.md Other: reference/firewall-detection.md, reference/service-enum.md, reference/ip-reputation.md, reference/overview.md

z tego samego repozytorium

Więcej Skills

Wszystkie Skills
transilienceai
Społeczność

attack-path-stitcher

Stitches confirmed single-asset findings into multi-hop attack paths across the organization. Builds a graph where nodes are assets and edges are confirmed exploit hops citing the findings that enable them.

instalacje
5
GitHub Stars
534
Aktualizacja
29 lip
transilienceai
Społeczność

authenticated-session-acquisition

Acquire an authenticated session THROUGH MFA/OTP on an in-scope target and emit a reusable session artifact (Playwright storageState + Bearer) so executors can test the post-auth attack surface. Use when the highest-value authenticated classes (BOLA/IDOR/mass-assignment/injection on the real data APIs) are blocked because login is gated by SMS-OTP or TOTP MFA. Distinct from the authentication skill (which ATTACKS auth); this one legitimately authenticates and hands the session to the rest of the engagement.

instalacje
1
GitHub Stars
534
Aktualizacja
29 lip
transilienceai
Społeczność

blockchain-security

Smart contract security testing and blockchain CTF exploitation. Covers Solidity vulnerability analysis, EVM storage manipulation, delegatecall attacks, CREATE/CREATE2 address prediction, and common DeFi exploit patterns. Use when analyzing Solidity contracts, solving blockchain challenges, or testing smart contract security.

instalacje
1
GitHub Stars
534
Aktualizacja
29 lip
transilienceai
Społeczność

client-side

Client-side vulnerability testing - XSS (reflected/stored/DOM), CSRF, CORS misconfiguration, Clickjacking, DOM-based attacks, and Prototype Pollution.

instalacje
1
GitHub Stars
534
Aktualizacja
29 lip