Merged timeline of 219 items — blog publish times and listing timestamps, cut at midnight . Page 2 of 5.
### offensive-xss - - **Skill Name**: xss - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-waf-bypass - - **Skill Name**: waf-bypass - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-ssti - Dense description covering Server-Side Template Injection across Jinja2, Twig, Freemarker, Velocity, Pebble, Smarty, Mako, Handlebars, ERB, - Practical, repeatable guidance for authorized security w…
### offensive-ssrf - - **Skill Name**: ssrf - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-sqli - SQL injection testing skill for offensive security assessments and bug bounty hunting. Covers error-based, UNION-based, boolean/time-based b - Practical, repeatable guidance for authorized security…
### offensive-request-smuggling - - **Skill Name**: request-smuggling - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-rce - - **Skill Name**: rce - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-race-condition - - **Skill Name**: race-condition - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-parameter-pollution - - **Skill Name**: parameter-pollution - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-file-upload - - **Skill Name**: file-upload - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-idor - - **Skill Name**: idor - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-graphql - Offensive methodology for attacking GraphQL APIs during penetration tests and bug bounty engagements. Covers the full attack lifecycle: endp - Practical, repeatable guidance for authorized securi…
### offensive-open-redirect - - **Skill Name**: open-redirect - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-deserialization - Insecure deserialization exploitation across Java, PHP, .NET, Python, Node.js, and Ruby. Covers gadget chain construction with ysoserial/php - Practical, repeatable guidance for authorize…
### offensive-business-logic - Business logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations, multi-step process ab - Practical, repeatable guidance for authorized…
### offensive-reporting - Penetration test and red team report writing methodology. Covers executive summary structuring (risk-led narrative for non-technical readers - Practical, repeatable guidance for authorized secu…
### offensive-fast-checking - - **Skill Name**: fast-checking - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-supply-chain - Comprehensive offensive methodology for software supply chain attacks covering the full kill chain from reconnaissance through exploitation. - Practical, repeatable guidance for authorized s…
### offensive-dependency-confusion - Deep-dive offensive methodology for dependency confusion and namespace attacks across all major package ecosystems. Covers npm scope confusi - Practical, repeatable guidance for auth…
### offensive-social-engineering - Social engineering attack techniques beyond email phishing for authorized red team and physical penetration testing engagements. Covers pret - Practical, repeatable guidance for author…
### offensive-phishing - Phishing campaign execution methodology for authorized red team engagements. Covers end-to-end campaign lifecycle: infrastructure provisioni - Practical, repeatable guidance for authorized secur…
### offensive-osint - Comprehensive OSINT methodology skill for offensive security, red team intelligence gathering, and bug bounty reconnaissance. Covers domain - Practical, repeatable guidance for authorized security…
### offensive-osint-methodology - - **Skill Name**: osint-methodology - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-windows-privesc - Comprehensive Windows privilege escalation methodology for offensive security engagements. Covers the full attack surface from a standard us - Practical, repeatable guidance for authorize…
### offensive-linux-privesc - Comprehensive Linux privilege escalation methodology for offensive security engagements. Covers the full attack surface from a low-privilege - Practical, repeatable guidance for authorized…
### offensive-persistence - Comprehensive persistence tradecraft for authorized red team engagements covering Windows and Linux mechanisms. Windows techniques include r - Practical, repeatable guidance for authorized se…
### offensive-data-exfiltration - Dense methodology covering DNS exfiltration (dnscat2, iodine, dns2tcp), HTTPS tunneling (domain fronting, CDN abuse, legitimate service chan - Practical, repeatable guidance for authori…
### offensive-lateral-movement - Comprehensive lateral movement tradecraft for authorized red team engagements covering credential-based movement (pass-the-hash, pass-the-ti - Practical, repeatable guidance for authoriz…
### offensive-network-attacks - Dense description covering ARP spoofing, LLMNR/NBT-NS/mDNS poisoning, DNS poisoning, MITM attacks, VLAN hopping, DHCP attacks, 802.1X/NAC by - Practical, repeatable guidance for authorize…
### offensive-mobile - Mobile (Android + iOS) application penetration testing methodology. Covers static analysis (apktool/jadx for Android, class-dump/Hopper/IDA - Practical, repeatable guidance for authorized security…
### offensive-iot - IoT and embedded device security testing methodology. Covers hardware reconnaissance (UART, JTAG, SWD, SPI flash, I2C EEPROM, eMMC chip-off) - Practical, repeatable guidance for authorized security w…
### offensive-windows-mitigations - - **Skill Name**: windows-mitigations - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-windows-boundaries - - **Skill Name**: windows-boundaries - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-shellcode - Shellcode development reference for offensive security engagements. Use when writing custom x86/x64 shellcode, implementing position-indepen - Practical, repeatable guidance for authorized secu…
### offensive-keylogger-arch - - **Skill Name**: keylogger-architecture - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-initial-access - - **Skill Name**: initial-access - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-edr-evasion - - **Skill Name**: edr-evasion - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-advanced-redteam - Comprehensive red team operations methodology covering full engagement lifecycle from planning through reporting. Addresses engagement scopi - Practical, repeatable guidance for authoriz…
### offensive-vuln-classes - - **Skill Name**: vulnerability-classes - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-fuzzing - Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), - Practical, repeatable guidance for authorized securit…
### offensive-fuzzing-course - - **Skill Name**: fuzzing-course - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-bug-identification - - **Skill Name**: bug-identification - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-c2-frameworks - Command and Control framework deployment, configuration, and operational tradecraft for red team engagements. Covers Cobalt Strike (malleabl - Practical, repeatable guidance for authorized…
### offensive-anti-forensics - Anti-forensics and evidence destruction techniques for red team operators conducting authorized engagements. Covers log clearing on Windows - Practical, repeatable guidance for authorized…
### offensive-toctou - Time-of-Check / Time-of-Use (TOCTOU) race condition exploitation methodology across binary, kernel, filesystem, web, and container layers. C - Practical, repeatable guidance for authorized securit…
### offensive-mitigations - - **Skill Name**: security-mitigations - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-exploit-development - - **Skill Name**: exploit-development - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-exploit-dev-course - - **Skill Name**: exploit-dev-curriculum - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-crash-analysis - - **Skill Name**: crash-analysis - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
### offensive-basic-exploitation - - **Skill Name**: basic-exploitation - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.