exploit-development--payload-engineering
FeaturedProof-of-concept development, payload crafting, shellcode analysis, and exploitation technique research for authorized security testing
Install
Quality Score: 95/100
Skill Content
Details
- Author
- Masriyan
- Repository
- Masriyan/Claude-Code-CyberSecurity-Skill
- Created
- 6 months ago
- Last Updated
- 3 days ago
- Language
- Python
- License
- MIT
Bundled in these plugins
Similar Skills
Semantically similar based on skill content — not just same category
linmas-exploit-validation-specialist
Exploit validation skill for authorized environments, attack-surface review, and bounded proof-of-impact workflows.
exploit-poc-development
Turn a known/1-day vulnerability or a raw bug into a working, reliable PoC for an authorized target. Load when a CVE/advisory needs weaponizing, a public PoC needs adapting, or "write an exploit/PoC". Signals: a versioned service with a known CVE, a crash/primitive to develop, searchsploit hits.
burp-pentest
Elite methodology for authenticated web application penetration testing and bug bounty hunting using Burp Suite via MCP. Triggers on any mention of pentest, bug bounty, web vulnerability hunting, Burp, authorization/IDOR/BOLA/BFLA testing, injection (SQLi/NoSQLi/SSTI/cmd/LDAP/XPath/XSLT/CSV-formula/LaTeX), authentication/MFA/SSO flaws, OAuth/OIDC abuse, SAML attacks (XSW signature wrapping / comment injection / audience confusion), JWT attacks, SSRF, business logic flaws, race conditions, HTTP request smuggling, HTTP header injection (User-Agent SQLi, Referer abuse, Host header injection, log4shell, CRLF, HPP), insecure deserialization (Java ysoserial / .NET ViewState / PHP unserialize / Python pickle / Ruby Marshal / Node serialize), JavaScript source/sink analysis, Spring Boot Actuator abuse (heapdump, env, jolokia, gateway), JBoss/WebLogic/WebSphere/Tomcat exploitation, Struts CVE chain, Spring4Shell, H2 console RCE, cloud post-exploitation (AWS IAM / Azure managed identity / GCP service accounts / K8s pod