claudemods

来源snailsploit/claude-red

snailsploit/claude-red 不完整

claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.

查看上游仓库

不完整 队列状态为部分处理,或最近保存的扫描被截断或不完整,或有未完成的续扫记录。已收录的内容可能缺失。

仓库

规范名称
SnailSploit/Claude-Red
GitHub 仓库 ID
1172273835
包记录
79 (历史登记记录,不代表现在仍可用)

发现与队列

首个记录来源
search:topic:claude-skills fork:false
发现于
队列状态
ok
记录的错误次数
0
最近完成的处理
下次检查资格
起具备资格

首个记录来源是队列第一次保存的来源,不是完整的发现历史。错误次数在处理以错误状态结束时增加,成功处理后清零,不是全部尝试次数。「最近完成的处理」是结束时间,不是开始时间。

资格按 计算。它不是排期:采集器每次运行只处理有限数量的来源,具备资格也不保证何时检查。

最近保存的扫描

仓库元数据读取于
扫描状态
truncated
扫描保存于
识别器版本
2
续扫记录
没有

扫描记录与队列状态分开:队列状态说明处理进度,扫描记录说明最近一次保存了什么。有续扫记录只表示存有未完成的状态,没有剩余数量。

源文件证据覆盖

已存储的包版本在这个仓库中引用的固定源文件的原始计数。它反映已记录了什么,不代表仓库有多完整。

范围与限制

统计所有已存储版本(来自任何包)中指向本仓库规范名称的不同固定文件链接(仓库、提交、路径)。本仓库所拥有的包的文件,只有被某个版本在这里链接时才会计入。不合并别名,也不会根据当前名称推测历史。

「已知」表示已记录普通文件身份,不表示整个目录或包已被覆盖。不是有效固定文件 URL 的链接不计入。

引用了 79 个固定源文件

  • 79 已知
  • 0 提交中不存在
  • 0 文件列表截断
  • 0 不受支持
  • 0 尚无记录
  • 0 读取失败

按仓库、提交和路径去重;同一路径出现在两个提交中,按两个文件身份计数。不是组件组数。

读取失败的提交 0

尚无记录的文件没有对应的提交读取失败记录。

关联的包 79

按仓库的已验证身份关联。数量是历史登记记录,不是当前可用性。

第 1–20 条,共 79 条结果

  • offensive-active-directory技能

    Active Directory attack methodology for internal network red team engagements. Covers reconnaissance (BloodHound, PowerView, ADExplorer), credential abuse (Kerberoasting, ASREProasting, NTLM relay, LLMNR/NBT-NS poisoning), privilege escala…

  • offensive-advanced-redteam技能

    Comprehensive red team operations methodology covering full engagement lifecycle from planning through reporting. Addresses engagement scoping and rules of engagement negotiation, multi-tier C2 infrastructure design with redirectors and do…

  • offensive-ai-security技能

    上游没有提供描述

  • offensive-anti-forensics技能

    Anti-forensics and evidence destruction techniques for red team operators conducting authorized engagements. Covers log clearing on Windows (wevtutil, Clear-EventLog, ETW provider patching) and Linux (journal truncation, utmp/wtmp binary e…

  • offensive-api-abuse技能

    Advanced API exploitation methodology focused on business logic abuse and sophisticated attack patterns that bypass traditional security controls. Covers business logic bypass through API call chaining and workflow manipulation. Addresses …

  • offensive-api-security技能

    Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. Addresses the full OWASP API Security Top 10 2023 including BOLA/IDOR, broken authentication, excessive data exposure, rate limiting bypass,…

  • offensive-basic-exploitation技能

    上游没有提供描述

  • offensive-bluetooth-ble技能

    Bluetooth Low Energy (BLE) attack methodology — GATT enumeration, characteristic read/write without auth, pairing downgrade (Just Works forced), LE Secure Connections bypass, MITM via active relay, sniffing with Sniffle (TI CC1352) / Ubert…

  • offensive-bluetooth-classic技能

    Bluetooth Classic (BR/EDR) attack methodology — device discovery, service enumeration via SDP, LMP/L2CAP layer attacks, legacy PIN cracking (BlueBorne / KNOB), Bluetooth file-transfer abuse (BlueSnarfing legacy), unauthenticated profile ab…

  • offensive-bug-identification技能

    上游没有提供描述

  • offensive-business-logic技能

    Business logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations, multi-step process abuse, price/quantity/discount manipulation, currency confusion, coupon stacking, refund/chargeback a…

  • offensive-c2-frameworks技能

    Command and Control framework deployment, configuration, and operational tradecraft for red team engagements. Covers Cobalt Strike (malleable C2 profiles, Beacon types HTTP/HTTPS/DNS/SMB, Beacon Object Files for in-memory execution, sleep …

  • offensive-cicd-pipeline技能

    Comprehensive CI/CD pipeline exploitation methodology covering GitHub Actions injection vectors (expression injection via PR titles and issue bodies, workflow_run event abuse, GITHUB_TOKEN over-scoping, composite action supply chain compro…

  • offensive-cicd-secrets技能

    Comprehensive secrets extraction methodology targeting CI/CD environments across all major platforms. Covers environment variable extraction from build contexts, exploitation of vault and secrets-manager misconfigurations (HashiCorp Vault,…

  • offensive-cloud技能

    Cloud security attack methodology covering AWS, Azure, and GCP. Includes credential harvesting (IMDS, ~/.aws, env vars, leaked CI secrets, instance roles), enumeration with cloud-specific tools (pacu, ScoutSuite, Prowler, ROADtools, gcp_en…

  • offensive-container-escape技能

    Container escape and breakout techniques targeting Docker, containerd, and Podman runtimes. Covers privileged container breakout via host filesystem mount and nsenter, Docker socket abuse through /var/run/docker.sock, Linux capability expl…

  • offensive-crash-analysis技能

    上游没有提供描述

  • offensive-crypto-attacks技能

    Systematic methodology for identifying and exploiting cryptographic implementation weaknesses in real-world applications. Covers padding oracle attacks against CBC-mode ciphers with PKCS7 padding (Vaudenay's original attack through modern …

  • offensive-data-exfiltration技能

    Dense methodology covering DNS exfiltration (dnscat2, iodine, dns2tcp), HTTPS tunneling (domain fronting, CDN abuse, legitimate service channels), ICMP tunneling (icmpsh, ptunnel-ng), cloud storage dead drops (S3 presigned URLs, Azure Blob…

  • offensive-deauth-disassoc技能

    Deauthentication and disassociation attacks against 802.11 networks — targeted single-client deauth for handshake capture, broadcast deauth for DoS (with authorization), action-frame attacks bypassing 802.11w (PMF), beacon flooding, mdk4 /…

已保存的扫描说明 1

  • 4 packages with incomplete coverage

记录的别名 0

这些名称在上次记录时指向这个仓库。这是记录下来的解析结果,不是实时的 GitHub 检查;本站不会因此合并包或元数据。

没有记录到指向这个仓库的别名。

不支持的市场条目 0

这个仓库的市场清单里、本站暂不支持的条目。它们是原样保存的来源数据,不会被抓取或执行。

没有记录到不支持的条目。