Enterprise Vpn Attack (Grade B) logo

Enterprise Vpn Attack (Grade B)Security-tested testing-security skill for Claude AI. Grade B. External SSL VPN / remote-access appliance attack matrix — Cisco ASA/AnyConnect, Fortinet FortiGate/FortiOS, Citrix NetScaler/ADC, Palo A

(0)
Daniel NikulshynReviewed by Daniel Nikulshyn·Updated July 2026

Overview

This skill provides an external SSL VPN / remote-access appliance attack matrix for various vendors including Cisco ASA/AnyConnect, Fortinet FortiGate/FortiOS, Citrix NetScaler/ADC, Palo Alto GlobalProtect, Pulse Secure / Ivanti Connect Secure, SonicWall, and F5 Big-IP. It covers version fingerprinting, CVE matrix from 2018-2026, AAA backend identification, default credentials, configuration-disclosure paths, and pre-auth RCE/SSRF/path-traversal exploits where applicable. The skill is built from authorized-engagement Cisco ASA testing and the 2024-2026 enterprise VPN CVE landscape. It is used to identify and potentially exploit vulnerabilities in SSL VPN appliances or remote-access gateways, which are common initial-access points in actor TTPs for 2024-2026.

Key features

  • Version fingerprinting for Cisco ASA/AnyConnect, Fortinet FortiGate/FortiOS, Citrix NetScaler/ADC, Palo Alto GlobalProtect, Pulse Secure / Ivanti Connect Secure
  • CVE matrix from 2018-2026
  • AAA backend identification
  • Default credentials identification
  • Configuration-disclosure paths
  • Pre-auth RCE/SSRF/path-traversal exploits

Pricing

Model
Free
Category
Skills
Rating
No reviews yet

Use cases

Identifying and Exploiting Cisco ASA/AnyConnect Vulnerabilities

Use this skill to identify and potentially exploit vulnerabilities in Cisco ASA/AnyConnect SSL VPN appliances, including version fingerprinting, CVE matrix checking, and pre-auth exploit attempts.

Scanning for Fortinet FortiGate/FortiOS Vulnerabilities

Utilize this skill to scan Fortinet FortiGate/FortiOS SSL VPN appliances for potential vulnerabilities, including version identification and CVE matrix checking.

Pros & Cons

Pros

  • Comprehensive attack matrix for multiple vendors
  • Covers version fingerprinting and CVE matrix from 2018-2026
  • Includes techniques for AAA backend identification and default credentials
  • Provides methods for configuration-disclosure paths and pre-auth exploits

Cons

  • Limited to SSL VPN appliances and remote-access gateways
  • Does not cover internal lateral-movement post-foothold or VPN client-side bugs
  • Excludes IPsec / L2TP / OpenVPN protocols

Reviews

Sign in to leave a review.

No reviews yet. Be the first!

Q&A

What's inside?

The bundle contains 82 auto‑loaded skills covering the external attack surface: Web application hunting (13 skills such as XSS, SQLi, SSRF, IDOR, LFI, SSTI, XXE, CSRF, CORS, open‑redirect), Authentication & identity (7 skills including auth‑bypass, session, OAuth, SAML, MFA‑bypass, ATO), API & infrastructure (15 skills like GraphQL, gRPC, WebSocket, API‑misconfig, host‑header, RCE), Advanced & concurrency (6 skills such as race‑condition, HTTP smuggling, deserialization, cache‑poison), Framework‑specific (4 skills for Next.js, Node.js, Laravel, Spring Boot), Enterprise identity & cloud (3 skills for M365/Entra, Okta, cloud‑IAM), Infrastructure & appliance (4 skills for VMware vCenter, enterprise VPN, SharePoint, ASP.NET/NTLM), Red‑team tradecraft (4 skills), Recon & OSINT (4 skills), Workflow, reporting & specialized (11 skills). It also ships 15 slash commands (/hunt, /recon, /report, …) and a deterministic engagement engine that maps a target’s attack surface and routes each finding to the appropriate skill.

Asked by Youssef El-Sayed · Nov 10, 2025

What is this?

claude-bughunter is a drop-in skill bundle for the Claude Code skills system. Install once and Claude Code stops being a chatbot and starts behaving like a senior bug‑hunting researcher or red‑team operator: it knows the techniques, the chain templates, the VRT mappings, the platform CVE chains, and the hygiene — and it stays in scope. Four layers stack: Think — bb‑methodology + redteam‑mindset: the 5‑phase non‑linear workflow, critical‑thinking framework, and red‑team operator discipline. Hunt webapps — 48 hunt‑skills curated from 681 disclosed HackerOne reports: per‑class detection patterns, payloads, bypass tables, and chain templates. Hit the perimeter — enterprise platform chains (M365/Entra, Okta, vCenter, SSL‑VPN appliances, SharePoint, cloud IAM): current 2024‑2026 CVE chains + post‑credential escalation. Ship it — triage‑validation + reporting + evidence‑hygiene: the 7‑Question Gate, VRT‑aware severity, OOS rebuttals, PII redaction, and red‑team deliverables. All triggered automatically by topic — describe what you’re testing in plain English and the relevant skill loads. No invocation by name.

Asked by Ivana Novak · Sep 24, 2025

How does it work?

The bundle follows a six‑phase, non‑linear workflow: recon → map & rank → hunt → validate → report, with scope enforced in code and a 7‑Question Gate before any finding is submitted. There are two ways to drive it: describe what you’re testing in plain English and the relevant skill loads are automatically applied, or use the /hunt scaffold and the cbh CLI, which provides an engagement‑folder structure, state management, and orchestration. Documentation includes a usage guide, a worked example, a 6‑phase architecture diagram, and a skill‑to‑phase mapping.

Asked by Yuki Mori · Jul 26, 2025

Ask a question

Skills alternatives

Using Git Worktrees (Grade A) logo
Using Git Worktrees (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Use when starting feature work that needs isolation from current workspace or before executing implementation plans - creates isolated git worktre

(0)
Free
Ga4 Bigquery Schema (Grade A) logo
Ga4 Bigquery Schema (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. GA4 BigQuery Export Schema Reference — complete field reference, nested structures, query patterns, and performance tips

(0)
Free
Meta Capi (Grade A) logo
Meta Capi (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Meta Conversions API (CAPI) Setup Reference — architecture, event types, customer information hashing, deduplication, implementation examples, AEM

(0)
Free
Callees (Grade A) logo
Callees (Grade A)Skills

Security-tested development skill for Claude AI. Grade A. Lista o que uma funcao/metodo chama (call graph direto)

(0)
Free
Test Module Name (Grade A) logo
Test Module Name (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Name Haskell test modules after the module under test with a Spec suffix in the same namespace. Use when writing or reviewing Haskell test module

(0)
Free
Board Of Directors (Grade A) logo
Board Of Directors (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Simulate a 5-member expert board deliberation for major decisions. Use when evaluating plans, architecture choices, feature designs, or any decisi

(0)
Free
Advpl Mvc Avancado (Grade A) logo
Advpl Mvc Avancado (Grade A)Skills

Security-tested development skill for Claude AI. Grade A. MVC avançado via PE (Pontos de Entrada) — adicionar grids customizadas em telas MVC padrão (CNTA300/MATA070/MATA440/MATA460/FINA040 via *STRU)

(0)
Free
D
Docs Writer (Grade A)Skills

Security-tested devops skill for Claude AI. Grade A. **WORKFLOW SKILL** — Maintains repository documentation accuracy and freshness across the docs site, agent files, and changelog. WHEN: "update docs

(0)
Free