Hunt Aspnet (Grade A) logo

Hunt Aspnet (Grade A)Security-tested testing-security skill for Claude AI. Grade A. Hunt ASP.NET-specific surface — ViewState deserialization (signed-only vs encrypted), machineKey recovery, dual-parser MAC-bypass anti-pa

(0)
Daniel NikulshynReviewed by Daniel Nikulshyn·Updated July 2026

Overview

Hunt Aspnet is a security testing skill for Claude AI, specifically designed to identify vulnerabilities in ASP.NET applications. It focuses on various attack surfaces including ViewState deserialization, machineKey recovery, and request-validator bypass. The skill is built for testing ASP.NET Webforms, WCF, and SharePoint farms. It helps in identifying high-value targets such as SharePoint farms, Telerik UI for ASP.NET AJAX, and classic ASP.NET Webforms enterprise apps. The skill also provides insights into attack surface signals, URL patterns to probe, and tech-stack signals to identify potential vulnerabilities.

Key features

  • ViewState deserialization testing
  • machineKey recovery testing
  • Request-validator bypass testing
  • Telerik UI for ASP.NET AJAX testing
  • Classic ASP.NET Webforms testing
  • SharePoint farm testing

Pricing

Model
Free
Category
Skills
Rating
No reviews yet

Use cases

Testing SharePoint Farms

Use Hunt Aspnet to identify vulnerabilities in SharePoint farms, specifically targeting sign-only ViewState and permissive ToolPane.aspx

Identifying Telerik UI Vulnerabilities

Use Hunt Aspnet to test Telerik UI for ASP.NET AJAX and identify potential RCE sinks

Testing Classic ASP.NET Webforms

Use Hunt Aspnet to identify vulnerabilities in classic ASP.NET Webforms enterprise apps, such as banking portals and dealer portals

Pros & Cons

Pros

  • Helps identify high-paying vulnerabilities in ASP.NET applications
  • Specifically designed for testing ASP.NET Webforms, WCF, and SharePoint farms
  • Provides insights into attack surface signals and tech-stack signals

Cons

  • Limited to testing ASP.NET applications
  • May require additional configuration for specific testing scenarios

Reviews

Sign in to leave a review.

No reviews yet. Be the first!

Q&A

Why this exists?

Most bug‑hunting Claude setups are either too generic (one big "security" prompt) or too fragmented (you bookmark 30 disclosed reports and re‑read them every engagement). Neither scales past the second target. This bundle was built and validated through authorized engagements that exposed different capability gaps: Bug‑bounty engagement — surfaced four gaps a starter 3‑skill stack could not close: 1. No hypothesis discipline — drafts written before validation → wasted hours, hurt validity ratio 2. No per‑program reporting tactics — VRT defaults auto‑downgraded P3‑worthy findings to P4 3. No engagement coordination — findings, evidence, and submission IDs scattered across folders 4. No evidence hygiene — screenshots leaked cookies and victim PII External red‑team engagement — exposed five additional gaps that bug‑bounty defaults made worse: 1. Conservative defaults retracted real findings — WAPT mindset stopped tests early on defended targets where red‑team continuation would have surfaced bypass chains → redteam‑mindset 2. No mid‑engagement situational awareness — client SOC patched confirmed SQLi within 30 min; external attacker locked 14 accounts during a live test session — both invisible without explicit detection methodology → mid‑engagement‑ir‑detection 3. No enterprise‑platform attack chains — M365 + Entra ID, on‑prem SharePoint, Cisco SSL VPN, vCenter, and 7 Android APKs all needed current 2024‑2026 CVE knowledge and platform‑specific tradecraft → m365‑entra‑attack, …

Asked by Olamide Fashola · Aug 12, 2025

Why your model switched mid‑session?

Separate from refusals, and easy to miss. On Opus 5, a narrow set of higher‑risk cyber requests — Anthropic names exploit generation, binary‑based vulnerability scanning and penetration testing — fall back to Opus 4.8 rather than being refused. You get a notice and the response is labelled with the model that answered, but in a long agentic run that is easy to scroll past, so it can look like Opus 5 quietly got worse. See why Claude switched models. What to do depends on what you are actually doing: | Situation | What helps | |---|---| | Auditing your own code — reviewing a repo you own for defects | Say so. "Defensive review of my own repo", "check this against the OWASP Top 10", "secure refactor to remediate" describe the work accurately and read as remediation. This is not a workaround; the work genuinely is defensive. | | Authorized offensive work — live engagement, PoC for a bounty submission | This is what the bundle is for, and the supported route is CVP. Do not reword an offensive engagement to look defensive to get past a classifier — enroll instead. | | You just want the switching off | Settings → Capabilities disables automatic model switching. | /hunt states the engagement frame (authorized, scope‑bounded, remediable finding) on its first turn for exactly this reason — engagement context belongs in the session explicitly, not implied.

Asked by Rosalind Frost · Jul 19, 2025

How it works?

A 6‑phase, non‑linear workflow — recon → map & rank → hunt → validate → report — with scope enforced in code and a 7‑Question Gate before anything is submitted. Two ways to drive it: Plain English — describe what you're testing and the relevant skill loads automatically. /hunt scaffold + cbh CLI — engagement‑folder structure, state, and orchestration. → Usage guide & worked example · 6‑phase architecture & skill‑to‑phase map · cbh CLI

Asked by Camille Laurent · Jun 4, 2025

What's inside?

82 skills, auto‑loaded by topic — no invocation by name. Coverage across the external attack surface: | Category | # | Examples | |---|---|---| | Web application hunting | 13 | XSS, SQLi, SSRF, IDOR, LFI, SSTI, XXE, CSRF, CORS, open‑redirect | | Authentication & identity | 7 | auth‑bypass, session, OAuth, SAML, MFA‑bypass, ATO | | API & infrastructure | 15 | GraphQL, gRPC, WebSocket, API‑misconfig, host‑header, RCE | | Advanced & concurrency | 6 | race‑condition, HTTP smuggling, deserialization, cache‑poison | | Framework‑specific | 4 | Next.js, Node.js, Laravel, Spring Boot | | Enterprise identity & cloud | 3 | M365/Entra, Okta, cloud‑IAM‑deep | | Infrastructure & appliance | 4 | VMware vCenter, enterprise VPN, SharePoint, ASP.NET/NTLM | | Red‑team tradecraft | 4 | redteam‑mindset, APK pipeline, supply‑chain recon, mid‑engagement IR | | Recon & OSINT | 4 | web2‑recon, offensive‑osint, subdomain | | Workflow, reporting & specialized | 11 | methodology, triage‑validation, evidence‑hygiene, VRT‑aware reporting | Full searchable catalog → docs/skills.md. Also ships 15 slash commands (/hunt, /recon, /report, …) and a deterministic engagement engine (engine/) that maps a target's attack surface and routes each finding to the skill that handles it.

Asked by Fernando Rojas · May 27, 2025

What is this?

claude-bughunter is a drop-in skill bundle for the Claude Code skills system. Install once and Claude Code stops being a chatbot and starts behaving like a senior bug‑hunting researcher or red‑team operator: it knows the techniques, the chain templates, the VRT mappings, the platform CVE chains, and the hygiene — and it stays in scope. Four layers stack: Think — bb‑methodology + redteam‑mindset: the 5‑phase non‑linear workflow, critical‑thinking framework, and red‑team operator discipline. Hunt webapps — 48 hunt‑skills curated from 681 disclosed HackerOne reports: per‑class detection patterns, payloads, bypass tables, and chain templates. Hit the perimeter — enterprise platform chains (M365/Entra, Okta, vCenter, SSL‑VPN appliances, SharePoint, cloud IAM): current 2024–2026 CVE chains + post‑credential escalation. Ship it — triage‑validation + reporting + evidence‑hygiene: the 7‑Question Gate, VRT‑aware severity, OOS rebuttals, PII redaction, and red‑team deliverables. All triggered automatically by topic — describe what you're testing in plain English and the relevant skill loads. No invocation by name.

Asked by Constantin Ionescu · May 17, 2025

Ask a question

Skills alternatives

Using Git Worktrees (Grade A) logo
Using Git Worktrees (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Use when starting feature work that needs isolation from current workspace or before executing implementation plans - creates isolated git worktre

(0)
Free
Ga4 Bigquery Schema (Grade A) logo
Ga4 Bigquery Schema (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. GA4 BigQuery Export Schema Reference — complete field reference, nested structures, query patterns, and performance tips

(0)
Free
Meta Capi (Grade A) logo
Meta Capi (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Meta Conversions API (CAPI) Setup Reference — architecture, event types, customer information hashing, deduplication, implementation examples, AEM

(0)
Free
Callees (Grade A) logo
Callees (Grade A)Skills

Security-tested development skill for Claude AI. Grade A. Lista o que uma funcao/metodo chama (call graph direto)

(0)
Free
Test Module Name (Grade A) logo
Test Module Name (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Name Haskell test modules after the module under test with a Spec suffix in the same namespace. Use when writing or reviewing Haskell test module

(0)
Free
Board Of Directors (Grade A) logo
Board Of Directors (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Simulate a 5-member expert board deliberation for major decisions. Use when evaluating plans, architecture choices, feature designs, or any decisi

(0)
Free
Advpl Mvc Avancado (Grade A) logo
Advpl Mvc Avancado (Grade A)Skills

Security-tested development skill for Claude AI. Grade A. MVC avançado via PE (Pontos de Entrada) — adicionar grids customizadas em telas MVC padrão (CNTA300/MATA070/MATA440/MATA460/FINA040 via *STRU)

(0)
Free
D
Docs Writer (Grade A)Skills

Security-tested devops skill for Claude AI. Grade A. **WORKFLOW SKILL** — Maintains repository documentation accuracy and freshness across the docs site, agent files, and changelog. WHEN: "update docs

(0)
Free