Hunt Ato (Grade A) logo

Hunt Ato (Grade A)Drošības pārbaudīta testēšanas kompetence Claude AI. Grade A. Hunt konta pārņemšanas taksonomija — 9 atšķirīgi ceļi uz ATO, kā arī ķēdes.

(0)
Daniel NikulshynPārskatījis Daniel Nikulshyn·Atjaunināts 2026. g. jūlijs

Pārskats

Hunt Ato (Grade A) ir drošības testēšanas kompetence Claude AI, kas fokusējas uz konta pārņemšanas (ATO) ievainojamībām. Tā nodrošina taksonomiju ar 9 atšķirīgiem ceļiem uz ATO, ieskaitot paroles atiestatīšanas defektus, e-pasta maiņu bez pārbaudes, OAuth konta saites CSRF, MFA piesprieguma apkalpošanu, sesiju fiksāciju, JWT manipulāciju, paroles maiņu bez step‑up, sociālās atjaunošanas / drošības jautājumu brute‑force un SSO subdomēna pārņemšanu OAuth redirect_uri. Kompetence aptver arī ievainojamību ķēdes, kas noved pie pastāvīgas ATO.

Galvenās funkcijas

  • Konta pārņemšanas taksonomija
  • 9 atšķirīgi ceļi uz ATO
  • Ķēdes uz ATO novedīgās ievainojamības
  • Testēšanas un validēšanas norādījumi
  • Detalizētas izskaustības par katru ievainojamības ceļu

Cenas

Modelis
Free
Kategorija
Taktu
Vērtējums
Nav atsauksmju

Lietošanas gadījumi

Paroles atiestatīšanas ievainojamību testēšana

Izmantojiet Hunt Ato, lai pārbaudītu paroles atiestatīšanas ievainojamības, tostarp servera galvenes injekcijas un paredzamus atiestatīšanas tokenus.

ATO ķēžu identificēšana

Izmantojiet Hunt Ato, lai identificētu ievainojamību ķēdes, kas var novest pie pastāvīgas ATO, piemēram, sīkfailu nozagšanu un parole oraklu.

Plusi un mīnusi

Plusi

  • Visaptveroša ATO ievainojamību taksonomija
  • Detalizētas izskaustības par katru ievainojamības ceļu
  • Nodrošina testēšanas un validēšanas norādījumus
  • Aptver dažādas ievainojamību ķēdes, kas noved uz ATO

Mīnusi

  • Prasa eksperti izpratni par drošības testēšanu un ATO ievainojamībām
  • Var nebūt aptver visus iespējamos ATO scenārijus
  • Validēšanai nepieciešams pierādīt testā konta pārņemšanu

Atsauksmes

Pieslēdzies, lai atstātu atsauksmi.

Vēl nav atsauksmju. Esi pirmais!

Jautājumi

Why this exists

Most bug-hunting Claude setups are either too generic (one big "security" prompt) or too fragmented (you bookmark 30 disclosed reports and re-read them every engagement). Neither scales past the second target. This bundle was built and validated through authorized engagements that exposed different capability gaps: Bug-bounty engagement — surfaced four gaps a starter 3-skill stack could not close: 1. No hypothesis discipline — drafts written before validation → wasted hours, hurt validity ratio 2. No per-program reporting tactics — VRT defaults auto-downgraded P3-worthy findings to P4 3. No engagement coordination — findings, evidence, and submission IDs scattered across folders 4. No evidence hygiene — screenshots leaked cookies and victim PII External red-team engagement — exposed five additional gaps that bug-bounty defaults made worse: 1. Conservative defaults retracted real findings — WAPT mindset stopped tests early on defended targets where red-team continuation would have surfaced bypass chains → redteam-mindset 2. No mid-engagement situational awareness — client SOC patched confirmed SQLi within 30 min; external attacker locked 14 accounts during a live test session — both invisible without explicit detection methodology → mid-engagement-ir-detection 3. No enterprise-platform attack chains — M365 + Entra ID, on-prem SharePoint, Cisco SSL VPN, vCenter, and 7 Android APKs all needed current 2024-2026 CVE knowledge and platform-specific tradecraft → m365-entra-attack, o

Asked by Vasyl Kovalenko · Aug 2, 2025

Why your model switched mid-session

Separate from refusals, and easy to miss. On Opus 5, a narrow set of higher-risk cyber requests — Anthropic names exploit generation, binary-based vulnerability scanning and penetration testing — fall back to Opus 4.8 rather than being refused. You get a notice and the response is labelled with the model that answered, but in a long agentic run that is easy to scroll past, so it can look like Opus 5 quietly got worse. See why Claude switched models. What to do depends on what you are actually doing: | Situation | What helps | |---|---| | Auditing your own code — reviewing a repo you own for defects | Say so. "Defensive review of my own repo", "check this against the OWASP Top 10", "secure refactor to remediate" describe the work accurately and read as remediation. This is not a workaround; the work genuinely is defensive. | | Authorized offensive work — live engagement, PoC for a bounty submission | This is what the bundle is for, and the supported route is CVP. Do not reword an offensive engagement to look defensive to get past a classifier — enroll instead. | | You just want the switching off | Settings → Capabilities disables automatic model switching. | /hunt states the engagement frame (authorized, scope-bounded, remediable finding) on its first turn for exactly this reason — engagement context belongs in the session explicitly, not implied. ---

Asked by Katarzyna Zielinska · Jun 21, 2025

Kā tas darbojas?

6-fāzju, nelineārs darba plūsmas — recon → map & rank → hunt → validate → report — ar kodā noteiktu darbības jomu un 7 jautājumu slīpām (Gate) pirms jebkura iesniegšanas. Divas iespējas to vadīt: Vienkāršais angļu – aprakstiet, ko testējat, un atbilstošie prasmes automātiski tiek ielādētas. /hunt scaffold + cbh CLI – iesaistīšanas mape, stāvoklis un orkestrācija. → Lietošanas vadlīnijas un piemērs · 6-fāžu arhitektūra & prasmes-fāzes kartes · cbh CLI

Asked by Jarrah Whitlock · Jun 7, 2025

What's inside

82 skills, auto-loaded by topic — no invocation by name. Coverage across the external attack surface: | Category | # | Examples | |---|---|---| | Web application hunting | 13 | XSS, SQLi, SSRF, IDOR, LFI, SSTI, XXE, CSRF, CORS, open-redirect | | Authentication & identity | 7 | auth-bypass, session, OAuth, SAML, MFA-bypass, ATO | | API & infrastructure | 15 | GraphQL, gRPC, WebSocket, API-misconfig, host-header, RCE | | Advanced & concurrency | 6 | race-condition, HTTP smuggling, deserialization, cache-poison | | Framework-specific | 4 | Next.js, Node.js, Laravel, Spring Boot | | Enterprise identity & cloud ★ | 3 | M365/Entra, Okta, cloud-IAM-deep | | Infrastructure & appliance ★ | 4 | VMware vCenter, enterprise VPN, SharePoint, ASP.NET/NTLM | | Red-team tradecraft ★ | 4 | redteam-mindset, APK pipeline, supply-chain recon, mid-engagement IR | | Recon & OSINT | 4 | web2-recon, offensive-osint, subdomain | | Workflow, reporting & specialized | 11 | methodology, triage-validation, evidence-hygiene, VRT-aware reporting | Full searchable catalog → docs/skills.md. Also ships 15 slash commands (/hunt, /recon, /report, …) and a deterministic engagement engine (engine/) that maps a target's attack surface and routes each finding to the skill that handles it. ---

Asked by Sami Virtanen · May 30, 2025

What is this?

claude-bughunter is a drop-in skill bundle for the Claude Code skills system. Install once and Claude Code stops being a chatbot and starts behaving like a senior bug-hunting researcher or red-team operator: it knows the techniques, the chain templates, the VRT mappings, the platform CVE chains, and the hygiene — and it stays in scope. Four layers stack: Think — bb-methodology + redteam-mindset: the 5-phase non-linear workflow, critical-thinking framework, and red-team operator discipline. Hunt webapps — 48 hunt- skills curated from 681 disclosed HackerOne reports: per-class detection patterns, payloads, bypass tables, and chain templates. Hit the perimeter — enterprise platform chains (M365/Entra, Okta, vCenter, SSL-VPN appliances, SharePoint, cloud IAM): current 2024–2026 CVE chains + post-credential escalation. Ship it** — triage-validation + reporting + evidence-hygiene: the 7-Question Gate, VRT-aware severity, OOS rebuttals, PII redaction, and red-team deliverables. All triggered automatically by topic — describe what you're testing in plain English and the relevant skill loads. No invocation by name. ---

Asked by George Papadakis · May 24, 2025

Uzdod jautājumu

Taktu alternatīvas

Manage Headers (Grade A) logo
Manage Headers (Grade A)Taktu

Drošības pārbaudīta izstrādes prasme Claude AI. Klases A. Pārbauda un konfigurē Power Pages vietnes pārlūkprogrammām nosūtītās drošības galvenes — Content Security Policy, frame un clickjacking aizsardzība

(0)
Free
Using Git Worktrees (Grade A) logo
Using Git Worktrees (Grade A)Taktu

Saugamības pārbaudīta datu-AI prasmju funkcija Claude AI. Grēds A. Izmantojiet, kad sākat funkciju darbu, kas prasa izolāciju no pašreizējās darba vietas vai pirms izpildes plānu - izveido izolēti git worktrees

(0)
Free
Ga4 Bigquery Schema (Grade A) logo
Ga4 Bigquery Schema (Grade A)Taktu

Drošības pārbaudīts datu-AI uzdevums Claude AI. Grēds A. GA4 BigQuery Eksporta shēmas atsauce — pilnīga lauku atsauce, iekļautas struktūras, vaicājumu modeļi un veiktspējas padomi

(0)
Free
Meta Capi (Grade A) logo
Meta Capi (Grade A)Taktu

Drošības pārbaudīta datu AI prasme Claude AI. Grads A.

(0)
Free
Callees (Grade A) logo
Callees (Grade A)Taktu

Sekuritātes testētu izstrādes iemaņu kalāšana ar Claude AI. Kvalitāti A. Saraksts, ko viena funkcija/metode saistījušas

(0)
Free
Test Module Name (Grade A) logo
Test Module Name (Grade A)Taktu

Drošības pārbaudīta datu-AI prasmju rīks Claude AI. Grēds A. Nosauciet Haskell testa moduļus pēc testējamā modula ar Spec sufiksu tajā pašā nosaukuma telpā. Lietojiet, kad rakstāt vai pārskatāt Haskell testa moduli.

(0)
Free
Board Of Directors (Grade A) logo
Board Of Directors (Grade A)Taktu

Izvēlētais dati-IA spēks par Claude AI. Grade A. Simulēt 5 dalībnieku ekspertu padomes diskusiju svarīgām lēmumiem. Lietot, lai novērtētu plānu, arhitektūras izvēles, funkciju dizainu vai nekādus citus lēmumus, kas prasību dažādus ekspertu skatu pārstāvju pārskatu.

(0)
Free
Advpl Mvc Avancado (Grade A) logo
Advpl Mvc Avancado (Grade A)Taktu

Rīkotāja, kas testēta kārtībā, lai izmantotu Claude AI. A klasē ar MVC. Pārstāv ADVPL peles — izveidot atstājīgs gridus MVC standarta tēlēs.

(0)
Free