Enterprise Vpn Attack (Grade B) logo

Enterprise Vpn Attack (Grade B)针对 Claude AI 的安全测试技能,已通过安全性测试。等级 B。外部 SSL VPN / 远程接入设备攻击矩阵 — Cisco ASA/AnyConnect、Fortinet FortiGate/FortiOS、Citrix NetScaler/ADC、Palo A

(0)
Daniel Nikulshyn审阅者 Daniel Nikulshyn·更新 2026年7月

概览

该技能提供了针对多家厂商的外部 SSL VPN / 远程接入设备攻击矩阵,包括 Cisco ASA/AnyConnect、Fortinet FortiGate/FortiOS、Citrix NetScaler/ADC、Palo Alto GlobalProtect、Pulse Secure / Ivanti Connect Secure、SonicWall 和 F5 Big-IP。涵盖版本指纹识别、2018‑2026 年 CVE 矩阵、AAA 后端识别、默认凭据、配置泄露路径,以及在适用情况下的预认证 RCE/SSRF/路径遍历利用。该技能基于授权参与的 Cisco ASA 测试以及 2024‑2026 年企业 VPN CVE 全景构建。它用于识别并可能利用 SSL VPN 设备或远程接入网关中的漏洞,这类设备是 2024‑2026 年攻击者 TTP 中常见的初始访问点。

主要功能

  • 针对 Cisco ASA/AnyConnect、Fortinet FortiGate/FortiOS、Citrix NetScaler/ADC、Palo Alto GlobalProtect、Pulse Secure / Ivanti Connect Secure 的版本指纹识别
  • 2018‑2026 年 CVE 矩阵
  • AAA 后端识别
  • 默认凭据识别
  • 配置泄露路径
  • 预认证 RCE/SSRF/路径遍历利用

价格

模型
Free
评分
暂无评价

使用场景

识别并利用 Cisco ASA/AnyConnect 漏洞

使用此技能识别并可能利用 Cisco ASA/AnyConnect SSL VPN 设备中的漏洞,包括版本指纹识别、CVE 矩阵检查以及预认证利用尝试。

扫描 Fortinet FortiGate/FortiOS 漏洞

利用此技能对 Fortinet FortiGate/FortiOS SSL VPN 设备进行漏洞扫描,包括版本识别和 CVE 矩阵检查。

优点 & 缺点

优点

  • 为多家厂商提供了全面的攻击矩阵
  • 覆盖 2018‑2026 年的版本指纹识别和 CVE 矩阵
  • 包含 AAA 后端识别和默认凭据的技术
  • 提供配置泄露路径和预认证利用的方法

缺点

  • 仅限于 SSL VPN 设备和远程接入网关
  • 不涵盖内部横向移动或 VPN 客户端侧漏洞
  • 排除 IPsec / L2TP / OpenVPN 协议

评测

登录以留下评测。

暂无评测。来当第一个吧!

问答

What's inside?

The bundle contains 82 auto‑loaded skills covering the external attack surface: Web application hunting (13 skills such as XSS, SQLi, SSRF, IDOR, LFI, SSTI, XXE, CSRF, CORS, open‑redirect), Authentication & identity (7 skills including auth‑bypass, session, OAuth, SAML, MFA‑bypass, ATO), API & infrastructure (15 skills like GraphQL, gRPC, WebSocket, API‑misconfig, host‑header, RCE), Advanced & concurrency (6 skills such as race‑condition, HTTP smuggling, deserialization, cache‑poison), Framework‑specific (4 skills for Next.js, Node.js, Laravel, Spring Boot), Enterprise identity & cloud (3 skills for M365/Entra, Okta, cloud‑IAM), Infrastructure & appliance (4 skills for VMware vCenter, enterprise VPN, SharePoint, ASP.NET/NTLM), Red‑team tradecraft (4 skills), Recon & OSINT (4 skills), Workflow, reporting & specialized (11 skills). It also ships 15 slash commands (/hunt, /recon, /report, …) and a deterministic engagement engine that maps a target’s attack surface and routes each finding to the appropriate skill.

Asked by Youssef El-Sayed · Nov 10, 2025

What is this?

claude-bughunter is a drop-in skill bundle for the Claude Code skills system. Install once and Claude Code stops being a chatbot and starts behaving like a senior bug‑hunting researcher or red‑team operator: it knows the techniques, the chain templates, the VRT mappings, the platform CVE chains, and the hygiene — and it stays in scope. Four layers stack: Think — bb‑methodology + redteam‑mindset: the 5‑phase non‑linear workflow, critical‑thinking framework, and red‑team operator discipline. Hunt webapps — 48 hunt‑skills curated from 681 disclosed HackerOne reports: per‑class detection patterns, payloads, bypass tables, and chain templates. Hit the perimeter — enterprise platform chains (M365/Entra, Okta, vCenter, SSL‑VPN appliances, SharePoint, cloud IAM): current 2024‑2026 CVE chains + post‑credential escalation. Ship it — triage‑validation + reporting + evidence‑hygiene: the 7‑Question Gate, VRT‑aware severity, OOS rebuttals, PII redaction, and red‑team deliverables. All triggered automatically by topic — describe what you’re testing in plain English and the relevant skill loads. No invocation by name.

Asked by Ivana Novak · Sep 24, 2025

How does it work?

The bundle follows a six‑phase, non‑linear workflow: recon → map & rank → hunt → validate → report, with scope enforced in code and a 7‑Question Gate before any finding is submitted. There are two ways to drive it: describe what you’re testing in plain English and the relevant skill loads are automatically applied, or use the /hunt scaffold and the cbh CLI, which provides an engagement‑folder structure, state management, and orchestration. Documentation includes a usage guide, a worked example, a 6‑phase architecture diagram, and a skill‑to‑phase mapping.

Asked by Yuki Mori · Jul 26, 2025

提问

育言活动 的替代品

Using Git Worktrees (Grade A) logo
Using Git Worktrees (Grade A)育言活动

安全试验的数据-AI技能 - Claude AI。A级。即将开始需要与当前工作环境隔离的功能工作,或执行实施计划前-创建隔离的git工作tree

(0)
Free
Ga4 Bigquery Schema (Grade A) logo
Ga4 Bigquery Schema (Grade A)育言活动

为Claude AI提供了经过安全测试的数据ai技能。 Grade A. GA4 BigQuery导出模式参考 - 完整字段参考、嵌套结构、查询模式和性能提示

(0)
Free
Meta Capi (Grade A) logo
Meta Capi (Grade A)育言活动

安全测试的数据-AI技能,专为Claude AI打造。Grade A. Meta Conversions API (CAPI) 设置指南-架构、事件类型、客户信息哈希、去重复、实现示例、AEM

(0)
Free
Callees (Grade A) logo
Callees (Grade A)育言活动

经过安全测试的 Claude AI 开发技能。Grade A。列出函数/方法调用的直接调用图

(0)
Free
Test Module Name (Grade A) logo
Test Module Name (Grade A)育言活动

安全测试数据-ai技能,Grade A. 名为Haskell测试模块,以同一命名空间中的测试模块命名,并在其后添加 Spec 辅助。 在编写或审阅Haskell测试模块时使用。

(0)
Free
Board Of Directors (Grade A) logo
Board Of Directors (Grade A)育言活动

经安全检测的数据 AI 技能,适用于 Claude AI。A级。模拟五位专家董事会就重大决策进行审议。用于评估计划、架构选择、功能设计或任何决策。

(0)
Free
Advpl Mvc Avancado (Grade A) logo
Advpl Mvc Avancado (Grade A)育言活动

安全测试的开发技能,适用于 Claude AI。Grade A。通过 PE(入口点)实现高级 MVC —— 在标准 MVC 界面(CNTA300/MATA070/MATA440/MATA460/FINA040 via *STRU)中添加自定义网格。

(0)
Free
D
Docs Writer (Grade A)育言活动

经过安全测试的 DevOps 技能,适用于 Claude AI。Grade A。**WORKFLOW SKILL** — 在 docs site、agent files 和 changelog 中保持仓库文档的准确性和新鲜度。WHEN: "update docs"

(0)
Free