NULLpointer
Official@0x0pointer
Offers specialized security assessment, vulnerability research, and penetration testing capabilities for enterprise infrastructure, cloud environments, and application codebases.
Agent Skills by NULLpointer
Showing 18 vetted skills indexed across 2 GitHub repositories.
email-security
Assess email infrastructure security by scanning SPF, DKIM, DMARC, and STARTTLS.
ssl-tls-audit
Audit TLS/SSL configurations across multiple ports and map findings to compliance frameworks.
lateral-movement
Identify and exploit Active Directory lateral movement paths using credential reuse and relay techniques.
network-assess
Map internal networks and enumerate hosts, services, and VLANs with network tools.
web-exploit
Chain advanced injection techniques to exploit web application vulnerabilities.
request-cves
Generate CVE request packages from pentest findings files.
cloud-security
Assesses AWS, Azure, and GCP infrastructure for misconfigurations, exposure, and compliance gaps.
osint
Map target organizations through passive OSINT sources with confidence scoring.
remediate
Generate implementable remediation patches for findings in findings.json.
post-exploit
Escalate privileges, harvest credentials, and enumerate compromised Linux and Windows hosts.
colang-gen
Generate NeMo Guardrails Colang files and YAML configuration from natural-language descriptions.
codebase
Analyze source code for security issues using the ASVS 5.0 framework.
api-security
Automate API security assessments across REST, GraphQL, gRPC, SOAP, and MCP backends.
metasploit
Validate and exploit CVEs with Metasploit in a controlled container.
aikido-triage
Triage Aikido CSV security findings against a local codebase.
threat-modeling
Model security threats with PASTA and Shostack methods, producing Mermaid diagrams and risk registers.
analyze-cve
Trace code paths from user input to vulnerable sinks and generate exploit requests for Burp Suite.
gh-export
Format penetration testing findings from JSON into GitHub issue markdown blocks.
Frequently Asked Questions About NULLpointer
FAQPage SchemaWhat specific security tasks can be performed using these capabilities?▼
These capabilities enable comprehensive security assessments including threat modeling via PASTA, Active Directory lateral movement analysis, TLS/SSL configuration auditing, and automated vulnerability research. Users can map internal networks, perform OSINT, and generate structured remediation patches or CVE request packages directly from identified security findings.
Which technical personas benefit most from these security modules?▼
These modules are designed for penetration testers, security researchers, and infrastructure engineers. Professionals tasked with hardening cloud environments, conducting red team exercises, or ensuring compliance with ASVS 5.0 standards will find these functions essential for identifying, validating, and documenting security vulnerabilities within complex enterprise systems.
What are the prerequisites for running these security assessment modules?▼
Execution requires a local environment capable of handling JSON-based findings and standard security testing frameworks. Specific modules depend on access to target infrastructure, such as cloud provider credentials for infrastructure auditing, or a containerized environment for validating exploits via Metasploit and generating Burp Suite request payloads.