brukal001
Community@brukal001
brukal001 publishes 54 offensive security skills covering fuzzing, exploit development, web, wireless, cloud, Active Directory, and IoT penetration testing methodologies.
Agent Skills by brukal001
Showing 19 vetted skills indexed across 1 GitHub repositories.
offensive-fuzzing
Guides offensive fuzzing campaigns from target research through crash triage across multiple fuzzer frameworks.
vulnerability-classes
Teaches core memory corruption and logic vulnerability classes using real-world CVE case studies.
fuzzing-course
Teaches coverage-guided fuzzing methodology with AFL++, libFuzzer, FuzzTest, and Honggfuzz.
crash-analysis
Analyzes crash dumps and fuzzer crashes to assess exploitability using WinDbg, GDB, and sanitizers.
basic-exploitation
Teaches foundational Linux binary exploitation techniques including ROP chains, ret2libc, and shellcode injection.
offensive-jwt
Tests JWT implementations for algorithm confusion, weak secrets, and header injection vulnerabilities.
parameter-pollution
Tests web applications for HTTP parameter pollution and duplicate parameter handling flaws.
open-redirect
Tests web applications for open redirect vulnerabilities using bypass techniques and chaining methods.
ssrf
Tests web applications for Server-Side Request Forgery using discovery, bypass, and escalation checklists.
insecure-deserialization
Tests applications for insecure deserialization vulnerabilities across Java, PHP, .NET, Python, and other languages.
race-condition
Tests web applications for race condition and TOCTOU vulnerabilities using concurrent request techniques.
xss
Tests web applications for stored, reflected, DOM, and blind XSS vulnerabilities.
idor
Tests web applications for IDOR and broken access control vulnerabilities.
offensive-deauth-disassoc
Executes 802.11 deauthentication and disassociation attacks using aireplay-ng and mdk4.
windows-mitigations
Analyze Windows exploit mitigations including ASLR, DEP, CFG, CET, and SEHOP with bypass techniques.
offensive-osint
Guides open-source intelligence gathering across domains, people, infrastructure, cryptocurrency, and geospatial sources.
osint-methodology
Guides structured OSINT investigations covering geolocation, cryptocurrency tracing, and threat actor attribution.
fast-checking
Applies a rapid offensive security checklist for time-boxed web application and infrastructure assessments.
offensive-reporting
Write penetration test reports with CVSS scoring, evidence hygiene, and executive summaries.
Frequently Asked Questions About brukal001
FAQPage SchemaWhat tasks can I perform using brukal001's offensive security skills?▼
You can execute fuzzing campaigns, exploit TOCTOU race conditions, attack JWT and OAuth implementations, test business logic flaws, crack WPA2/WPA3 handshakes, exploit BLE/Zigbee/Z-Wave devices, escalate privileges in AWS/Azure/GCP, abuse Active Directory via Kerberoasting and ADCS ESC1-ESC15, and write CVSS-scored pentest reports.
Who are brukal001's skills designed for?▼
The skills target penetration testers, red team operators, bug bounty hunters, and embedded security researchers. Specific personas include wireless assessors running evil-twin engagements, mobile testers using Frida and Objection, IoT testers doing UART/JTAG hardware recon, and consultants authoring client deliverables.
What tools and dependencies do these skills reference?▼
Referenced tooling includes AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller, hashcat, hcxdumptool, hostapd-mana, eaphammer, reaver/bully, KillerBee, HackRF, RTL-SDR, Flipper Zero, Frida, Objection, BloodHound, PowerView, pacu, ScoutSuite, Prowler, binwalk, and Sniffle for BLE sniffing.
Do the skills cover wireless and RF attack surfaces?▼
Yes. Dedicated skills cover WPA2-PSK handshake and PMKID capture, WPA3 SAE downgrade and Dragonblood, WPA-Enterprise evil-twin RADIUS attacks, KRACK and FragAttacks, WPS Pixie Dust, deauthentication, Bluetooth Classic and BLE, Zigbee/Thread/Matter, Z-Wave, and LoRaWAN/sub-GHz replay with SDR hardware.
How do the skills support engagement reporting and scoping?▼
The offensive-reporting skill defines executive summary structure, technical finding format, CVSS v3.1/v4.0 scoring with vector justification, OWASP risk rating, evidence hygiene, PoC artifact management, and deliverable formats including PDF, DOCX, HTML, and JSON for SIEM ingestion, plus retest and remediation tracking.