Wolf Group Security Team avatar

Wolf Group Security Team

Official

@wgpsec · Earth

0Followers
|
54Public Repos
|
127Published Skills

Wolf Group Security Team 狼组安全团队 子团队@ffffffff0x

Skills Distribution
DomainCybersecurit...Penetration Testing (40%)Red-Team Infrastru.. (30%)Cloud Security (30%)

Agent Skills by Wolf Group Security Team

Showing 127 vetted skills indexed across 3 GitHub repositories.

wgpsecwgpsec
1.7k

aboutsecurity-content-ingestion

Integrates external security knowledge into the AboutSecurity repository following structured SOP phases.

Official
Advanced
wgpsecwgpsec
1.7k

agent-security

Tests AI agent systems against OWASP Agentic AI Security Top 10 attack scenarios.

Official
Advanced
wgpsecwgpsec
1.7k

mcp-security

Tests MCP servers for tool description poisoning, rug pulls, and hidden instruction injection.

Official
Advanced
wgpsecwgpsec
1.7k

ai-identity-security

Tests AI agent identity, role boundaries, permissions, sessions, and credential controls for bypass.

Official
Advanced
wgpsecwgpsec
1.7k

ai-data-security

Tests LLM and AI systems for data leakage, training data extraction, and RAG poisoning risks.

Official
Advanced
wgpsecwgpsec
1.7k

cot-injection

Tests Chain-of-Thought and ReAct agent reasoning chains for injection and manipulation vulnerabilities.

Official
Intermediate
wgpsecwgpsec
1.7k

middleware-tactics

Exploit Tomcat, WebLogic, JBoss, IIS, Nginx, and Apache middleware via weak credentials, WAR deployment, and parsing flaws.

Official
Intermediate
wgpsecwgpsec
1.7k

database-tactics

Guides penetration testing attacks against Redis, MSSQL, PostgreSQL, MySQL, and MongoDB services.

Official
Advanced
wgpsecwgpsec
1.7k

disk-forensics-evasion

Analyze disk forensics artifacts and apply anti-forensics techniques on NTFS and ext4 systems.

Official
Advanced
wgpsecwgpsec
1.7k

emergency-response

Investigate compromised Linux and Windows hosts through account, process, persistence, and log analysis.

Official
Advanced
wgpsecwgpsec
1.7k

firmware-analysis

Analyzes embedded device firmware through extraction, static analysis, QEMU emulation, and repackaging.

Official
Advanced
wgpsecwgpsec
1.7k

http-smuggling-advanced

Exploit confirmed HTTP request smuggling vulnerabilities through chained attacks and HTTP/2 downgrade techniques.

Official
Advanced
wgpsecwgpsec
1.7k

captcha-bypass-methodology

Bypass and recognize image, click, and slider captchas during authorized penetration tests.

Official
Intermediate
wgpsecwgpsec
1.7k

password-reset-methodology

Tests password reset flows for verification code flaws and unauthorized account modification.

Official
Intermediate
wgpsecwgpsec
1.7k

mobile-backend

Tests mobile app backend APIs for authentication flaws, IDOR, and business logic vulnerabilities.

Official
Intermediate
wgpsecwgpsec
1.7k

mssql-pentesting

Tests MSSQL servers on port 1433 through enumeration, xp_cmdshell execution, and privilege escalation.

Official
Advanced
wgpsecwgpsec
1.7k

ftp-pentesting

Tests FTP services on port 21 for anonymous access, weak credentials, and known exploits.

Official
Advanced
wgpsecwgpsec
1.7k

binary-exploitation-methodology

Guides analysis and exploitation of binary vulnerabilities including stack overflows, heap corruption, and format strings.

Official
Advanced
wgpsecwgpsec
1.7k

binary-exploitation-tools

Guides selection and usage of debugging, exploitation, and reverse engineering tools for binary analysis.

Official
Intermediate
wgpsecwgpsec
1.7k

web-vuln-scan

Guides deep vulnerability scanning of a single web target using fingerprint-driven tool selection and manual testing.

Official
Intermediate
wgpsecwgpsec
1.7k

ssti-methodology

Detect, identify, and exploit server-side template injection across Jinja2, Twig, FreeMarker, and other engines.

Official
Advanced
wgpsecwgpsec
1.7k

http-host-header-attacks

Tests HTTP Host header handling for password reset poisoning, cache poisoning, SSRF, and virtual host enumeration.

Official
Advanced
wgpsecwgpsec
1.7k

subdomain-takeover

Detect and exploit dangling DNS records to claim abandoned subdomains on cloud providers.

Official
Intermediate
wgpsecwgpsec
1.7k

java-framework-audit

Detects known vulnerability patterns in Spring, Struts2, Shiro, FastJSON, and MyBatis source code.

Official
Advanced

Frequently Asked Questions About Wolf Group Security Team

FAQPage Schema
What specific security tasks are enabled by these methodologies?

These methodologies enable comprehensive penetration testing, including web application fuzzing, Active Directory domain enumeration, Kubernetes cluster reconnaissance, and post-exploitation lateral movement across internal networks.

Which technical personas benefit from these security resources?

Red-team operators, penetration testers, and cloud security engineers utilize these resources to standardize assessment phases, manage infrastructure deployments, and execute complex security research tasks.

What are the prerequisites for deploying the infrastructure modules?

Deployment requires a configured environment with Terraform installed, valid cloud provider credentials for AWS, Azure, or GCP, and basic familiarity with Linux-based command-line operations for VPS management.