Wolf Group Security Team
Official@wgpsec · Earth
Wolf Group Security Team 狼组安全团队 子团队@ffffffff0x
Agent Skills by Wolf Group Security Team
Showing 127 vetted skills indexed across 3 GitHub repositories.
aboutsecurity-content-ingestion
Integrates external security knowledge into the AboutSecurity repository following structured SOP phases.
agent-security
Tests AI agent systems against OWASP Agentic AI Security Top 10 attack scenarios.
mcp-security
Tests MCP servers for tool description poisoning, rug pulls, and hidden instruction injection.
ai-identity-security
Tests AI agent identity, role boundaries, permissions, sessions, and credential controls for bypass.
ai-data-security
Tests LLM and AI systems for data leakage, training data extraction, and RAG poisoning risks.
cot-injection
Tests Chain-of-Thought and ReAct agent reasoning chains for injection and manipulation vulnerabilities.
middleware-tactics
Exploit Tomcat, WebLogic, JBoss, IIS, Nginx, and Apache middleware via weak credentials, WAR deployment, and parsing flaws.
database-tactics
Guides penetration testing attacks against Redis, MSSQL, PostgreSQL, MySQL, and MongoDB services.
disk-forensics-evasion
Analyze disk forensics artifacts and apply anti-forensics techniques on NTFS and ext4 systems.
emergency-response
Investigate compromised Linux and Windows hosts through account, process, persistence, and log analysis.
firmware-analysis
Analyzes embedded device firmware through extraction, static analysis, QEMU emulation, and repackaging.
http-smuggling-advanced
Exploit confirmed HTTP request smuggling vulnerabilities through chained attacks and HTTP/2 downgrade techniques.
captcha-bypass-methodology
Bypass and recognize image, click, and slider captchas during authorized penetration tests.
password-reset-methodology
Tests password reset flows for verification code flaws and unauthorized account modification.
mobile-backend
Tests mobile app backend APIs for authentication flaws, IDOR, and business logic vulnerabilities.
mssql-pentesting
Tests MSSQL servers on port 1433 through enumeration, xp_cmdshell execution, and privilege escalation.
ftp-pentesting
Tests FTP services on port 21 for anonymous access, weak credentials, and known exploits.
binary-exploitation-methodology
Guides analysis and exploitation of binary vulnerabilities including stack overflows, heap corruption, and format strings.
binary-exploitation-tools
Guides selection and usage of debugging, exploitation, and reverse engineering tools for binary analysis.
web-vuln-scan
Guides deep vulnerability scanning of a single web target using fingerprint-driven tool selection and manual testing.
ssti-methodology
Detect, identify, and exploit server-side template injection across Jinja2, Twig, FreeMarker, and other engines.
http-host-header-attacks
Tests HTTP Host header handling for password reset poisoning, cache poisoning, SSRF, and virtual host enumeration.
subdomain-takeover
Detect and exploit dangling DNS records to claim abandoned subdomains on cloud providers.
java-framework-audit
Detects known vulnerability patterns in Spring, Struts2, Shiro, FastJSON, and MyBatis source code.
Frequently Asked Questions About Wolf Group Security Team
FAQPage SchemaWhat specific security tasks are enabled by these methodologies?▼
These methodologies enable comprehensive penetration testing, including web application fuzzing, Active Directory domain enumeration, Kubernetes cluster reconnaissance, and post-exploitation lateral movement across internal networks.
Which technical personas benefit from these security resources?▼
Red-team operators, penetration testers, and cloud security engineers utilize these resources to standardize assessment phases, manage infrastructure deployments, and execute complex security research tasks.
What are the prerequisites for deploying the infrastructure modules?▼
Deployment requires a configured environment with Terraform installed, valid cloud provider credentials for AWS, Azure, or GCP, and basic familiarity with Linux-based command-line operations for VPS management.