attack-patterns-reference

Look up 51 confirmed attack patterns for web application and WordPress penetration testing.

1.1k|191|Updated Jun 24, 2026
One-click install
npx skills add https://github.com/uphiago/recon-skills --skill attack-patterns-reference
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: attack-patterns-reference
Source: https://github.com/uphiago/recon-skills/tree/main/meta/attack-patterns-reference
Command: npx skills add https://github.com/uphiago/recon-skills --skill attack-patterns-reference

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill eliminates the time spent manually searching for the right exploitation technique when you uncover a specific vulnerability during reconnaissance, ensuring you don't miss relevant attack paths or waste effort on dead-end testing methods.

Core Features & Use Cases

  • Comprehensive Pattern Catalog: Includes 25 general attack patterns (P-01 to P-25), 18 WordPress abuse patterns (WP-01 to WP-18), and 8 CORS bypass variants (V1 to V8), all validated across 600+ real-world targets and 9 waves of reconnaissance.
  • Attack Chain Building: Cross-reference patterns to construct multi-step exploitation chains, such as CORS + user enumeration → account takeover or SSRF → IMDS → AWS credential theft.
  • Sector-Specific Intelligence: Access tier-based sector vulnerability data to prioritize testing efforts on high-yield targets like law firms, pest control services, and landscaping companies.
  • Avoid Failed Patterns: Reference the curated list of saturated and broken patterns to skip testing methods that no longer work on modern systems, saving hours of redundant work.

Quick Start

Use the attack-patterns-reference skill to match your latest WordPress CORS finding to the correct exploitation variant and related attack chain steps.

Frequently Asked Questions about attack-patterns-reference

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I match penetration testing findings to validated attack patterns?

Cross-reference 51 confirmed attack patterns to match penetration testing findings to validated exploitation techniques, complete with severity ratings and exact detection commands. This lookup process eliminates manual searches and streamlines red team operations by avoiding dead-end testing methods.

What WordPress security vulnerabilities should I prioritize during red teaming?

Prioritize 18 WordPress abuse patterns (WP-01 to WP-18) validated across 600+ real-world targets during red teaming. Access tier-based sector vulnerability data to focus testing efforts on high-yield targets like law firms, pest control services, and landscaping companies.

How do I construct multi-step attack chains for web application exploitation?

Construct multi-step attack chains by cross-referencing catalog patterns to build sequences like CORS bypass plus user enumeration leading to account takeover, or SSRF to IMDS for AWS credential theft. The catalog provides validated techniques for chaining vulnerabilities into cohesive exploitation paths.

Can I find CORS bypass variants for web application penetration testing?

Yes, find 8 CORS bypass variants (V1 to V8) for web application penetration testing within the catalog. These variants are confirmed across real-world targets and include guidance on matching specific findings to the correct exploitation technique and related attack chain steps.

How do I avoid dead-end testing methods during security reconnaissance?

Avoid dead-end testing methods during security reconnaissance by referencing a curated list of saturated and broken patterns that no longer work on modern systems. This saves hours of redundant work and ensures testing efforts focus only on field-tested, viable exploitation techniques.

Does the attack pattern catalog include real-world confirmed target examples?

Yes, the attack pattern catalog includes real-world confirmed target examples validated across 600+ targets and 9 waves of reconnaissance. It provides field-tested pattern data with severity ratings and exact detection commands to support practical red team operations.