enterprise-vpn-attack

Fingerprint exposed enterprise VPN appliances and map CVEs and misconfiguration paths.

Updated May 31, 2026
One-click install
npx skills add https://github.com/grivera82/pi-bughunter --skill enterprise-vpn-attack-grivera82
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: enterprise-vpn-attack
Source: https://github.com/grivera82/pi-bughunter/tree/main/skills/enterprise-vpn-attack
Command: npx skills add https://github.com/grivera82/pi-bughunter --skill enterprise-vpn-attack-grivera82

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

External SSL VPN / remote-access appliance exposure creates broad initial-access risk; this Skill provides a consolidated matrix to fingerprint vendors, enumerate CVEs, identify default credentials, and discover configuration-disclosure paths for major VPN platforms.

Core Features & Use Cases

  • Vendor fingerprinting & CVE mapping across Cisco ASA/AnyConnect, Fortinet FortiGate/FortiOS, Citrix NetScaler/ADC, Palo Alto GlobalProtect, Pulse Secure / Ivanti Connect Secure, SonicWall, and F5 Big-IP.
  • Pre-auth and post-auth visibility of common misconfig paths, default creds, and disclosure vectors to guide targeted testing and risk assessment.
  • Operational workflows linking to downstream skills (hunt-rce, hunt-saml, mid-engagement-ir-detection) for end-to-end engagement and reporting.

Quick Start

Run a remote VPN surface assessment to fingerprint vendors, map CVEs, and identify potential disclosure paths.

Frequently Asked Questions about enterprise-vpn-attack

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I fingerprint enterprise VPN appliances exposed to the public internet?▼

You can fingerprint enterprise VPN appliances by identifying backend identity and mapping vendors like Cisco ASA, Fortinet FortiGate, and Palo Alto GlobalProtect to detect exposed remote-access surface risks.

What CVEs and default credentials affect SSL VPN portals like Pulse Secure and Citrix NetScaler?▼

This approach maps CVEs and default credentials for SSL VPN portals including Pulse Secure, Citrix NetScaler, and F5 Big-IP to identify pre-auth and post-auth misconfiguration paths.

Can I use this for red-team testing of SonicWall and F5 Big-IP remote-access appliances?▼

Yes, you can use this for red-team and pentest engagements to codify operational checks, determine backend identity, and discover configuration disclosure paths for SonicWall and F5 Big-IP appliances.

How do I map VPN configuration disclosure paths during a remote surface assessment?▼

You map VPN configuration disclosure paths by applying pre-auth and post-auth visibility checks to identify common misconfigurations and disclosure vectors across major enterprise VPN platforms.

What downstream skills link to enterprise VPN attack workflows for end-to-end reporting?▼

Operational workflows link to downstream skills like hunt-rce, hunt-saml, and mid-engagement-ir-detection to extend VPN vulnerability identification into end-to-end engagement and reporting.