What problem does it solve?
This Skill helps you quickly identify common enterprise SSL VPN / remote-access appliances and determine which pre-auth or auth-bypass CVE paths are relevant, so you can plan targeted testing under Rules of Engagement.
Core Features & Use Cases
- Vendor fingerprinting & version hints: Detect Cisco ASA/AnyConnect, Fortinet FortiGate/FortiOS, Citrix NetScaler/ADC, Palo Alto GlobalProtect, Pulse Secure/Ivanti Connect Secure, SonicWall, and F5 Big-IP using observable login pages, cookies, and endpoint patterns.
- CVE mapping for 2018–2026 VPN attack surface: Provides a CVE matrix with scope notes (pre-auth path traversal, file read, auth bypass, and selected pre-auth RCE where applicable) and non-disruptive test guidance.
- SAML/AAA misconfiguration checks: Encourages validating SAML SP metadata and AAA backend identification to guide subsequent strategy without assuming patch status from version strings.
- Operational guardrails: Emphasizes rate limiting, detection-first for disruptive tests, and avoiding out-of-scope lateral movement or client-side bug classes.
Quick Start
Use the enterprise-vpn-attack skill to triage a suspected SSL VPN endpoint at https://target by running the non-disruptive fingerprint and then selecting the highest-probability CVE tests from the matrix.