What problem does it solve?
This Skill provides a structured framework to fingerprint enterprise VPN appliances, map common pre-auth CVEs, and identify misconfigurations that expose perimeters to initial-access threats.
Core Features & Use Cases
- Vendor fingerprinting across major SSL VPN appliances (Cisco ASA/AnyConnect, Fortinet FortiGate/FortiOS, Citrix NetScaler/ADC, Palo Alto GlobalProtect, Pulse Secure/Ivanti Connect Secure, SonicWall, F5 Big-IP).
- CVE matrix coverage (2018-2026) with guidance on pre-auth or authentication-bypass paths and practical verification steps.
- SAML SP / IdP metadata misconfig checks and AAA backend identification to assess federation risk.
- Default credentials and common misconfig indicators for rapid risk triage.
- Nuclei templates and bridge strategies to other security skills for end-to-end engagement workflows.
- Operational discipline and best practices to minimize disruption during assessment.
Quick Start
Run a quick triage sweep on the VPN appliance to fingerprint the vendor and check for common pre-auth CVEs.