AKasem1
GitHub profile for AKasem134 skills
Are you AKasem1? Claim your skills.
AKasem1 / cloud-iam-deep
Analyzes cloud IAM vulnerabilities across AWS, Azure, and GCP, focusing on external exploitation and privilege escalation techniques.
AKasem1 / hunt-api-misconfig
Identifies and exploits API security misconfigurations, including mass assignment, JWT vulnerabilities, and CORS issues.
AKasem1 / hunt-llm-ai
Identifies and mitigates LLM/AI feature bugs, focusing on security vulnerabilities like prompt injection and data exfiltration.
AKasem1 / hunt-mfa-bypass
Identifies vulnerabilities in MFA/2FA implementations through various bypass techniques, enhancing security assessments.
AKasem1 / hunt-saml
Identifies and exploits SAML/SSO vulnerabilities, enhancing security assessments against XML Signature Wrapping and other attack patterns.
AKasem1 / hunt-ssti
Detects server-side template injection vulnerabilities across various templating engines, enabling escalation to remote code execution.
AKasem1 / m365-entra-attack
Explores Microsoft 365 Entra ID attack vectors, providing insights for credential attacks and user enumeration scenarios.
AKasem1 / mid-engagement-ir-detection
Detects client SOC patches and attacker activity during red-team engagements, converting observations into actionable findings.
AKasem1 / offensive-osint
Provides a comprehensive toolkit for authorized external red-team and bug-bounty reconnaissance, including probes, wordlists, and discovery techniques.
AKasem1 / redteam-mindset
Enhances red team operations by instilling a mindset that prioritizes offensive testing and thorough engagement strategies.
AKasem1 / redteam-report-template
Facilitates the creation of structured red-team reports for client engagements, ensuring clarity for both technical and non-technical stakeholders.
AKasem1 / enterprise-vpn-attack
Analyzes and exploits vulnerabilities in SSL VPN appliances, providing a comprehensive attack matrix for various platforms.
AKasem1 / evidence-hygiene
Enhances bug-bounty submissions by ensuring proper evidence hygiene, focusing on sensitive data redaction and secure evidence capture protocols.
AKasem1 / hunt-aspnet
Identifies and exploits ASP.NET vulnerabilities, focusing on deserialization issues and security misconfigurations.
AKasem1 / hunt-ato
Provides a comprehensive taxonomy for identifying and exploiting account takeover vulnerabilities across various attack paths.
AKasem1 / hunt-auth-bypass
This skill aids in identifying and exploiting authentication bypass vulnerabilities, enhancing security assessments for web applications.
AKasem1 / hunt-cloud-misconfig
Identifies and validates cloud infrastructure misconfigurations across AWS, GCP, and Azure to enhance security posture.
AKasem1 / hunt-file-upload
Identifies and exploits file upload vulnerabilities, including RCE, XSS, and SSRF, using various bypass techniques for security testing.
AKasem1 / hunt-http-smuggling
Identifies and exploits HTTP request smuggling vulnerabilities by analyzing inconsistencies in header parsing between proxies and servers.
AKasem1 / hunt-ntlm-info
Identifies NTLM information disclosure vulnerabilities in internet-exposed IIS/SharePoint/Exchange servers for enhanced security assessments.