Security Arsenal
Paste the following prompt into your AI chat to install this skill:
Follow https://skillhub.cn/install/skillhub.md to install @user_2354702d/security-arsenal.
About this skill
Problem
Offensive security work often gets stuck because tools are scattered, stage boundaries are unclear, and command examples are mixed with legal constraints. security-arsenal organizes the material into eight Cyber Kill Chain directories, from 01_Reconnaissance to 08_WebSec, so engineers can browse reconnaissance, weaponization, delivery, exploitation, persistence, C2, actions on objectives, and Web security tasks in one structured path.
How it works
The skill maps 96 tools to stages and keeps reference docs: references/cyber_kill_chain.md for theory, references/tool_catalog.md for purpose, official links, and install notes, references/usage_examples.md for common commands, and references/legal_guidelines.md for authorization templates. The workflow is to classify the task, pick the matching directory, and choose a tool set, such as Nuclei, mitmproxy, XSStrike, JWT Tool, and Kiterunner for Web app assessment, or CrackMapExec, Impacket, Mimikatz, and BloodHound for internal lateral movement.
Boundaries
Use it only for authorized penetration testing, enterprise security assessment, CTF, or isolated labs. It must not be used for unapproved scanning, attacks, phishing delivery, data theft, or availability disruption. Confirm the written authorization scope, time window, and target list, and protect sensitive data collected during testing.
Use Cases
- Before authorized Web penetration testing, select stage-specific tools such as Nuclei, mitmproxy, and XSStrike for vulnerability validation and report evidence.
- During authorized internal lateral movement, map AD attack paths with CrackMapExec, Impacket, Mimikatz, and BloodHound for credential and privilege review.
- Before phishing simulation, configure Gophish and SET email templates, clone sites, and measure click rates to evaluate employee awareness results.
- In isolated lab C2 exercises, compare Sliver, Covenant, dnscat2, FRP, and ngrok to design reliable command channels, noting protocol limits.
Best For
- Authorized enterprise security engineers who need stage-based penetration testing tools and command examples.
- CTF players who need quick reconnaissance, exploitation, and C2 tool lookup in isolated ranges.
- Red team coaches who need to teach Cyber Kill Chain tool boundaries and legal constraints.
- Web security testers who need authorized combinations of Nuclei, mitmproxy, and XSStrike for validation.
Related Skills
Detects child climbing, leaning out, or gripping window/balcony edges from surveillance video and outputs tiered alerts with historical reports.
A pre-release security auditor for Skills that statically checks injection, credentials, SSRF, CVEs, and permissions, with scored reports.
For independent developers, automates Git weekly reports, prioritized bug tickets, and project health checks into shareable Markdown.
Scan Windows caches, temporary files, and junk files, show space usage and risk levels, and clean selected items to free disk space.