Skip to content

feat: add 20 new hunt#7

Open
muhsiindeniiz wants to merge 1 commit into
elementalsouls:mainfrom
muhsiindeniiz:feat/expand-hunt-skills-v3
Open

feat: add 20 new hunt#7
muhsiindeniiz wants to merge 1 commit into
elementalsouls:mainfrom
muhsiindeniiz:feat/expand-hunt-skills-v3

Conversation

@muhsiindeniiz
Copy link
Copy Markdown

  • skills, 9 disclosed reports, and expanded recon pipeline

New skills (20):

  • hunt-lfi, hunt-nosqli, hunt-deserialization, hunt-cors, hunt-host-header, hunt-open-redirect, hunt-brute-force, hunt-session, hunt-ldap (injection classes)
  • hunt-nextjs, hunt-nodejs, hunt-dom, hunt-websocket, hunt-grpc (modern JS/runtime)
  • hunt-laravel, hunt-springboot (framework-specific)
  • hunt-k8s, hunt-cicd, hunt-source-leak, hunt-tls-network (infra/recon)

New disclosed report pattern libraries (9):

  • LFI, NoSQLi, Deserialization, CORS, Host Header, Open Redirect, Brute Force, Session, LDAP

Updated files:

  • hunt-file-upload: add ImageMagick/FFmpeg SSRF, Headless Chrome PDF SSRF, Zip Slip
  • hunt-dispatch: 20 new fingerprint signals + full WAPT skill list expanded
  • recon.md: Step 8 (source leak quick wins) + Step 9 (DNS/TLS checks)
  • commands/scope.md: new pre-flight scope command

Skills: 60 → 73 | Disclosed reports: 15 → 24 | Commands: 14 → 15

…on pipeline

New skills (20):
- hunt-lfi, hunt-nosqli, hunt-deserialization, hunt-cors, hunt-host-header,
  hunt-open-redirect, hunt-brute-force, hunt-session, hunt-ldap (injection classes)
- hunt-nextjs, hunt-nodejs, hunt-dom, hunt-websocket, hunt-grpc (modern JS/runtime)
- hunt-laravel, hunt-springboot (framework-specific)
- hunt-k8s, hunt-cicd, hunt-source-leak, hunt-tls-network (infra/recon)

New disclosed report pattern libraries (9):
- LFI, NoSQLi, Deserialization, CORS, Host Header,
  Open Redirect, Brute Force, Session, LDAP

Updated files:
- hunt-file-upload: add ImageMagick/FFmpeg SSRF, Headless Chrome PDF SSRF, Zip Slip
- hunt-dispatch: 20 new fingerprint signals + full WAPT skill list expanded
- recon.md: Step 8 (source leak quick wins) + Step 9 (DNS/TLS checks)
- commands/scope.md: new pre-flight scope command

Skills: 60 → 73 | Disclosed reports: 15 → 24 | Commands: 14 → 15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant