Burp MCP Security Analysis Toolkit
Burp MCP Security Analysis Toolkit
Offensive Open Redirect
A Claude skill from SnailSploit/Claude-Red.
Offensive Fast Checking
A Claude skill from SnailSploit/Claude-Red.
Offensive Jwt
JWT attack methodology for penetration testers. Covers algorithm confusion (alg:none, RS256→HS256), weak HMAC secret brute force, kid parameter injection (SQLi, path traversal), jku/x5u/jwk header injection, JWKS cache poisoning, JWS/JWE confusion, timing attacks, and mobile JWT storage extraction. Use when testing JWT-based authentication, hunting auth bypass via token manipulation, or evaluatin…
Offensive Bluetooth Classic
Bluetooth Classic (BR/EDR) attack methodology — device discovery, service enumeration via SDP, LMP/L2CAP layer attacks, legacy PIN cracking (BlueBorne / KNOB), Bluetooth file-transfer abuse (BlueSnarfing legacy), unauthenticated profile abuse (HSP, HFP, OPP), and modern relevance against older industrial / automotive / accessory targets. Use when in-scope devices use Bluetooth Classic (Bluetooth…
Offensive Deserialization
A Claude skill from SnailSploit/Claude-Red.
Offensive Waf Bypass
A Claude skill from SnailSploit/Claude-Red.
Offensive Keylogger Arch
A Claude skill from SnailSploit/Claude-Red.
Offensive Exploit Development
A Claude skill from SnailSploit/Claude-Red.
Offensive Krack Fragattacks
KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants. Covers Vanhoef's test scripts, viability against modern patched stacks (mostly mitigated post-2021), residual unpatched embedded devices and IoT vendors, and the practical limitations of these attacks in modern engagements. Use when…
Offensive Xss
A Claude skill from SnailSploit/Claude-Red.
Offensive Basic Exploitation
A Claude skill from SnailSploit/Claude-Red.
Offensive Ai Security
A Claude skill from SnailSploit/Claude-Red.
Offensive Request Smuggling
A Claude skill from SnailSploit/Claude-Red.
Offensive Windows Mitigations
A Claude skill from SnailSploit/Claude-Red.
Offensive Oauth
A Claude skill from SnailSploit/Claude-Red.
Offensive Crash Analysis
A Claude skill from SnailSploit/Claude-Red.
Offensive Osint
Comprehensive OSINT methodology skill for offensive security, red team intelligence gathering, and bug bounty reconnaissance. Covers domain recon, email harvesting, social media profiling, GitHub/code leaks, Shodan/Censys enumeration, breach data lookup, employee profiling, infrastructure mapping, cryptocurrency tracing, geospatial intelligence, and AI-assisted analysis workflows. Use when perfor…
Offensive Business Logic
Business logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations, multi-step process abuse, price/quantity/discount manipulation, currency confusion, coupon stacking, refund/chargeback abuse, race conditions on logic boundaries, parameter tampering for hidden flows, role/tenant boundary violations, time-of-check vs use, anti-automation defeat,…
Offensive Reporting
Penetration test and red team report writing methodology. Covers executive summary structuring (risk-led narrative for non-technical readers), technical finding format (title, severity, affected scope, narrative, reproduction steps, impact, remediation, references), CVSS v3.1 / v4.0 scoring with vector justification, OWASP risk rating, evidence hygiene (redacting credentials, hashing client data,…
Offensive Evil Twin
Evil Twin / KARMA / Mana access point methodology — rogue AP construction with hostapd-mana / wifiphisher / airgeddon, KARMA universal probe response, Mana selective probe response, captive portal phishing, deauth-driven client coercion to attacker AP, MAC randomization defeat via PNL leak analysis, post-association MITM (DNS, ARP, transparent proxy), credential capture for portal/web/SMB, and de…
Offensive Initial Access
A Claude skill from SnailSploit/Claude-Red.
Offensive Mobile
Mobile (Android + iOS) application penetration testing methodology. Covers static analysis (apktool/jadx for Android, class-dump/Hopper/IDA for iOS), dynamic instrumentation with Frida and Objection, SSL pinning bypass strategies, root/jailbreak detection bypass, deep-link / URL-scheme abuse, exported component attacks (Android activities, services, providers, receivers; iOS XPC, URL schemes, uni…
Offensive Active Directory
Active Directory attack methodology for internal network red team engagements. Covers reconnaissance (BloodHound, PowerView, ADExplorer), credential abuse (Kerberoasting, ASREProasting, NTLM relay, LLMNR/NBT-NS poisoning), privilege escalation (ACL abuse, GPO abuse, unconstrained/constrained delegation), lateral movement (Pass-the-Hash, Pass-the-Ticket, Overpass-the-Hash, WMI/WinRM/PsExec), persi…
Offensive Windows Boundaries
A Claude skill from SnailSploit/Claude-Red.
Offensive Osint Methodology
A Claude skill from SnailSploit/Claude-Red.
Offensive Exploit Dev Course
A Claude skill from SnailSploit/Claude-Red.
Offensive Iot
IoT and embedded device security testing methodology. Covers hardware reconnaissance (UART, JTAG, SWD, SPI flash, I2C EEPROM, eMMC chip-off), firmware acquisition (vendor portals, OTA capture, flash dump, binwalk extraction), firmware analysis (filesystem mounting, binary triage, hardcoded secrets, default credential discovery), bootloader attacks (U-Boot console, secure-boot bypass, fault inject…
Offensive Rce
A Claude skill from SnailSploit/Claude-Red.
Offensive Parameter Pollution
A Claude skill from SnailSploit/Claude-Red.
Offensive Ssrf
A Claude skill from SnailSploit/Claude-Red.
Offensive Mitigations
A Claude skill from SnailSploit/Claude-Red.
Offensive Fuzzing
Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies, coverage measurement, and crash triage. Use when setting up or running fuzz campaigns against any target: file parsers, network protocols, kernel drivers, EDR engines, embedded firmware, or language runti…
Offensive Xxe
A Claude skill from SnailSploit/Claude-Red.
Offensive Idor
A Claude skill from SnailSploit/Claude-Red.
Offensive Race Condition
A Claude skill from SnailSploit/Claude-Red.
Offensive Bluetooth Ble
Bluetooth Low Energy (BLE) attack methodology — GATT enumeration, characteristic read/write without auth, pairing downgrade (Just Works forced), LE Secure Connections bypass, MITM via active relay, sniffing with Sniffle (TI CC1352) / Ubertooth / Frontline, encryption key extraction (LE Legacy Pairing crackable, LE Secure Connections strong), proximity authentication abuse (cars, locks), and compa…
Offensive Bug Identification
A Claude skill from SnailSploit/Claude-Red.
Offensive Cloud
Cloud security attack methodology covering AWS, Azure, and GCP. Includes credential harvesting (IMDS, ~/.aws, env vars, leaked CI secrets, instance roles), enumeration with cloud-specific tools (pacu, ScoutSuite, Prowler, ROADtools, gcp_enum), privilege escalation paths (IAM PassRole, AssumeRole chains, Lambda/Functions privilege flips, Azure Owner-on-self, GCP serviceAccountTokenCreator), persis…
Offensive Vuln Classes
A Claude skill from SnailSploit/Claude-Red.
Offensive File Upload
A Claude skill from SnailSploit/Claude-Red.
Offensive Fuzzing Course
A Claude skill from SnailSploit/Claude-Red.
Offensive Lorawan Sub Ghz
LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz protocol replay (KeeLoq garage doors, fixed-code remotes, TPMS spoofing, smart plug telemetry), HackRF / RTL-SDR / Flipper Zero workflows, signal analysis with Inspectrum / Universal Radio Hacker, and…
Offensive Toctou
Time-of-Check / Time-of-Use (TOCTOU) race condition exploitation methodology across binary, kernel, filesystem, web, and container layers. Covers symbolic-link races (open/access/stat split), file-descriptor races, fopen/realpath traversal races, /proc and procfs races, FUSE-backed slow-fs races to widen the window, ptrace and signal races, kernel double-fetch / userspace pointer races, container…
Offensive Advanced Redteam
A Claude skill from SnailSploit/Claude-Red.
Offensive Edr Evasion
A Claude skill from SnailSploit/Claude-Red.
Offensive Ssti
A Claude skill from SnailSploit/Claude-Red.
Offensive Deauth Disassoc
Deauthentication and disassociation attacks against 802.11 networks — targeted single-client deauth for handshake capture, broadcast deauth for DoS (with authorization), action-frame attacks bypassing 802.11w (PMF), beacon flooding, mdk4 / aireplay-ng tooling, and rate-limit / PMF-aware operation. Use to coerce client reconnection (handshake capture, evil-twin roaming), as targeted DoS, or to tes…
Offensive Graphql
A Claude skill from SnailSploit/Claude-Red.
Offensive Shellcode
Shellcode development reference for offensive security engagements. Use when writing custom x86/x64 shellcode, implementing position-independent code (PIC), building shellcode loaders, evading AV/EDR detection, or converting PE files to shellcode. Covers null byte avoidance, API hashing, encoder/decoder patterns, staged vs stageless payloads, Windows PEB traversal, and cross-platform shellcode te…
Offensive Sqli
SQL injection testing skill for offensive security assessments and bug bounty hunting. Covers error-based, UNION-based, boolean/time-based blind, out-of-band, second-order, NoSQL, GraphQL, WebSocket, and JSON-operator SQLi. Includes WAF bypass techniques, database-specific exploitation (MySQL, MSSQL, PostgreSQL, Oracle), cloud-native attack paths, ORM CVE tracking, and SQLmap automation. Use when…