{
  "markdown": "[中文文档](README.zh-CN.md) | English\n\n![AboutSecurity — The world's largest structured pentest knowledge base](assets/img/banner.png)\n\n# AboutSecurity\n\nPenetration testing knowledge base with security methodologies in AI Agent-executable format.\n\n## Core Modules\n\n**Skills/** — 200+ skill methodologies covering the full chain from recon to post-exploitation\n\n- `ai-security/` — AI security (prompt injection, model jailbreaking, prompt leaking, agent attack chains)\n- `cloud/` — Cloud environments (Docker escape, K8s attack chains, AWS IAM, Alibaba Cloud, Tencent Cloud, Serverless)\n- `code-audit/` — Code auditing (PHP 8-skill system, Java 8-skill system covering injection/file/serialization/auth/framework/exploit chains)\n- `ctf/` — CTF competitions (Web challenges, reversing, PWN, cryptography, forensics, AI/ML)\n- `dfir/` — Digital forensics & incident response (memory forensics & anti-forensics, disk forensics, log evasion)\n- `evasion/` — Evasion techniques (C2 frameworks, shellcode generation, security research)\n- `exploit/` — Exploitation (organized by subcategory)\n  - `advanced/` — Advanced exploitation (HTTP smuggling, race conditions, supply chain attacks, OT/ICS, crypto attacks)\n  - `auth/` — Authentication & authorization (JWT, OAuth/SSO, IDOR, CORS, CSRF, cookie analysis)\n  - `binary/` — Binary exploitation methodology and tools\n  - `network-service/` — Network service pentesting by port/protocol (SMB, FTP, SMTP, DNS, LDAP, etc.)\n  - `web-method/` — Web methodology (injection, XSS, SSRF, SSTI, file upload, deserialization, WAF bypass...)\n- `general/` — General (report generation, supply chain auditing, mobile backend API)\n- `hardware/` — Hardware/physical access pentesting\n- `lateral/` — Lateral movement (AD domain attacks, NTLM relay, database pivoting, Kerberoasting, ACL abuse)\n- `malware/` — Malware (sample analysis methodology, C2 beacon config extraction, sandbox evasion)\n- `mobile/` — Mobile app pentesting (Android, iOS)\n- `postexploit/` — Post-exploitation\n  - `post-exploit-linux/` / `post-exploit-windows/` — OS-level privilege escalation, credential theft\n  - `persist-maintain/` — Persistence techniques (cron, services, webshell)\n  - `tool-delivery/` — Tool delivery to compromised hosts (fscan, frp, chisel, linpeas, mimikatz, etc.; Linux/Windows transfer methods: wget/curl/certutil/bitsadmin/PowerShell/python/nc/base64/SMB; no-egress scenarios, AV bypass, post-exec cleanup)\n  - `product/` — Product-specific post-exploitation tactics (ArgoCD, Harbor, databases, middleware, Portainer, RabbitMQ)\n- `recon/` — Reconnaissance (subdomain enumeration, passive information gathering, JS API extraction)\n- `threat-intel/` — Threat intelligence (IOC evasion, APT simulation, threat hunting evasion)\n- `tool/` — Tool usage (fscan, nuclei, sqlmap, msfconsole, ffuf, hashcat)\n\n**Dic/** — Dictionary library (lowercase hyphen-separated naming, each directory has `_meta.yaml` metadata)\n\n- `auth/` — Usernames/passwords (complexity-rule passwords, WPA, pinyin names), plus default credentials of government/enterprise security appliances & OA systems (`device-default/`)\n- `network/` — DNS servers, excluded IP ranges\n- `port/` — Service-specific brute-force dictionaries (mysql, redis, ssh, etc. — 19 types)\n- `regular/` — General-purpose dictionaries (numbers, letters, addresses, keywords)\n- `web/` — Web directories, API parameters, middleware, upload bypass, webshells, HTTP headers\n\n**Payload/** — Attack payloads (lowercase hyphen-separated naming, each directory has `_meta.yaml` metadata)\n\n- `sqli/`, `xss/`, `ssrf/`, `xxe/`, `lfi/`, `rce/`, `upload/`, `cors/`, `hpp/`, `format/`, `ssi/`, `email/`, `access-bypass/`, `prompt-injection/`\n\n**Vuln/** — 600+ vulnerability entries, structured vulnerability data organized by product\n\n- `ai/` — AI-related (ComfyUI, Dify, LangFlow, AnythingLLM, etc.)\n- `cloud/` — Cloud platforms (AWS API Gateway, etc.)\n- `middleware/` — Middleware (ActiveMQ, Nacos, Grafana, Jenkins, RocketMQ, etc. — 394 entries)\n- `network/` — Network devices (routers, switches, etc.)\n- `web/` — Web applications (1Panel, WordPress, OFBiz, etc.)\n\n> **postexploit/ vs Vuln/**: Skills under `postexploit/` are the **post-exploitation layer** — what to do after gaining access (privilege escalation, persistence, credential extraction, lateral movement, product-specific tactics). Entries under `Vuln/` are the **vulnerability data layer** — affected versions, PoC code, specific exploitation steps per CVE. In short: **Skills tell you \"what to do after you're in\", Vuln tells you \"how to get in\"**.\n\n## Quick Start\n\n### 1. Clone the Repository\n\n```bash\ngit clone https://github.com/wgpsec/AboutSecurity.git\n```\n\n### 2. Sync Skills to Your Project\n\n```bash\n# Sync all security skills to your working project\ncd AboutSecurity\n./scripts/sync-claude-skills.sh --target /path/to/your-project\n\n# Result: creates .claude/skills/<skill-name>/ symlinks in the target project\n# Claude Code will automatically discover and invoke these skills\n```\n\n> Omit `--target` to sync to the AboutSecurity repo itself (for using Agent directly in this repo). Re-run after adding or removing skills.\n\n### 3. Using Dictionaries & Payloads\n\nDictionaries and payloads don't need syncing — just reference the paths in your Agent conversation:\n\n```\n\"Use the dictionaries under /path/to/AboutSecurity/Dic/auth/ to brute-force SSH\"\n\"Load the payload list from /path/to/AboutSecurity/Payload/xss/ for fuzz testing\"\n```\n\nThe Agent reads these files directly via Read / Glob tools — just provide the correct repo path.\n\n<details>\n<summary><b>Background (for newcomers): What is a Skill? Why sync?</b></summary>\n\n- **Skill** = a structured methodology file (`SKILL.md`) that tells an AI Agent \"what to do when encountering scenario X\"\n- Claude Code only recognizes the flat structure `.claude/skills/<name>/SKILL.md`\n- This repo organizes skills in nested categories (e.g., `skills/exploit/web-method/sql-injection/SKILL.md`), the sync script creates symlinks for the nested → flat mapping\n- After syncing, the Agent **automatically matches and loads** relevant Skills based on conversation context — no manual specification needed\n\n</details>\n\n### 4. Use via MCP Service (context1337) (Highly Recommended)\n\nIf you want to **search and invoke** all resources in this repo via natural language through AI assistants (Claude Code, Cursor, Claude Desktop, etc.), deploy [context1337](https://github.com/wgpsec/context1337) — a standalone MCP resource service that turns AboutSecurity from a file repo into a consumable API (like context7, but for security).\n\n```bash\ngit clone https://github.com/wgpsec/context1337.git\ncd context1337\nmake run   # One command: clone data + build index + start server\n```\n\nThen add the MCP service to your AI tool:\n\n```bash\n# Claude Code\nclaude mcp add aboutsecurity --transport http http://localhost:1337/mcp\n```\n\nAfter that, query with natural language: \"Search for SQL injection resources\", \"List all XSS payloads\", \"Find critical Apache vulnerabilities\", etc. See [context1337 README](https://github.com/wgpsec/context1337) for details.\n\n---\n\n## Skills Overview\n\n[skills/README.md](./skills/README.md) covers the skills classification architecture, format specification, and benchmark testing process.\n\n## Dic/Payload Naming Conventions\n\n### Directory Naming\n- All lowercase, hyphen-separated: `file-backup/`, `api-param/`, `prompt-injection/`\n\n### File Naming\n- All English, lowercase, hyphen-separated\n- No `Fuzz_` prefix (legacy naming has been cleaned up)\n- Examples: `password-top100.txt`, `xss-tag-event-full.txt`, `complex-8char-upper-lower-digit.txt`\n\n### `_meta.yaml` Metadata\n\nEvery directory containing data files has a `_meta.yaml` providing structured metadata for AI search:\n\n```yaml\ncategory: auth                     # Top-level category\nsubcategory: password              # Subcategory (optional)\ndescription: \"Common weak passwords and complexity-rule generated password dictionaries\"\ntags: \"password,weak-password,brute-force,login,credential\"\n\nfiles:\n  - name: top100.txt\n    lines: 100\n    description: \"Top 100 most common weak passwords\"\n    usage: \"Initial brute-force screening, quick default password verification\"\n    tags: \"top100,common,weak\"\n```\n\n`description` and `usage` use Chinese, `tags` are bilingual (Chinese + English). Update the corresponding `_meta.yaml` when adding new dictionary/payload files.\n\n## Contributing\n\nRead [CONTRIBUTING.md](./CONTRIBUTING.md) before submitting, which covers Skill format specification, Vuln database writing standards, references requirements, and benchmark testing process.\n\n## WgpSec Agentic Ecosystem\n\nAboutSecurity is the knowledge layer of the **WgpSec Agentic Ecosystem** — a full-stack pipeline from structured security knowledge to autonomous penetration testing.\n\n```\n┌───────────────────── WgpSec Agentic Ecosystem ─────────────────────┐\n│                                                                     │\n│  Knowledge ➜ Service ➜ Execution ➜ Evaluation                      │\n│                                                                     │\n│  AboutSecurity ──▶ context1337 ──▶ tchkiller ──▶ benchmark-platform │\n│  (this repo)       (MCP Server)    (Pentest Agent)  (CTF Range)    │\n│                                         ▲                           │\n│                                    PoJun (通用求解引擎)              │\n│                                                                     │\n└─────────────────────────────────────────────────────────────────────┘\n```\n\n| Project | Role |\n|---------|------|\n| [AboutSecurity](https://github.com/wgpsec/AboutSecurity) | Structured pentest knowledge base (Skills, Dic, Payload, Vuln) |\n| [context1337](https://github.com/wgpsec/context1337) | MCP Server — turns AboutSecurity into a searchable API for AI agents |\n| [tchkiller](https://github.com/wgpsec/tchkiller) | Autonomous pentest agent with multi-round decision-making and team collaboration |\n| [benchmark-platform](https://github.com/wgpsec/benchmark-platform) | HunXiang CTF challenge platform for evaluating agent offensive capabilities |\n| [benchmark-challenges](https://github.com/wgpsec/benchmark-challenges) | Challenge data repository — packed & distributed via GitHub Releases |\n| PoJun | General-purpose AI problem-solving engine (private) |\n\n## References\n\n- https://github.com/anthropics/skills/blob/main/skills/skill-creator/SKILL.md\n- https://github.com/ljagiello/ctf-skills\n- https://github.com/JDArmy/Evasion-SubAgents\n- https://github.com/teamssix/twiki\n- https://github.com/yaklang/hack-skills\n- https://github.com/mukul975/Anthropic-Cybersecurity-Skills\n- https://github.com/Pa55w0rd/secknowledge-skill\n- https://github.com/0xShe/PHP-Code-Audit-Skill\n- https://github.com/RuoJi6/java-audit-skills\n- https://github.com/HackTricks-wiki/hacktricks\n- https://github.com/HackTricks-wiki/hacktricks-cloud\n- https://github.com/swisskyrepo/InternalAllTheThings\n",
  "bytes": 10935,
  "sha": "fb5ebcf74cb90961f61f64126cb6e4fddbf7fe67b897cb628a69339547ed9b67",
  "repo_slug": "wgpsec/aboutsecurity",
  "fonte": "repo",
  "truncated": false,
  "api": "https://api.agentalog.com/api/listings/skl_wgpsec_aboutsecurity_ad_acl_abuse_363df023/readme"
}