Brayden Habets avatar

Brayden Habets

Community

@braydos-h · South Australia

7Followers
|
11Public Repos
|
131Published Skills

i break stuff, find out why, then fix it. :)

Skills Distribution
DomainCybersecurit...Web & API Penetrat.. (35%)Vulnerability Mana.. (20%)Red Teaming & Acti.. (20%)Threat Intelligenc.. (15%)

Agent Skills by Brayden Habets

Showing 131 vetted skills indexed across 1 GitHub repositories.

braydos-hbraydos-h
4

exploiting-broken-function-level-authorization

Tests APIs for Broken Function Level Authorization by probing admin endpoints with low-privilege credentials.

Community
Intermediate
braydos-hbraydos-h
4

implementing-epss-score-for-vulnerability-prioritization

Prioritize vulnerability remediation using FIRST EPSS exploitation probability scores and CVSS.

Community
Intermediate
braydos-hbraydos-h
4

scanning-infrastructure-with-nessus

Automates Nessus vulnerability scans and parses results into severity-ranked reports.

Community
Advanced
braydos-hbraydos-h
4

performing-jwt-none-algorithm-attack

Forge and test JWT none-algorithm tokens to detect signature verification bypass vulnerabilities.

Community
Intermediate
braydos-hbraydos-h
4

performing-service-account-audit

Audit service accounts across Active Directory, AWS, and Azure to flag orphaned and over-privileged accounts.

Community
Intermediate
braydos-hbraydos-h
4

performing-api-rate-limiting-bypass

Tests API rate limiting implementations for bypass vulnerabilities via header, path, and method manipulation.

Community
Intermediate
braydos-hbraydos-h
4

prioritizing-vulnerabilities-with-cvss-scoring

Prioritize vulnerabilities using CVSS scores, EPSS exploit probability, and CISA KEV data.

Community
Intermediate
braydos-hbraydos-h
4

performing-threat-modeling-with-owasp-threat-dragon

Create OWASP Threat Dragon data flow diagrams and apply STRIDE analysis to generate threat model reports.

Community
Intermediate
braydos-hbraydos-h
4

analyzing-api-gateway-access-logs

Detects BOLA, credential scanning, injection, and rate limit bypass in API gateway access logs.

Community
Intermediate
braydos-hbraydos-h
4

auditing-tls-certificate-transparency-logs

Monitors Certificate Transparency logs via crt.sh to detect unauthorized certificates and discover subdomains.

Community
Advanced
braydos-hbraydos-h
4

performing-subdomain-enumeration-with-subfinder

Enumerate subdomains with Subfinder and validate live hosts using httpx and dnsx.

Community
Intermediate
braydos-hbraydos-h
4

performing-security-headers-audit

Audit HTTP security headers and cookie attributes to identify missing browser-level protections.

Community
Intermediate
braydos-hbraydos-h
4

performing-web-application-scanning-with-nikto

Automates Nikto web server vulnerability scanning and generates severity-classified HTML and JSON reports.

Community
Intermediate
braydos-hbraydos-h
4

performing-agentless-vulnerability-scanning

Scan Linux, Windows, and cloud VMs for vulnerabilities via SSH, WinRM, and EBS snapshot analysis.

Community
Advanced
braydos-hbraydos-h
4

performing-asset-criticality-scoring-for-vulns

Score asset criticality with weighted factors and adjust vulnerability remediation SLAs by tier.

Community
Intermediate
braydos-hbraydos-h
4

performing-directory-traversal-testing

Tests web applications for path traversal and local file inclusion vulnerabilities using encoded payloads.

Community
Intermediate
braydos-hbraydos-h
4

exploiting-race-condition-vulnerabilities

Detect and exploit race condition vulnerabilities in web applications using Turbo Intruder single-packet attacks.

Community
Intermediate
braydos-hbraydos-h
4

performing-cve-prioritization-with-kev-catalog

Prioritize CVE remediation by cross-referencing CISA KEV, EPSS, and CVSS data.

Community
Intermediate
braydos-hbraydos-h
4

scanning-network-with-nmap-advanced

Performs Nmap network reconnaissance with NSE scripts, timing controls, and structured reporting.

Community
Intermediate
braydos-hbraydos-h
4

performing-graphql-depth-limit-attack

Tests GraphQL endpoints for depth limit vulnerabilities using nested, circular, and batched queries.

Community
Intermediate
braydos-hbraydos-h
4

performing-dns-enumeration-and-zone-transfer

Enumerates DNS records, attempts zone transfers, and brute-forces subdomains during authorized reconnaissance.

Community
Intermediate
braydos-hbraydos-h
4

performing-second-order-sql-injection

Detect and exploit second-order SQL injection by tracing stored payloads to unsafe query execution points.

Community
Intermediate
braydos-hbraydos-h
4

performing-api-security-testing-with-postman

Builds Postman collections and Newman pipelines to test APIs for OWASP API Security Top 10 vulnerabilities.

Community
Intermediate
braydos-hbraydos-h
4

attacking-domains-end-to-end

Orchestrates domain reconnaissance, subdomain enumeration, DNS analysis, and web exploitation across an authorized attack surface.

Community
Advanced

Frequently Asked Questions About Brayden Habets

FAQPage Schema
What tasks can I perform using braydos-h's skills?▼

The registry covers authorized security testing end-to-end: web and API penetration testing against OWASP Top 10 risks, vulnerability scanning with Nessus and OpenVAS, Active Directory exploitation, red team engagement planning, threat intelligence feed analysis, network forensics with Wireshark, and SBOM supply-chain assessment.

Who is the target audience for these skills?▼

Penetration testers, red team operators, SOC analysts, vulnerability management engineers, and threat intelligence analysts. Skills assume familiarity with frameworks like MITRE ATT&CK, NIST CSF, OWASP testing guides, and hands-on experience with Burp Suite, Metasploit, and BloodHound.

Are these skills free to use and under what license?▼

Yes. Nearly all skills in the manifest are published under the Apache-2.0 open-source license, permitting free use, modification, and redistribution. Many underlying scanners referenced, such as Nikto, OpenVAS, and sqlmap, are themselves open source.

What prerequisites do these skills require?▼

Skills expect authorized testing scope and access to the referenced security software: Burp Suite, Nmap, Metasploit, Nessus, BloodHound with SharpHound, Wireshark, sqlmap, and Postman. Several skills also require credentials for authenticated scanning or valid API keys for services like Shodan.

Do the skills map to compliance or detection frameworks?▼

Yes. Each skill's frontmatter maps to NIST CSF categories such as ID.RA-01 and DE.CM-01, plus MITRE ATT&CK technique IDs like T1190 and T1078. Selected skills also reference MITRE D3FEND countermeasures, NIST AI RMF, and ATLAS techniques for detection engineering alignment.