NwN
Community@lnwnl
NwN publishes 145 offensive security playbooks covering web, API, binary, cloud, Active Directory, mobile, and cryptographic vulnerability testing.
Agent Skills by NwN
Showing 83 vetted skills indexed across 2 GitHub repositories.
nosql-injection
Tests NoSQL backends for operator injection, authentication bypass, and blind data extraction.
401-403-bypass-techniques
Tests 401 and 403 access controls using path, method, header, and protocol bypass techniques.
type-juggling
Exploit PHP loose comparison and magic hash collisions to bypass authentication checks.
jndi-injection
Guides JNDI injection testing against Java applications via RMI, LDAP, and Log4Shell vectors.
request-smuggling
Tests HTTP request smuggling and desynchronization between proxies, CDNs, and origin servers.
expression-language-injection
Detects and exploits Expression Language injection in SpEL, OGNL, and Java EL frameworks.
race-condition
Tests web applications for race conditions and TOCTOU flaws using parallel HTTP request techniques.
cors-cross-origin-misconfiguration
Tests CORS configurations for origin reflection, credential exposure, and allowlist bypass vulnerabilities.
csp-bypass-advanced
Analyzes Content Security Policy configurations to identify bypass vectors and exfiltration channels.
business-logic-vulnerabilities
Tests web applications for business logic flaws including race conditions, price manipulation, and workflow bypass.
http-host-header-attacks
Tests HTTP Host header injection for password reset poisoning, cache poisoning, SSRF, and virtual host bypass.
defi-attack-patterns
Analyzes DeFi protocols for flash loan, oracle manipulation, MEV, and governance attack vectors.
mobile-ssl-pinning-bypass
Bypass SSL certificate pinning on Android and iOS apps using Frida, Objection, and repackaging techniques.
android-pentesting-tricks
Tests Android applications for SSL pinning, exported components, WebView flaws, and root detection weaknesses.
subdomain-takeover
Detects and exploits dangling DNS records enabling subdomain takeover across cloud providers.
http-parameter-pollution
Tests duplicate HTTP parameters to exploit parser disagreements across WAFs, proxies, and frameworks.
xslt-injection
Tests XSLT injection endpoints through processor fingerprinting, XXE, document() SSRF, and extension-based RCE.
email-header-injection
Tests email-sending features for SMTP CRLF header injection and SPF/DKIM/DMARC spoofing weaknesses.
file-access-vuln
Routes file access and upload vulnerability testing to specialized workflow skills.
dependency-confusion
Detect dependency confusion risks where internal package names resolve to public registries.
injection-checking
Routes injection testing workflows to specialized skills based on input sink type.
prototype-pollution
Tests JavaScript applications for prototype pollution via __proto__ and constructor.prototype injection paths.
unauthorized-access-common-services
Exploit exposed unauthenticated management services using port-scoped attack playbooks.
saml-sso-assertion-attacks
Tests SAML SSO assertions for signature validation, wrapping, and trust boundary flaws.
Frequently Asked Questions About NwN
FAQPage SchemaWhat tasks can I perform using NwN's skills?▼
You can execute structured offensive security playbooks: detect and exploit SQLi, XSS, SSRF, XXE, SSTI, and command injection; escalate privileges on Linux and Windows; attack Active Directory via Kerberos and AD CS; reverse binaries with symbolic execution; analyze PCAP and memory dumps; and test mobile, Kubernetes, and smart contract targets.
Who are NwN's skills designed for?▼
The skills target penetration testers, bug bounty hunters, red team operators, and CTF players. Entry-level P0/P1 router skills like hack, api-sec, and auth-sec guide testers to the correct deep playbook, while advanced skills cover heap exploitation, V8 browser exploitation, and lattice cryptanalysis for specialists.
How do NwN's skills work in practice?▼
Each skill is a decision-driven playbook: router skills classify the observed target signals (endpoint behavior, input sinks, error responses) and route to a topic playbook containing concrete payloads, fingerprinting probes, and exploitation steps, such as polyglot SSTI probes or DBMS-specific UNION and time-based SQLi techniques.
What prerequisites do NwN's skills assume?▼
Prerequisites vary by playbook: binary skills assume glibc/ELF knowledge and debuggers; forensics skills require Volatility 2/3 or Wireshark/tshark; symbolic execution skills use angr, Z3, and Unicorn; Active Directory skills assume domain access and BloodHound output. All skills are scoped to authorized testing engagements.
Do NwN's skills cover cloud and container environments?▼
Yes. Dedicated playbooks cover Kubernetes penetration testing (RBAC enumeration, etcd access, pod escape), Docker and LXC container escapes via privileged mode and cgroup abuse, subdomain takeover of deprovisioned cloud resources, and SSRF against cloud metadata endpoints.