attack-ssti
Server-Side Template Injection — detection, engine fingerprinting, and exploitation across 7 template engines
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Server-Side Template Injection — detection, engine fingerprinting, and exploitation across 7 template engines
Subdomain takeover — CNAME detection, cloud service fingerprinting, dangling DNS exploitation
WebSocket security testing — CSWSH, message injection, auth bypass, origin validation
Develop, document, and disseminate to [organization-defined]: [organization-defined] audit and accountability policy that: Procedures to facilitate th
Bind the identity of the information producer with the information to [organization-defined] ;
Maintain reviewer or releaser credentials within the established chain of custody for information reviewed or released.
Validate the binding of the information reviewer identity to the information at the transfer or release points prior to release or transfer between...
Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [organization-defined].
Retain audit records for [organization-defined] to provide support for after-the-fact investigations of incidents and to meet regulatory and organizat