
VAPT/AppSecおよびペネトレーションテストガイドの完全ソリューション: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST など...
完全で検索可能なペネトレーションテストの知識ベース。23のセキュリティドメインをカバー。
ライブウェブサイト · PentestingChecklist · コントリビュート · 問題を報告
オンラインで読む: pentesting.m14r41.in。完全検索可能、108のドキュメントページ、104のリファレンスPDF、23ドメインにわたる212以上のトピックを収録。このウェブサイトはリポジトリを高速で構造化された読みやすい知識ベースに変換します。
v2.0.0の新機能: プロジェクトは完全なウェブサイトになり、インスタント全文検索、フィルタ可能なリファレンスPDFライブラリ、一般的なエンゲージメントのラーニングパス、checklist.m14r41.inのコンパニオンチェックリストを備えています。詳細は変更履歴に記載。
PentestingEverything はオープンソースの包括的なペネトレーションテスト知識ベースです。方法論、チェックリスト、ペイロード、コマンド、および23のドメイン(Web、API、モバイル、ネットワーク、クラウド、Active Directory、OSINTなど)にわたる実戦で試されたリファレンスをまとめています。目標はシンプル: エンゲージメントのスコープ設定から特定の脆弱性クラスの調査、レポート作成まで、あらゆるターゲットを評価するための簡潔で実践的な知識を提供することです。
実用的なコンパニオン: PentestingChecklist. このプロジェクトは知識ベースです。チェックリストは実践的な、チェックしながら進めるコンパニオンです。23プラットフォーム(Web、API、モバイル、クラウド、ADなど)にわたる構造化されたチェックリストで、進捗追跡、メモ、エクスポート機能を備えています。これらを並行して使用してください。
ポータブルなAgent Skillをインストールすると、Cursorや他のコーディングエージェントからこの知識ベースを使用できます。回答をPentestingEverythingのMarkdownに基づかせ、スコープされたチェックリストを作成し、許可された評価のみのためのエビデンスベースのノートを下書きします。
対象者: バグハンター、セキュリティテスター、ペネトレーションテスターで、静的ドキュメントを閲覧するだけでなく、エージェントを通じて実際のエンゲージメントを実行する方。基本ルールにより自律的な使用を安全に保ちます: アクティブテスト前に認可を確認、高影響のアクションはゲート制御、発見事項は下書き前に誤検知チェックを通過、自動リクエストはプログラムのレート制限を尊重するペースで行われます。
インストール (プロジェクトローカル):
npx skills add m14r41/PentestingEverything --skill pentesting-everything
```
**グローバルにインストール**(すべてのプロジェクトで利用可能):```bash
npx skills add m14r41/PentestingEverything --skill pentesting-everything --global
```
**特定のクライアントをターゲットにする** (例):```bash
npx skills add m14r41/PentestingEverything --skill pentesting-everything --agent cursor
npx skills add m14r41/PentestingEverything --skill pentesting-everything --agent claude-code
```
**インストールせずに一覧表示:**```bash
npx skills add m14r41/PentestingEverything --list
```
スキルソース: [`.agents/skills/pentesting-everything/`](https://github.com/m14r41/PentestingEverything/tree/main/.agents/skills/pentesting-everything).
<details>
<summary><b>近日公開予定の新リソース!</b></summary>```python
Your ideas, suggestions, and contributions are always welcome!
```
- [ ] **新しいモジュール:** ペネトレーションテストにおけるAIの活用
</details>
<details>
<summary><b>最近更新されたコンテンツ : 2026</b></summary>
- [x] iOSペネトレーションテストモジュール
- [x] Androidペネトレーションテスト
- [x] APIペネトレーションテストモジュール
- [x] SAST / ソースコードレビュー
- [x] DevSecOps & SCA
- [x] シッククライアントペネトレーションテスト
- [x] OWASP Top 10:2025 Webアプリケーション
- [x] 脅威モデリング、設計レビュー、アイデアレビュー、アーキテクチャレビュー
- [x] 新しいモジュール : LLMs OWASP Top 10
- [x] 新しいモジュール : MCPペネトレーションテスト
- [x] 新しいモジュール : ファイアウォール(進行中)
</details>
<details>
<summary><b>改善と高度な技術</b></summary>
- [ ] SSLピンバイパスと悪用のためのさらなる方法
- [ ] iptablesと透過プロキシを使用したモバイルTCPトラフィックの傍受
- [ ] Fridaとオブジェクト分析による包括的な列挙
*(ローカルストレージ、クラス、メソッド、アクティビティ、サービス、インテント、レシーバーなど)*
- [ ] ADBとDrozerを使用したAndroidコンポーネントの悪用
- [ ] MobSFを超えた高度なSAST
</details>
<details>
<summary><b>現在探検中 & 協力募集中</b></summary>
> クラウドおよびエンタープライズインフラストラクチャのペネトレーションテストの専門家からの貢献と知識共有を歓迎します。
- クラウドペネトレーションテスト
- エンタープライズペネトレーションテスト(ネットワーク、ファイアウォール、WiFi & 設定レビュー)
</details>
<div align="right">
<details>
<summary >Language</summary>
<div>
<div align="right">
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=en">English</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=zh-CN">简体中文</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=zh-TW">繁體中文</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=ja">日本語</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=ko">한국어</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=hi">हिन्दी</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=th">ไทย</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=fr">Français</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=de">Deutsch</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=es">Español</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=it">Itapano</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=ru">Русский</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=pt">Português</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=nl">Nederlands</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=pl">Polski</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=ar">العربية</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=fa">فارسی</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=tr">Türkçe</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=vi">Tiếng Việt</a></p>
<p><a href="https://openaitx.github.io/view.html?user=m14r41&project=PentestingEverything&lang=id">Bahasa Indonesia</a></p>
</div>
</div>
</details>
</div>
## 0.1. 目次