offensive-tools/forensic/stegseek/SKILL.md
Auth/lab ref: high-speed wordlist attacker for steghide-protected files. For you suspect a JPEG/BMP/WAV/AU artifact contains steghide data but extraction is blocked by a passphrase.
npx skillsauth add aeondave/malskill stegseekInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
The fast lane for steghide passphrase guessing.
Use Stegseek when you need to:
# Try a wordlist against a carrier
stegseek image.jpg rockyou.txt
steghide info or prior challenge hints before assuming the wordlist is the problem.No bundled scripts/, references/, or assets/.
Use the upstream project docs for extraction behavior, output handling, and troubleshooting.
development
White-box auditing methodology for AI-generated ('vibe-coded') applications. Focuses on modern stack misconfigurations (Supabase, Next.js, Vercel).
development
Hybrid AI/Deterministic SAST methodology for discovering zero-day vulnerabilities in source code. Orchestrates structural search with AI-driven data flow and sink validation.
development
Auth assessment: hardware/embedded methodology; UART/JTAG/SWD/SPI/I2C, firmware extraction, boot/debug paths, embedded OS evidence.
devops
Container methodology: Identifying containerization limits, Docker/K8s misconfigurations, and executing escapes to the host node.