github.com/PurpleAILAB/Decepticon
| Skill | Added | Review |
|---|---|---|
wps-pixie-dust packages/decepticon/decepticon/skills/standard/wireless/wps-pixie-dust/SKILL.md WPS Pixie-Dust offline nonce attack (reaver -K / pixiewps) and fallback online PIN brute (bully) to recover the AP's WPA PSK without capturing a handshake. | 63 63 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
wpa3-sae packages/decepticon/decepticon/skills/standard/wireless/wpa3-sae/SKILL.md WPA3-SAE transition-mode downgrade (DragonShift), SSID Confusion CVE-2023-52424, Dragonblood side-channels, and SAE captive-portal credential recovery against WPA3-Personal networks. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
wpa2-psk packages/decepticon/decepticon/skills/standard/wireless/wpa2-psk/SKILL.md WPA/WPA2-PSK handshake capture via targeted deauth + PMKID (no deauth required) + offline hashcat cracking. The most common consumer/SMB encryption mode in 2026. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
wpa-enterprise-eap packages/decepticon/decepticon/skills/standard/wireless/wpa-enterprise-eap/SKILL.md WPA/WPA2/WPA3-Enterprise (802.1X/EAP) rogue-RADIUS evil-twin for MSCHAPv2 capture, GTC downgrade, and PEAP relay. MSCHAPv2 capture equals a NetNTLM hash — the primary wireless on-ramp to Active Directory. | 63 63 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
krack-fragattacks packages/decepticon/decepticon/skills/standard/wireless/krack-fragattacks/SKILL.md KRACK key-reinstallation (CVE-2017-13077..13082) and FragAttacks fragmentation/aggregation flaws (CVE-2020-24586..24588, CVE-2020-26139..26147) against legacy or embedded 802.11 supplicants with poor patch cadence. | 61 61 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
evil-twin-karma packages/decepticon/decepticon/skills/standard/wireless/evil-twin-karma/SKILL.md Evil-twin rogue AP with KARMA/Mana PNL-probe response, captive-portal credential capture, and post-association MITM for PSK/open networks. Distinct from wpa-enterprise-eap which targets 802.1X. | 63 63 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
deauth-pmf packages/decepticon/decepticon/skills/standard/wireless/deauth-pmf/SKILL.md Targeted and broadcast 802.11 deauthentication / disassociation, 802.11w/PMF posture detection, and action-frame attack variants. Reusable by wpa2-psk (handshake), wpa3-sae (downgrade), and evil-twin (roaming coercion). | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
wireless-overview packages/decepticon/decepticon/skills/standard/wireless/SKILL.md Top-level index for the Decepticon 802.11 wireless attack suite. Routes the WirelessOperator to the correct leaf skill based on the target AP's crypto column (PSK / SAE / MGT / WPS) and engagement posture. BLE, Zigbee, Z-Wave, LoRaWAN, and sub-GHz live under iot/ by design — link provided below to prevent duplication. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
supply-chain-overview packages/decepticon/decepticon/skills/standard/supply-chain/SKILL.md Use when the engagement scope includes supply-chain attack simulation — typosquatted package publication, dependency confusion, GitHub Actions secret mining, internal mirror poisoning, OAuth-app impersonation, or vendor portal credential abuse. | 59 59 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
emulation-volt-typhoon packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/emulation/volt-typhoon/SKILL.md Volt Typhoon (Vanguard Panda, PRC) adversary-emulation playbook — edge-device initial access, living-off-the-land-only operations, NTDS/credential theft, long-dwell pre-positioning toward critical infrastructure, multi-hop proxy egress. Use when emulating stealthy LOTL pre-positioning. Triggers on: 'emulate Volt Typhoon', 'Vanguard Panda', 'BRONZE SILHOUETTE', 'living off the land', 'edge device', 'pre-positioning', 'critical infrastructure persistence'. | 73 73 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
emulation-scattered-spider packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/emulation/scattered-spider/SKILL.md Scattered Spider (UNC3944 / Octo Tempest) adversary-emulation playbook — help-desk vishing → MFA takeover → cloud/SaaS/identity privilege expansion → RMM persistence → data-theft extortion. Use when emulating identity-first social-engineering eCrime against a help-desk/IdP estate. Triggers on: 'emulate Scattered Spider', 'UNC3944', 'Octo Tempest', '0ktapus', 'help desk social engineering', 'MFA fatigue', 'SIM swap', 'identity attack'. | 72 72 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
sandworm packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/emulation/sandworm/SKILL.md Sandworm (APT44 / Seashell Blizzard, GRU Unit 74455) adversary-emulation playbook — IT→OT intrusion ending in ICS manipulation or destructive impact, executed with living-off-the-land Windows tooling. SAFETY-CRITICAL: destructive and ICS-write steps are canary/lab-only and gated on explicit OT authorization. Use when emulating Sandworm against an ICS/OT or critical-infrastructure estate. Triggers on: 'emulate Sandworm', 'APT44', 'Seashell Blizzard', 'Voodoo Bear', 'ICS attack', 'OT destructive', 'Industroyer', 'NotPetya'. | 75 75 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
lockbit packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/emulation/lockbit/SKILL.md LockBit / generic RaaS-affiliate adversary-emulation playbook — broker/edge/RDP initial access, beacon, AD compromise to Domain Admin, defense evasion (Defender-disable via GPO, shadow-copy deletion), bulk exfil, then canary double-extortion encryption (Windows + ESXi). Reusable template for any ransomware affiliate (ALPHV, Akira, Black Basta). Triggers on: 'emulate LockBit', 'ransomware affiliate', 'RaaS', 'double extortion', 'StealBit', 'domain-wide ransomware', 'ESXi locker'. | 71 71 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
lazarus packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/emulation/lazarus/SKILL.md Lazarus Group (Hidden Cobra, DPRK RGB) adversary-emulation playbook — financially-motivated crypto/DeFi theft and supply-chain intrusion: fake-job social engineering, trojanized apps, wallet/key theft, and on-chain DeFi/bridge exploitation (testnet/fork only). Use when emulating DPRK financial actors against a crypto/exchange/DeFi target. Triggers on: 'emulate Lazarus', 'Hidden Cobra', 'DPRK crypto', 'AppleJeus', '3CX supply chain', 'DeFi bridge attack', 'crypto theft'. | 73 73 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
fin7 packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/emulation/fin7/SKILL.md FIN7 (Carbon Spider / Sangria Tempest) adversary-emulation playbook — revenue-targeted spearphishing with phone follow-up, EDR-evasion tradecraft, AD compromise, and big-game-hunting ransomware. Use when emulating a high-end financially-motivated crew that graduated from POS theft to ransomware. Triggers on: 'emulate FIN7', 'Carbanak', 'Carbon Spider', 'Sangria Tempest', 'big game hunting', 'EDR evasion', 'AvNeutralizer'. | 71 71 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
apt29 packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/emulation/apt29/SKILL.md APT29 (Cozy Bear / Midnight Blizzard, SVR) adversary-emulation playbook — malware-light cloud-identity espionage: no-MFA password spray, OAuth consent/token abuse, Golden SAML, mailbox collection over residential proxies. Use when emulating APT29 against an M365/Entra/AWS-identity estate. Triggers on: 'emulate APT29', 'Cozy Bear', 'Midnight Blizzard', 'NOBELIUM', 'OAuth abuse', 'cloud identity espionage', 'Golden SAML'. | 71 71 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
emulation-overview packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/emulation/SKILL.md Adversary-emulation playbook catalog — per-actor kill chains that turn an APT/eCrime threat profile into Decepticon CONOPS phases + OPPLAN objectives. Routing skill: pick the actor, seed plan/threat-profile.json, then map each kill-chain phase to the operational skill the executing agent runs. Triggers on: 'emulate', 'adversary emulation', 'APT playbook', 'threat actor playbook', 'emulation plan', 'attack flow'. | 67 67 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
threat-profile packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/SKILL.md Threat actor profiling for adversary emulation — APT group research, sophistication tiers, MITRE ATT&CK mapping, initial access vectors, custom archetypes. | 60 60 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
structured-questions packages/decepticon/decepticon/skills/standard/soundwave/structured-questions/SKILL.md How to use ask_user_question — the single operator-input channel for every interview question, including free-form fields via allow_other=true. | 59 59 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 0cf691e | |
roe-template packages/decepticon/decepticon/skills/standard/soundwave/roe-template/SKILL.md Rules of Engagement document creation — scope definition, prohibited/permitted actions, testing windows, escalation contacts, incident procedures. | 61 61 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 0cf691e | |
opplan-converter packages/decepticon/decepticon/skills/standard/soundwave/opplan-converter/SKILL.md Convert engagement documents into machine-readable OPPLAN for the ralph loop — objective decomposition, acceptance criteria, MITRE mapping, priority ordering. | 56 56 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
data-handling-template packages/decepticon/decepticon/skills/standard/soundwave/data-handling-template/SKILL.md Data handling plan generator — evidence retention, encryption, chain-of-custody, compliance frameworks (GDPR / HIPAA / PCI-DSS / SOC2). | 65 65 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 0cf691e | |
contact-template packages/decepticon/decepticon/skills/standard/soundwave/contact-template/SKILL.md Contact / communications plan generator — primary operator, escalation chain, abort signal recipient, external SOC endpoint, blackout windows. | 61 61 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 0cf691e | |
conops-template packages/decepticon/decepticon/skills/standard/soundwave/conops-template/SKILL.md Concept of Operations document creation — executive summary, threat actor profiling, attack narrative, kill chain design, communication plan, deconfliction. | 61 61 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
cleanup-template packages/decepticon/decepticon/skills/standard/soundwave/cleanup-template/SKILL.md Cleanup & restoration plan generator — artifact inventory, persistence removal commands, pre-engagement baseline, post-engagement verification. | 66 66 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e |