CtrlK
BlogDocsLog inGet started
Tessl Logo

Decepticon

github.com/PurpleAILAB/Decepticon

SkillAddedReview
wps-pixie-dust

packages/decepticon/decepticon/skills/standard/wireless/wps-pixie-dust/SKILL.md

WPS Pixie-Dust offline nonce attack (reaver -K / pixiewps) and fallback online PIN brute (bully) to recover the AP's WPA PSK without capturing a handshake.

63

wpa3-sae

packages/decepticon/decepticon/skills/standard/wireless/wpa3-sae/SKILL.md

WPA3-SAE transition-mode downgrade (DragonShift), SSID Confusion CVE-2023-52424, Dragonblood side-channels, and SAE captive-portal credential recovery against WPA3-Personal networks.

64

wpa2-psk

packages/decepticon/decepticon/skills/standard/wireless/wpa2-psk/SKILL.md

WPA/WPA2-PSK handshake capture via targeted deauth + PMKID (no deauth required) + offline hashcat cracking. The most common consumer/SMB encryption mode in 2026.

64

wpa-enterprise-eap

packages/decepticon/decepticon/skills/standard/wireless/wpa-enterprise-eap/SKILL.md

WPA/WPA2/WPA3-Enterprise (802.1X/EAP) rogue-RADIUS evil-twin for MSCHAPv2 capture, GTC downgrade, and PEAP relay. MSCHAPv2 capture equals a NetNTLM hash — the primary wireless on-ramp to Active Directory.

63

krack-fragattacks

packages/decepticon/decepticon/skills/standard/wireless/krack-fragattacks/SKILL.md

KRACK key-reinstallation (CVE-2017-13077..13082) and FragAttacks fragmentation/aggregation flaws (CVE-2020-24586..24588, CVE-2020-26139..26147) against legacy or embedded 802.11 supplicants with poor patch cadence.

61

evil-twin-karma

packages/decepticon/decepticon/skills/standard/wireless/evil-twin-karma/SKILL.md

Evil-twin rogue AP with KARMA/Mana PNL-probe response, captive-portal credential capture, and post-association MITM for PSK/open networks. Distinct from wpa-enterprise-eap which targets 802.1X.

63

deauth-pmf

packages/decepticon/decepticon/skills/standard/wireless/deauth-pmf/SKILL.md

Targeted and broadcast 802.11 deauthentication / disassociation, 802.11w/PMF posture detection, and action-frame attack variants. Reusable by wpa2-psk (handshake), wpa3-sae (downgrade), and evil-twin (roaming coercion).

64

wireless-overview

packages/decepticon/decepticon/skills/standard/wireless/SKILL.md

Top-level index for the Decepticon 802.11 wireless attack suite. Routes the WirelessOperator to the correct leaf skill based on the target AP's crypto column (PSK / SAE / MGT / WPS) and engagement posture. BLE, Zigbee, Z-Wave, LoRaWAN, and sub-GHz live under iot/ by design — link provided below to prevent duplication.

64

supply-chain-overview

packages/decepticon/decepticon/skills/standard/supply-chain/SKILL.md

Use when the engagement scope includes supply-chain attack simulation — typosquatted package publication, dependency confusion, GitHub Actions secret mining, internal mirror poisoning, OAuth-app impersonation, or vendor portal credential abuse.

59

emulation-volt-typhoon

packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/emulation/volt-typhoon/SKILL.md

Volt Typhoon (Vanguard Panda, PRC) adversary-emulation playbook — edge-device initial access, living-off-the-land-only operations, NTDS/credential theft, long-dwell pre-positioning toward critical infrastructure, multi-hop proxy egress. Use when emulating stealthy LOTL pre-positioning. Triggers on: 'emulate Volt Typhoon', 'Vanguard Panda', 'BRONZE SILHOUETTE', 'living off the land', 'edge device', 'pre-positioning', 'critical infrastructure persistence'.

73

emulation-scattered-spider

packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/emulation/scattered-spider/SKILL.md

Scattered Spider (UNC3944 / Octo Tempest) adversary-emulation playbook — help-desk vishing → MFA takeover → cloud/SaaS/identity privilege expansion → RMM persistence → data-theft extortion. Use when emulating identity-first social-engineering eCrime against a help-desk/IdP estate. Triggers on: 'emulate Scattered Spider', 'UNC3944', 'Octo Tempest', '0ktapus', 'help desk social engineering', 'MFA fatigue', 'SIM swap', 'identity attack'.

72

sandworm

packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/emulation/sandworm/SKILL.md

Sandworm (APT44 / Seashell Blizzard, GRU Unit 74455) adversary-emulation playbook — IT→OT intrusion ending in ICS manipulation or destructive impact, executed with living-off-the-land Windows tooling. SAFETY-CRITICAL: destructive and ICS-write steps are canary/lab-only and gated on explicit OT authorization. Use when emulating Sandworm against an ICS/OT or critical-infrastructure estate. Triggers on: 'emulate Sandworm', 'APT44', 'Seashell Blizzard', 'Voodoo Bear', 'ICS attack', 'OT destructive', 'Industroyer', 'NotPetya'.

75

lockbit

packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/emulation/lockbit/SKILL.md

LockBit / generic RaaS-affiliate adversary-emulation playbook — broker/edge/RDP initial access, beacon, AD compromise to Domain Admin, defense evasion (Defender-disable via GPO, shadow-copy deletion), bulk exfil, then canary double-extortion encryption (Windows + ESXi). Reusable template for any ransomware affiliate (ALPHV, Akira, Black Basta). Triggers on: 'emulate LockBit', 'ransomware affiliate', 'RaaS', 'double extortion', 'StealBit', 'domain-wide ransomware', 'ESXi locker'.

71

lazarus

packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/emulation/lazarus/SKILL.md

Lazarus Group (Hidden Cobra, DPRK RGB) adversary-emulation playbook — financially-motivated crypto/DeFi theft and supply-chain intrusion: fake-job social engineering, trojanized apps, wallet/key theft, and on-chain DeFi/bridge exploitation (testnet/fork only). Use when emulating DPRK financial actors against a crypto/exchange/DeFi target. Triggers on: 'emulate Lazarus', 'Hidden Cobra', 'DPRK crypto', 'AppleJeus', '3CX supply chain', 'DeFi bridge attack', 'crypto theft'.

73

fin7

packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/emulation/fin7/SKILL.md

FIN7 (Carbon Spider / Sangria Tempest) adversary-emulation playbook — revenue-targeted spearphishing with phone follow-up, EDR-evasion tradecraft, AD compromise, and big-game-hunting ransomware. Use when emulating a high-end financially-motivated crew that graduated from POS theft to ransomware. Triggers on: 'emulate FIN7', 'Carbanak', 'Carbon Spider', 'Sangria Tempest', 'big game hunting', 'EDR evasion', 'AvNeutralizer'.

71

apt29

packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/emulation/apt29/SKILL.md

APT29 (Cozy Bear / Midnight Blizzard, SVR) adversary-emulation playbook — malware-light cloud-identity espionage: no-MFA password spray, OAuth consent/token abuse, Golden SAML, mailbox collection over residential proxies. Use when emulating APT29 against an M365/Entra/AWS-identity estate. Triggers on: 'emulate APT29', 'Cozy Bear', 'Midnight Blizzard', 'NOBELIUM', 'OAuth abuse', 'cloud identity espionage', 'Golden SAML'.

71

emulation-overview

packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/emulation/SKILL.md

Adversary-emulation playbook catalog — per-actor kill chains that turn an APT/eCrime threat profile into Decepticon CONOPS phases + OPPLAN objectives. Routing skill: pick the actor, seed plan/threat-profile.json, then map each kill-chain phase to the operational skill the executing agent runs. Triggers on: 'emulate', 'adversary emulation', 'APT playbook', 'threat actor playbook', 'emulation plan', 'attack flow'.

67

threat-profile

packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/SKILL.md

Threat actor profiling for adversary emulation — APT group research, sophistication tiers, MITRE ATT&CK mapping, initial access vectors, custom archetypes.

60

structured-questions

packages/decepticon/decepticon/skills/standard/soundwave/structured-questions/SKILL.md

How to use ask_user_question — the single operator-input channel for every interview question, including free-form fields via allow_other=true.

59

roe-template

packages/decepticon/decepticon/skills/standard/soundwave/roe-template/SKILL.md

Rules of Engagement document creation — scope definition, prohibited/permitted actions, testing windows, escalation contacts, incident procedures.

61

opplan-converter

packages/decepticon/decepticon/skills/standard/soundwave/opplan-converter/SKILL.md

Convert engagement documents into machine-readable OPPLAN for the ralph loop — objective decomposition, acceptance criteria, MITRE mapping, priority ordering.

56

data-handling-template

packages/decepticon/decepticon/skills/standard/soundwave/data-handling-template/SKILL.md

Data handling plan generator — evidence retention, encryption, chain-of-custody, compliance frameworks (GDPR / HIPAA / PCI-DSS / SOC2).

65

contact-template

packages/decepticon/decepticon/skills/standard/soundwave/contact-template/SKILL.md

Contact / communications plan generator — primary operator, escalation chain, abort signal recipient, external SOC endpoint, blackout windows.

61

conops-template

packages/decepticon/decepticon/skills/standard/soundwave/conops-template/SKILL.md

Concept of Operations document creation — executive summary, threat actor profiling, attack narrative, kill chain design, communication plan, deconfliction.

61

cleanup-template

packages/decepticon/decepticon/skills/standard/soundwave/cleanup-template/SKILL.md

Cleanup & restoration plan generator — artifact inventory, persistence removal commands, pre-engagement baseline, post-engagement verification.

66