github.com/PurpleAILAB/Decepticon
| Skill | Added | Review |
|---|---|---|
ad-certipy-esc-chain packages/decepticon/decepticon/skills/standard/ad/certipy-esc-chain/SKILL.md ADCS abuse via Certipy — find vulnerable templates (ESC1-ESC15), request a certificate, authenticate as the target, dump the krbtgt. Full chain in 4 commands. Covers ESC1 (any SAN), ESC2 (any-purpose EKU), ESC3 (enrollment-agent), ESC4 (vulnerable ACL), ESC8 (NTLM relay to CA), ESC9/10/11/13. | 63 63 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
bloodhound-query packages/decepticon/decepticon/skills/standard/ad/bloodhound-query/SKILL.md BloodHound ingestion + canonical Cypher queries for AD attack-path enumeration. Run after collector dumps zip; promotes findings into the knowledge graph. | 66 66 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
bloodhound-bhce packages/decepticon/decepticon/skills/standard/ad/bloodhound-bhce/SKILL.md Operate BloodHound Community Edition v9.2.2 via Decepticon's bhce_* tools — health check, Cypher passthrough, SharpHound ZIP ingest. Replaces the in-house ingest + ESC* post-process pipeline per ADR-0005. | 69 69 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
asrep-roasting packages/decepticon/decepticon/skills/standard/ad/asrep-roasting/SKILL.md Request AS-REP for accounts with DONT_REQ_PREAUTH set and crack offline — like kerberoast but no auth required. | 60 60 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
adcs-esc1 packages/decepticon/decepticon/skills/standard/ad/adcs-esc1/SKILL.md Exploit Active Directory Certificate Services ESC1 — vulnerable template allows arbitrary SAN, enabling user impersonation up to domain admin. | 62 62 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
ad-overview packages/decepticon/decepticon/skills/standard/ad/SKILL.md Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction. | 63 63 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
stealth-infra packages/decepticon/decepticon/skills/shared/stealth-infra/SKILL.md Anti-bot evasion, proxy rotation, credential retrieval from password managers, and stealth HTTP tooling for covert web operations. | 52 52 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
references packages/decepticon/decepticon/skills/shared/references/SKILL.md External knowledge integration — HackerOne reports, PayloadsAllTheThings, Book of Secret Knowledge, CVE PoC corpora, bug bounty methodologies, and reference pentest agent architectures. Use these to calibrate, look up payloads, and accelerate research. | 63 63 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 0cf691e | |
opsec packages/decepticon/decepticon/skills/shared/opsec/SKILL.md Operational security management — traffic shaping, scan rate limiting, source IP management, tool signature avoidance, evidence handling, anti-detection patterns. | 57 57 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 0cf691e | |
finding-protocol packages/decepticon/decepticon/skills/shared/finding-protocol/SKILL.md Operational-tier finding template — minimal fields for sub-agent decision support. Heavyweight deliverable promotion lives in skills/decepticon/final-report. | 56 56 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 0cf691e | |
defense-evasion packages/decepticon/decepticon/skills/shared/defense-evasion/SKILL.md Endpoint defense bypass — AMSI/ETW patching, ScareCrow framework, custom loaders, direct/indirect syscalls, LOLBAS execution, process injection. | 61 61 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
volt-typhoon packages/decepticon/decepticon/skills/shared/adversary-emulation/volt-typhoon/SKILL.md Adversary-emulation profile for Volt Typhoon (G1017), a PRC state-sponsored actor pre-positioning in US critical infrastructure via living-off-the-land TTPs. | 56 56 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
turla-venomous-bear packages/decepticon/decepticon/skills/shared/adversary-emulation/turla/SKILL.md Adversary-emulation profile for Turla (G0010 / Venomous Bear / Secret Blizzard / Waterbug / KRYPTON / Snake), Russia's FSB Center 16 cyber-espionage actor. | 55 55 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
sidewinder-rattlesnake packages/decepticon/decepticon/skills/shared/adversary-emulation/sidewinder/SKILL.md Adversary-emulation profile for SideWinder (G0121 / Rattlesnake / T-APT-04 / Razor Tiger), India's suspected state-sponsored cyber-espionage actor. | 55 55 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
scattered-spider packages/decepticon/decepticon/skills/shared/adversary-emulation/scattered-spider/SKILL.md Adversary-emulation profile for Scattered Spider (UNC3944/Octo Tempest), a financially motivated social-engineering-led intrusion group, mapped to ATT&CK G1015 and Decepticon tooling. | 54 54 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
sandworm-team packages/decepticon/decepticon/skills/shared/adversary-emulation/sandworm-team/SKILL.md Adversary-emulation profile for Sandworm Team (Voodoo Bear / Seashell Blizzard / APT44 / ELECTRUM), Russia's GRU Unit 74455 destructive ICS/OT and influence actor (ATT&CK G0034). | 60 60 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
salt-typhoon-earth-estries packages/decepticon/decepticon/skills/shared/adversary-emulation/salt-typhoon/SKILL.md Adversary-emulation profile for Salt Typhoon (G1045 / Earth Estries / GhostEmperor / FamousSparrow / UNC2286 / RedMike / OPERATOR PANDA), a PRC state-sponsored cyber-espionage actor targeting telecommunications and critical infrastructure worldwide. | 56 56 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
pink-sandstorm-agrius packages/decepticon/decepticon/skills/shared/adversary-emulation/pink-sandstorm/SKILL.md Adversary-emulation profile for Pink Sandstorm (G1030 / Agrius / Agonizing Serpens / AMERICIUM / BlackShadow / DEV-0227), Iran's MOIS-linked destructive wiper and pseudo-ransomware operator. | 58 58 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
patchwork-dropping-elephant packages/decepticon/decepticon/skills/shared/adversary-emulation/patchwork/SKILL.md Adversary-emulation profile for Patchwork (G0040 / Dropping Elephant / Chinastrats / MONSOON / Hangover Group / Operation Hangover), an India-linked cyber-espionage actor. | 54 54 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
mustang-panda-bronze-president packages/decepticon/decepticon/skills/shared/adversary-emulation/mustang-panda/SKILL.md Adversary-emulation profile for Mustang Panda (G0129 / Bronze President / Stately Taurus / RedDelta / TA416 / TEMP.Hex), a China-based state-sponsored cyber-espionage actor operating since at least 2012. | 52 52 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
muddywater-mango-sandstorm packages/decepticon/decepticon/skills/shared/adversary-emulation/muddywater/SKILL.md Adversary-emulation profile for MuddyWater (G0069 / Mercury / Mango Sandstorm / Static Kitten / TEMP.Zagros / Seedworm), Iran's MOIS cyber-espionage actor. | 49 49 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
lazarus-group packages/decepticon/decepticon/skills/shared/adversary-emulation/lazarus-group/SKILL.md Adversary-emulation profile for Lazarus Group (G0032, aka Hidden Cobra / Diamond Sleet / Labyrinth Chollima), a North Korean RGB-linked actor conducting espionage, destructive, and financially motivated operations. | 56 56 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
kimsuky-velvet-chollima packages/decepticon/decepticon/skills/shared/adversary-emulation/kimsuky/SKILL.md Adversary-emulation profile for Kimsuky (G0094 / Velvet Chollima / Emerald Sleet / THALLIUM / Black Banshee / APT43 / TA427), North Korea's RGB 63rd Research Center cyber-espionage actor. | 52 52 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
fin7-carbanak packages/decepticon/decepticon/skills/shared/adversary-emulation/fin7-carbanak/SKILL.md Adversary-emulation profile for FIN7 (G0046; aka Carbanak, Carbon Spider, Sangria Tempest, GOLD NIAGARA, ELBRUS) — a financially motivated Russian-speaking crime group, mapping its TTPs to Decepticon tooling for authorized red-team emulation. | 54 54 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
dark-caracal packages/decepticon/decepticon/skills/shared/adversary-emulation/dark-caracal/SKILL.md Adversary-emulation profile for Dark Caracal (G0070), a Lebanese state-linked cyber-espionage and surveillance actor attributed to the General Directorate of General Security (GDGS), operating since at least 2012. | 54 54 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e |