CtrlK
BlogDocsLog inGet started
Tessl Logo

Decepticon

github.com/PurpleAILAB/Decepticon

SkillAddedReview
ad-certipy-esc-chain

packages/decepticon/decepticon/skills/standard/ad/certipy-esc-chain/SKILL.md

ADCS abuse via Certipy — find vulnerable templates (ESC1-ESC15), request a certificate, authenticate as the target, dump the krbtgt. Full chain in 4 commands. Covers ESC1 (any SAN), ESC2 (any-purpose EKU), ESC3 (enrollment-agent), ESC4 (vulnerable ACL), ESC8 (NTLM relay to CA), ESC9/10/11/13.

63

bloodhound-query

packages/decepticon/decepticon/skills/standard/ad/bloodhound-query/SKILL.md

BloodHound ingestion + canonical Cypher queries for AD attack-path enumeration. Run after collector dumps zip; promotes findings into the knowledge graph.

66

bloodhound-bhce

packages/decepticon/decepticon/skills/standard/ad/bloodhound-bhce/SKILL.md

Operate BloodHound Community Edition v9.2.2 via Decepticon's bhce_* tools — health check, Cypher passthrough, SharpHound ZIP ingest. Replaces the in-house ingest + ESC* post-process pipeline per ADR-0005.

69

asrep-roasting

packages/decepticon/decepticon/skills/standard/ad/asrep-roasting/SKILL.md

Request AS-REP for accounts with DONT_REQ_PREAUTH set and crack offline — like kerberoast but no auth required.

60

adcs-esc1

packages/decepticon/decepticon/skills/standard/ad/adcs-esc1/SKILL.md

Exploit Active Directory Certificate Services ESC1 — vulnerable template allows arbitrary SAN, enabling user impersonation up to domain admin.

62

ad-overview

packages/decepticon/decepticon/skills/standard/ad/SKILL.md

Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction.

63

stealth-infra

packages/decepticon/decepticon/skills/shared/stealth-infra/SKILL.md

Anti-bot evasion, proxy rotation, credential retrieval from password managers, and stealth HTTP tooling for covert web operations.

52

references

packages/decepticon/decepticon/skills/shared/references/SKILL.md

External knowledge integration — HackerOne reports, PayloadsAllTheThings, Book of Secret Knowledge, CVE PoC corpora, bug bounty methodologies, and reference pentest agent architectures. Use these to calibrate, look up payloads, and accelerate research.

63

opsec

packages/decepticon/decepticon/skills/shared/opsec/SKILL.md

Operational security management — traffic shaping, scan rate limiting, source IP management, tool signature avoidance, evidence handling, anti-detection patterns.

57

finding-protocol

packages/decepticon/decepticon/skills/shared/finding-protocol/SKILL.md

Operational-tier finding template — minimal fields for sub-agent decision support. Heavyweight deliverable promotion lives in skills/decepticon/final-report.

56

defense-evasion

packages/decepticon/decepticon/skills/shared/defense-evasion/SKILL.md

Endpoint defense bypass — AMSI/ETW patching, ScareCrow framework, custom loaders, direct/indirect syscalls, LOLBAS execution, process injection.

61

volt-typhoon

packages/decepticon/decepticon/skills/shared/adversary-emulation/volt-typhoon/SKILL.md

Adversary-emulation profile for Volt Typhoon (G1017), a PRC state-sponsored actor pre-positioning in US critical infrastructure via living-off-the-land TTPs.

56

turla-venomous-bear

packages/decepticon/decepticon/skills/shared/adversary-emulation/turla/SKILL.md

Adversary-emulation profile for Turla (G0010 / Venomous Bear / Secret Blizzard / Waterbug / KRYPTON / Snake), Russia's FSB Center 16 cyber-espionage actor.

55

sidewinder-rattlesnake

packages/decepticon/decepticon/skills/shared/adversary-emulation/sidewinder/SKILL.md

Adversary-emulation profile for SideWinder (G0121 / Rattlesnake / T-APT-04 / Razor Tiger), India's suspected state-sponsored cyber-espionage actor.

55

scattered-spider

packages/decepticon/decepticon/skills/shared/adversary-emulation/scattered-spider/SKILL.md

Adversary-emulation profile for Scattered Spider (UNC3944/Octo Tempest), a financially motivated social-engineering-led intrusion group, mapped to ATT&CK G1015 and Decepticon tooling.

54

sandworm-team

packages/decepticon/decepticon/skills/shared/adversary-emulation/sandworm-team/SKILL.md

Adversary-emulation profile for Sandworm Team (Voodoo Bear / Seashell Blizzard / APT44 / ELECTRUM), Russia's GRU Unit 74455 destructive ICS/OT and influence actor (ATT&CK G0034).

60

salt-typhoon-earth-estries

packages/decepticon/decepticon/skills/shared/adversary-emulation/salt-typhoon/SKILL.md

Adversary-emulation profile for Salt Typhoon (G1045 / Earth Estries / GhostEmperor / FamousSparrow / UNC2286 / RedMike / OPERATOR PANDA), a PRC state-sponsored cyber-espionage actor targeting telecommunications and critical infrastructure worldwide.

56

pink-sandstorm-agrius

packages/decepticon/decepticon/skills/shared/adversary-emulation/pink-sandstorm/SKILL.md

Adversary-emulation profile for Pink Sandstorm (G1030 / Agrius / Agonizing Serpens / AMERICIUM / BlackShadow / DEV-0227), Iran's MOIS-linked destructive wiper and pseudo-ransomware operator.

58

patchwork-dropping-elephant

packages/decepticon/decepticon/skills/shared/adversary-emulation/patchwork/SKILL.md

Adversary-emulation profile for Patchwork (G0040 / Dropping Elephant / Chinastrats / MONSOON / Hangover Group / Operation Hangover), an India-linked cyber-espionage actor.

54

mustang-panda-bronze-president

packages/decepticon/decepticon/skills/shared/adversary-emulation/mustang-panda/SKILL.md

Adversary-emulation profile for Mustang Panda (G0129 / Bronze President / Stately Taurus / RedDelta / TA416 / TEMP.Hex), a China-based state-sponsored cyber-espionage actor operating since at least 2012.

52

muddywater-mango-sandstorm

packages/decepticon/decepticon/skills/shared/adversary-emulation/muddywater/SKILL.md

Adversary-emulation profile for MuddyWater (G0069 / Mercury / Mango Sandstorm / Static Kitten / TEMP.Zagros / Seedworm), Iran's MOIS cyber-espionage actor.

49

lazarus-group

packages/decepticon/decepticon/skills/shared/adversary-emulation/lazarus-group/SKILL.md

Adversary-emulation profile for Lazarus Group (G0032, aka Hidden Cobra / Diamond Sleet / Labyrinth Chollima), a North Korean RGB-linked actor conducting espionage, destructive, and financially motivated operations.

56

kimsuky-velvet-chollima

packages/decepticon/decepticon/skills/shared/adversary-emulation/kimsuky/SKILL.md

Adversary-emulation profile for Kimsuky (G0094 / Velvet Chollima / Emerald Sleet / THALLIUM / Black Banshee / APT43 / TA427), North Korea's RGB 63rd Research Center cyber-espionage actor.

52

fin7-carbanak

packages/decepticon/decepticon/skills/shared/adversary-emulation/fin7-carbanak/SKILL.md

Adversary-emulation profile for FIN7 (G0046; aka Carbanak, Carbon Spider, Sangria Tempest, GOLD NIAGARA, ELBRUS) — a financially motivated Russian-speaking crime group, mapping its TTPs to Decepticon tooling for authorized red-team emulation.

54

dark-caracal

packages/decepticon/decepticon/skills/shared/adversary-emulation/dark-caracal/SKILL.md

Adversary-emulation profile for Dark Caracal (G0070), a Lebanese state-linked cyber-espionage and surveillance actor attributed to the General Directorate of General Security (GDGS), operating since at least 2012.

54