CtrlK
BlogDocsLog inGet started
Tessl Logo

Decepticon

github.com/PurpleAILAB/Decepticon

SkillAddedReview
windows-driver-assessment

packages/decepticon/decepticon/skills/standard/reverser/windows-internals/SKILL.md

Defensive Windows internals and driver exposure assessment for owner-authorized systems and disposable research VMs.

61

wireless-overview

packages/decepticon/decepticon/skills/standard/wireless/SKILL.md

Top-level index for the Decepticon 802.11 wireless attack suite. Routes the WirelessOperator to the correct leaf skill based on the target AP's crypto column (PSK / SAE / MGT / WPS) and engagement posture. BLE, Zigbee, Z-Wave, LoRaWAN, and sub-GHz live under iot/ by design — link provided below to prevent duplication.

64

wireless-security

packages/decepticon/decepticon/skills/standard/recon/wireless-security/SKILL.md

Wireless network security reconnaissance — WiFi analysis, Bluetooth assessment, RFID/NFC evaluation, signal capture, protocol analysis, encryption testing, rogue device detection.

54

wpa2-psk

packages/decepticon/decepticon/skills/standard/wireless/wpa2-psk/SKILL.md

WPA/WPA2-PSK handshake capture via targeted deauth + PMKID (no deauth required) + offline hashcat cracking. The most common consumer/SMB encryption mode in 2026.

64

wpa3-sae

packages/decepticon/decepticon/skills/standard/wireless/wpa3-sae/SKILL.md

WPA3-SAE transition-mode downgrade (DragonShift), SSID Confusion CVE-2023-52424, Dragonblood side-channels, and SAE captive-portal credential recovery against WPA3-Personal networks.

64

wpa-enterprise-eap

packages/decepticon/decepticon/skills/standard/wireless/wpa-enterprise-eap/SKILL.md

WPA/WPA2/WPA3-Enterprise (802.1X/EAP) rogue-RADIUS evil-twin for MSCHAPv2 capture, GTC downgrade, and PEAP relay. MSCHAPv2 capture equals a NetNTLM hash — the primary wireless on-ramp to Active Directory.

63

wps-pixie-dust

packages/decepticon/decepticon/skills/standard/wireless/wps-pixie-dust/SKILL.md

WPS Pixie-Dust offline nonce attack (reaver -K / pixiewps) and fallback online PIN brute (bully) to recover the AP's WPA PSK without capturing a handshake.

63

xpath-xslt

packages/decepticon/decepticon/skills/standard/exploit/web/xpath-xslt/SKILL.md

XPath + XSLT injection — query manipulation in XML data stores, server-side XSLT RCE via document() / EXSLT extensions.

60

xs-leaks

packages/decepticon/decepticon/skills/standard/exploit/web/xs-leaks/SKILL.md

XS-Leaks — cross-site information leaks via timing, frame counting, navigation, error oracles. Side-channel attacks against same-origin authenticated state.

60

xss

packages/decepticon/decepticon/skills/standard/exploit/web/xss/SKILL.md

Cross-Site Scripting (XSS) — reflected, stored, DOM-based XSS exploitation. Covers filter bypass, CSP evasion, bot-triggered cookie exfiltration, admin page scraping, and headless browser flag extraction. Use for any challenge involving client-side JavaScript injection, Cross payloads, cookie theft, or browser-based exploitation.

71

xxe

packages/decepticon/decepticon/skills/standard/analyst/xxe/SKILL.md

Hunt XML External Entity flaws in parsers and validate file read / SSRF impact with strict negative controls.

57

zigbee-touchlink

packages/decepticon/decepticon/skills/standard/iot/zigbee-touchlink/SKILL.md

Touchlink commissioning abuse on Zigbee Light Link (ZLL) devices using the well-known ZLL transport key, ZCL command injection (toggle/move/step), network key extraction, and factory reset via touchlink. Toolchain covers KillerBee, zbstumbler, zbreplay, and Sonoff Zigbee 3.0 Dongle E running Wireshark live capture.

60

z-wave

packages/decepticon/decepticon/skills/standard/iot/z-wave/SKILL.md

Z-Wave S0 network-key derivation flaw exploitation, S2 ECDH/DSK analysis, replay attacks against unauthenticated Z-Wave nodes, traffic capture with RTL-SDR, and active fuzzing/replay with EZ-Wave and Z-Force. Covers 868.42 MHz (EU) and 908.42 MHz (US) bands.

62