github.com/PurpleAILAB/Decepticon
| Skill | Added | Review |
|---|---|---|
ad-coercer packages/decepticon/decepticon/skills/standard/ad/coercer/SKILL.md Authentication coercion against Windows / AD — PetitPotam (MS-EFSR), PrinterBug (MS-RPRN), DFSCoerce (MS-DFSNM), ShadowCoerce (MS-FSRVP), Coercer.py meta-tool. Force a Windows machine to NTLM-authenticate to attacker, then relay or crack offline. | 63 63 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
adcs-esc1 packages/decepticon/decepticon/skills/standard/ad/adcs-esc1/SKILL.md Exploit Active Directory Certificate Services ESC1 — vulnerable template allows arbitrary SAN, enabling user impersonation up to domain admin. | 62 62 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
ad-ntlm-relay packages/decepticon/decepticon/skills/standard/ad/ntlm-relay/SKILL.md NTLM relay deep-dive — `ntlmrelayx` configuration matrix (SMB, LDAP, LDAPS, HTTP, RPC, IMAP, MSSQL), SMB-signing bypass, target selection (DC for DCSync, ADCS for cert, LAPS reader for cleartext), session relay vs cracking trade-off, multi-relay (forward auth from one victim to many). | 63 63 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
ad-overview packages/decepticon/decepticon/skills/standard/ad/SKILL.md Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction. | 63 63 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
adversarial-ml-evasion packages/decepticon/decepticon/skills/standard/analyst/adversarial-ml-evasion/SKILL.md Craft adversarial examples that cause trained ML classifiers to misclassify at inference time — image recognition, malware detectors, IDS, spam filters. | 62 62 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
adversary-emulation packages/decepticon/decepticon/skills/shared/adversary-emulation/SKILL.md Threat-informed adversary emulation — pick a real APT, load its profile, and reproduce its TTPs within RoE scope to test detection & response. Index of available actor profiles + the emulation methodology. | 60 60 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
analyst-overview packages/decepticon/decepticon/skills/standard/analyst/SKILL.md Root pointer for the analyst's vulnerability research playbooks. Load this first at iteration start to see the full catalog of vuln-class and chain-building skills. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
anti-debug-bypass packages/decepticon/decepticon/skills/standard/reverser/anti-debug-bypass/SKILL.md Detect and neutralize anti-debug / anti-VM checks — IsDebuggerPresent, ptrace, NtGlobalFlag, timing, hardware-breakpoint detection. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
api-grpc packages/decepticon/decepticon/skills/standard/exploit/api/grpc/SKILL.md gRPC API exploitation — reflection-based discovery via grpcurl, protobuf fuzzing, missing authz on streaming RPCs, gRPC-Web → backend SSRF, mTLS bypass, metadata header injection, h2c smuggling against gRPC fronts. | 67 67 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
api-overview packages/decepticon/decepticon/skills/standard/exploit/api/SKILL.md Modern API category — gRPC, SOAP/WSDL, WebSocket, Server-Sent Events. Routing skill: identify the API protocol from the response Content-Type or wire format, then load the matching sub-skill. | 60 60 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
api-server-sent-events packages/decepticon/decepticon/skills/standard/exploit/api/server-sent-events/SKILL.md Server-Sent Events (SSE / EventSource) exploitation — origin abuse for cross-site streaming exfil, prompt-injection via SSE messages into LLM clients, retry-after token leak, fragmenting events to bypass content-type sniffers. | 60 60 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
api-soap-wsdl packages/decepticon/decepticon/skills/standard/exploit/api/soap-wsdl/SKILL.md SOAP / WSDL exploitation — WSDL enumeration via ?wsdl, XXE in SOAP envelope, WS-Addressing replay, WS-Security UsernameToken brute, SAML token injection in WS-Trust, schema validation bypass. | 60 60 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
api-websocket packages/decepticon/decepticon/skills/standard/exploit/api/websocket/SKILL.md WebSocket exploitation — origin-bypass (CSWSH cross-site WebSocket hijacking), missing per-message auth, message-type confusion, msg-flood DoS, ws→wss downgrade, hidden RPC routes in the WS frame layer. | 63 63 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
apt10-stone-panda packages/decepticon/decepticon/skills/shared/adversary-emulation/apt10-stone-panda/SKILL.md Adversary-emulation profile for APT10 (G0045 / Stone Panda / menuPass / POTASSIUM / Red Apollo / CVNX), China's MSS Tianjin State Security Bureau cyber-espionage actor. | 59 59 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
apt28-fancy-bear packages/decepticon/decepticon/skills/shared/adversary-emulation/apt28-fancy-bear/SKILL.md Adversary-emulation profile for APT28 (G0007 / Fancy Bear / Forest Blizzard / Sofacy / STRONTIUM), Russia's GRU Unit 26165 cyber-espionage actor. | 56 56 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
apt29 packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/emulation/apt29/SKILL.md APT29 (Cozy Bear / Midnight Blizzard, SVR) adversary-emulation playbook — malware-light cloud-identity espionage: no-MFA password spray, OAuth consent/token abuse, Golden SAML, mailbox collection over residential proxies. Use when emulating APT29 against an M365/Entra/AWS-identity estate. Triggers on: 'emulate APT29', 'Cozy Bear', 'Midnight Blizzard', 'NOBELIUM', 'OAuth abuse', 'cloud identity espionage', 'Golden SAML'. | 71 71 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
apt29-cozy-bear packages/decepticon/decepticon/skills/shared/adversary-emulation/apt29-cozy-bear/SKILL.md Adversary-emulation profile for APT29 (Cozy Bear / Midnight Blizzard / NOBELIUM / The Dukes), Russia's SVR-attributed cyber-espionage group, mapping its ATT&CK TTPs to Decepticon emulation tooling. | 54 54 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
apt33-elfin packages/decepticon/decepticon/skills/shared/adversary-emulation/apt33-elfin/SKILL.md Adversary-emulation profile for APT33 (Elfin, Peach Sandstorm, HOLMIUM), a suspected Iranian state-sponsored espionage group, mapped to MITRE ATT&CK G0064 with Decepticon emulation guidance. | 56 56 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
apt34-oilrig packages/decepticon/decepticon/skills/shared/adversary-emulation/apt34-oilrig/SKILL.md Adversary-emulation profile for APT34 / OilRig (G0049), an Iranian state-sponsored espionage group, mapping its ATT&CK TTPs to Decepticon tooling for authorized red-team emulation. | 56 56 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
apt36-transparent-tribe packages/decepticon/decepticon/skills/shared/adversary-emulation/apt36-transparent-tribe/SKILL.md Adversary-emulation profile for APT36 (G0134 / Transparent Tribe / Mythic Leopard / ProjectM / COPPER FIELDSTONE), a Pakistan-linked cyber-espionage actor targeting Indian government, defense, and diplomatic entities. | 53 53 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b |