CtrlK
BlogDocsLog inGet started
Tessl Logo

Decepticon

github.com/PurpleAILAB/Decepticon

SkillAddedReview
ad-coercer

packages/decepticon/decepticon/skills/standard/ad/coercer/SKILL.md

Authentication coercion against Windows / AD — PetitPotam (MS-EFSR), PrinterBug (MS-RPRN), DFSCoerce (MS-DFSNM), ShadowCoerce (MS-FSRVP), Coercer.py meta-tool. Force a Windows machine to NTLM-authenticate to attacker, then relay or crack offline.

63

adcs-esc1

packages/decepticon/decepticon/skills/standard/ad/adcs-esc1/SKILL.md

Exploit Active Directory Certificate Services ESC1 — vulnerable template allows arbitrary SAN, enabling user impersonation up to domain admin.

62

ad-ntlm-relay

packages/decepticon/decepticon/skills/standard/ad/ntlm-relay/SKILL.md

NTLM relay deep-dive — `ntlmrelayx` configuration matrix (SMB, LDAP, LDAPS, HTTP, RPC, IMAP, MSSQL), SMB-signing bypass, target selection (DC for DCSync, ADCS for cert, LAPS reader for cleartext), session relay vs cracking trade-off, multi-relay (forward auth from one victim to many).

63

ad-overview

packages/decepticon/decepticon/skills/standard/ad/SKILL.md

Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction.

63

adversarial-ml-evasion

packages/decepticon/decepticon/skills/standard/analyst/adversarial-ml-evasion/SKILL.md

Craft adversarial examples that cause trained ML classifiers to misclassify at inference time — image recognition, malware detectors, IDS, spam filters.

62

adversary-emulation

packages/decepticon/decepticon/skills/shared/adversary-emulation/SKILL.md

Threat-informed adversary emulation — pick a real APT, load its profile, and reproduce its TTPs within RoE scope to test detection & response. Index of available actor profiles + the emulation methodology.

60

analyst-overview

packages/decepticon/decepticon/skills/standard/analyst/SKILL.md

Root pointer for the analyst's vulnerability research playbooks. Load this first at iteration start to see the full catalog of vuln-class and chain-building skills.

64

anti-debug-bypass

packages/decepticon/decepticon/skills/standard/reverser/anti-debug-bypass/SKILL.md

Detect and neutralize anti-debug / anti-VM checks — IsDebuggerPresent, ptrace, NtGlobalFlag, timing, hardware-breakpoint detection.

64

api-grpc

packages/decepticon/decepticon/skills/standard/exploit/api/grpc/SKILL.md

gRPC API exploitation — reflection-based discovery via grpcurl, protobuf fuzzing, missing authz on streaming RPCs, gRPC-Web → backend SSRF, mTLS bypass, metadata header injection, h2c smuggling against gRPC fronts.

67

api-overview

packages/decepticon/decepticon/skills/standard/exploit/api/SKILL.md

Modern API category — gRPC, SOAP/WSDL, WebSocket, Server-Sent Events. Routing skill: identify the API protocol from the response Content-Type or wire format, then load the matching sub-skill.

60

api-server-sent-events

packages/decepticon/decepticon/skills/standard/exploit/api/server-sent-events/SKILL.md

Server-Sent Events (SSE / EventSource) exploitation — origin abuse for cross-site streaming exfil, prompt-injection via SSE messages into LLM clients, retry-after token leak, fragmenting events to bypass content-type sniffers.

60

api-soap-wsdl

packages/decepticon/decepticon/skills/standard/exploit/api/soap-wsdl/SKILL.md

SOAP / WSDL exploitation — WSDL enumeration via ?wsdl, XXE in SOAP envelope, WS-Addressing replay, WS-Security UsernameToken brute, SAML token injection in WS-Trust, schema validation bypass.

60

api-websocket

packages/decepticon/decepticon/skills/standard/exploit/api/websocket/SKILL.md

WebSocket exploitation — origin-bypass (CSWSH cross-site WebSocket hijacking), missing per-message auth, message-type confusion, msg-flood DoS, ws→wss downgrade, hidden RPC routes in the WS frame layer.

63

apt10-stone-panda

packages/decepticon/decepticon/skills/shared/adversary-emulation/apt10-stone-panda/SKILL.md

Adversary-emulation profile for APT10 (G0045 / Stone Panda / menuPass / POTASSIUM / Red Apollo / CVNX), China's MSS Tianjin State Security Bureau cyber-espionage actor.

59

apt28-fancy-bear

packages/decepticon/decepticon/skills/shared/adversary-emulation/apt28-fancy-bear/SKILL.md

Adversary-emulation profile for APT28 (G0007 / Fancy Bear / Forest Blizzard / Sofacy / STRONTIUM), Russia's GRU Unit 26165 cyber-espionage actor.

56

apt29

packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/emulation/apt29/SKILL.md

APT29 (Cozy Bear / Midnight Blizzard, SVR) adversary-emulation playbook — malware-light cloud-identity espionage: no-MFA password spray, OAuth consent/token abuse, Golden SAML, mailbox collection over residential proxies. Use when emulating APT29 against an M365/Entra/AWS-identity estate. Triggers on: 'emulate APT29', 'Cozy Bear', 'Midnight Blizzard', 'NOBELIUM', 'OAuth abuse', 'cloud identity espionage', 'Golden SAML'.

71

apt29-cozy-bear

packages/decepticon/decepticon/skills/shared/adversary-emulation/apt29-cozy-bear/SKILL.md

Adversary-emulation profile for APT29 (Cozy Bear / Midnight Blizzard / NOBELIUM / The Dukes), Russia's SVR-attributed cyber-espionage group, mapping its ATT&CK TTPs to Decepticon emulation tooling.

54

apt33-elfin

packages/decepticon/decepticon/skills/shared/adversary-emulation/apt33-elfin/SKILL.md

Adversary-emulation profile for APT33 (Elfin, Peach Sandstorm, HOLMIUM), a suspected Iranian state-sponsored espionage group, mapped to MITRE ATT&CK G0064 with Decepticon emulation guidance.

56

apt34-oilrig

packages/decepticon/decepticon/skills/shared/adversary-emulation/apt34-oilrig/SKILL.md

Adversary-emulation profile for APT34 / OilRig (G0049), an Iranian state-sponsored espionage group, mapping its ATT&CK TTPs to Decepticon tooling for authorized red-team emulation.

56

apt36-transparent-tribe

packages/decepticon/decepticon/skills/shared/adversary-emulation/apt36-transparent-tribe/SKILL.md

Adversary-emulation profile for APT36 (G0134 / Transparent Tribe / Mythic Leopard / ProjectM / COPPER FIELDSTONE), a Pakistan-linked cyber-espionage actor targeting Indian government, defense, and diplomatic entities.

53