github.com/PurpleAILAB/Decepticon
Skill | Added | Review |
|---|---|---|
aws-iam-passrole-chain packages/decepticon/decepticon/skills/standard/cloud/aws-iam-passrole-chain/SKILL.md AWS IAM privilege escalation via `iam:PassRole` chains — Lambda/Glue/Sagemaker/EC2/ECS PassRole to a higher-priv role, AssumeRole chains across accounts, sts:GetCallerIdentity recon, account hijack via legacy root-mfa-bypass. | 67 67 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: e34afba | |
aws-iam-enum packages/decepticon/decepticon/skills/standard/cloud/aws-iam-enum/SKILL.md Enumerate AWS IAM policies, detect privilege escalation paths per Rhino Security Labs canonical 21 primitives. | 59 59 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: e34afba | |
cloud-overview packages/decepticon/decepticon/skills/standard/cloud/SKILL.md Cloud exploitation lane — AWS IAM privesc, S3 takeover, k8s RBAC abuse, Terraform state leaks, cloud metadata pivoting. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: e34afba | |
data-and-model-poisoning packages/decepticon/decepticon/skills/standard/analyst/data-and-model-poisoning/SKILL.md Hunt LLM training-data and model poisoning (OWASP LLM04:2025) — adversarial inputs that bias future model behaviour through fine-tuning, RLHF, or continuous-learning loops. | 73 73 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: e34afba | |
command-injection packages/decepticon/decepticon/skills/standard/analyst/command-injection/SKILL.md Hunt OS command injection (CWE-78) — user input reaching shell, exec, or system calls. Covers argument-array bypasses, path confusion, and template-string injection in modern frameworks. | 73 73 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: e34afba | |
chain-xss-to-takeover packages/decepticon/decepticon/skills/standard/analyst/chains/xss-to-takeover/SKILL.md Build chains from XSS into account takeover or privileged action execution. | 56 56 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: e34afba | |
chain-ssrf-to-rce packages/decepticon/decepticon/skills/standard/analyst/chains/ssrf-to-rce/SKILL.md Build and validate SSRF pivot chains toward metadata/infra control and final code execution impact. | 56 56 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: e34afba | |
chain-idor-to-priv-esc packages/decepticon/decepticon/skills/standard/analyst/chains/idor-to-priv-esc/SKILL.md Build chains where IDOR enables privilege escalation and high-impact control-plane actions. | 58 58 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: e34afba | |
chain-credential-reuse packages/decepticon/decepticon/skills/standard/analyst/chains/cred-reuse/SKILL.md Build chains where leaked or weak credentials pivot across services to privileged access. | 56 56 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: e34afba | |
bounty-hunting-methodology packages/decepticon/decepticon/skills/standard/analyst/bounty-hunting/SKILL.md Bug bounty white-box hunting methodology. Load when the target is an open-source project with a security advisory program, bug bounty, or responsible disclosure policy. | 76 76 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Reviewed: Version: e34afba | |
auth-bypass packages/decepticon/decepticon/skills/standard/analyst/auth-bypass/SKILL.md Hunt authentication/authorization bypass in route guards, role checks, tenant boundaries, and state-machine transitions. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: e34afba | |
adversarial-ml-evasion packages/decepticon/decepticon/skills/standard/analyst/adversarial-ml-evasion/SKILL.md Craft adversarial examples that cause trained ML classifiers to misclassify at inference time — image recognition, malware detectors, IDS, spam filters. | 66 66 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: e34afba | |
analyst-overview packages/decepticon/decepticon/skills/standard/analyst/SKILL.md Root pointer for the analyst's vulnerability research playbooks. Load this first at iteration start to see the full catalog of vuln-class and chain-building skills. | 62 62 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: e34afba | |
ad-ntlm-relay packages/decepticon/decepticon/skills/standard/ad/ntlm-relay/SKILL.md NTLM relay deep-dive — `ntlmrelayx` configuration matrix (SMB, LDAP, LDAPS, HTTP, RPC, IMAP, MSSQL), SMB-signing bypass, target selection (DC for DCSync, ADCS for cert, LAPS reader for cleartext), session relay vs cracking trade-off, multi-relay (forward auth from one victim to many). | 69 69 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: e34afba | |
dcsync packages/decepticon/decepticon/skills/standard/ad/dcsync/SKILL.md Abuse replication rights (DS-Replication-Get-Changes + GetChangesAll) to dump krbtgt and arbitrary user NT hashes from a DC. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: e34afba | |
ad-coercer packages/decepticon/decepticon/skills/standard/ad/coercer/SKILL.md Authentication coercion against Windows / AD — PetitPotam (MS-EFSR), PrinterBug (MS-RPRN), DFSCoerce (MS-DFSNM), ShadowCoerce (MS-FSRVP), Coercer.py meta-tool. Force a Windows machine to NTLM-authenticate to attacker, then relay or crack offline. | 67 67 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: e34afba | |
ad-certipy-esc-chain packages/decepticon/decepticon/skills/standard/ad/certipy-esc-chain/SKILL.md ADCS abuse via Certipy — find vulnerable templates (ESC1-ESC15), request a certificate, authenticate as the target, dump the krbtgt. Full chain in 4 commands. Covers ESC1 (any SAN), ESC2 (any-purpose EKU), ESC3 (enrollment-agent), ESC4 (vulnerable ACL), ESC8 (NTLM relay to CA), ESC9/10/11/13. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: e34afba | |
bloodhound-query packages/decepticon/decepticon/skills/standard/ad/bloodhound-query/SKILL.md BloodHound ingestion + canonical Cypher queries for AD attack-path enumeration. Run after collector dumps zip; promotes findings into the knowledge graph. | 61 61 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: e34afba | |
bloodhound-bhce packages/decepticon/decepticon/skills/standard/ad/bloodhound-bhce/SKILL.md Operate BloodHound Community Edition v9.2.2 via Decepticon's bhce_* tools — health check, Cypher passthrough, SharpHound ZIP ingest. Replaces the in-house ingest + ESC* post-process pipeline per ADR-0005. | 60 60 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: 5e34a6d | |
asrep-roasting packages/decepticon/decepticon/skills/standard/ad/asrep-roasting/SKILL.md Request AS-REP for accounts with DONT_REQ_PREAUTH set and crack offline — like kerberoast but no auth required. | 60 60 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: 5e34a6d | |
adcs-esc1 packages/decepticon/decepticon/skills/standard/ad/adcs-esc1/SKILL.md Exploit Active Directory Certificate Services ESC1 — vulnerable template allows arbitrary SAN, enabling user impersonation up to domain admin. | 66 66 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: 5e34a6d | |
ad-overview packages/decepticon/decepticon/skills/standard/ad/SKILL.md Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction. | 68 68 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: 5e34a6d | |
dark-caracal packages/decepticon/decepticon/skills/shared/adversary-emulation/dark-caracal/SKILL.md Adversary-emulation profile for Dark Caracal (G0070), a Lebanese state-linked cyber-espionage and surveillance actor attributed to the General Directorate of General Security (GDGS), operating since at least 2012. | 49 49 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: 4484f85 | |
apt41-double-dragon packages/decepticon/decepticon/skills/shared/adversary-emulation/apt41-double-dragon/SKILL.md Adversary-emulation profile for APT41 (Double Dragon / Wicked Panda / BARIUM / Brass Typhoon, ATT&CK G0096), a Chinese dual-mandate espionage-and-cybercrime actor. | 49 49 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: 4484f85 | |
apt37-reaper packages/decepticon/decepticon/skills/shared/adversary-emulation/apt37-reaper/SKILL.md Adversary-emulation profile for APT37 (G0067 / Reaper / ScarCruft / Ricochet Chollima / InkySquid / Group123), North Korea's RGB cyber-espionage actor. | 59 59 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Reviewed: Version: 4484f85 |