github.com/PurpleAILAB/Decepticon
| Skill | Added | Review |
|---|---|---|
apt37-reaper packages/decepticon/decepticon/skills/shared/adversary-emulation/apt37-reaper/SKILL.md Adversary-emulation profile for APT37 (G0067 / Reaper / ScarCruft / Ricochet Chollima / InkySquid / Group123), North Korea's RGB cyber-espionage actor. | 57 57 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
apt41-double-dragon packages/decepticon/decepticon/skills/shared/adversary-emulation/apt41-double-dragon/SKILL.md Adversary-emulation profile for APT41 (Double Dragon / Wicked Panda / BARIUM / Brass Typhoon, ATT&CK G0096), a Chinese dual-mandate espionage-and-cybercrime actor. | 66 66 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
asrep-roasting packages/decepticon/decepticon/skills/standard/ad/asrep-roasting/SKILL.md Request AS-REP for accounts with DONT_REQ_PREAUTH set and crack offline — like kerberoast but no auth required. | 60 60 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
ato-methodology packages/decepticon/decepticon/skills/standard/exploit/web/ato-methodology/SKILL.md Account Takeover decision tree — 9 canonical ATO paths, chaining patterns (IDOR→ATO, XSS→ATO, OAuth→ATO), MFA bypass entry points. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
auth-bypass packages/decepticon/decepticon/skills/standard/analyst/auth-bypass/SKILL.md Hunt authentication/authorization bypass in route guards, role checks, tenant boundaries, and state-machine transitions. | 61 61 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
aws-iam-enum packages/decepticon/decepticon/skills/standard/cloud/aws-iam-enum/SKILL.md Enumerate AWS IAM policies, detect privilege escalation paths per Rhino Security Labs canonical 21 primitives. | 55 55 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
aws-iam-passrole-chain packages/decepticon/decepticon/skills/standard/cloud/aws-iam-passrole-chain/SKILL.md AWS IAM privilege escalation via `iam:PassRole` chains — Lambda/Glue/Sagemaker/EC2/ECS PassRole to a higher-priv role, AssumeRole chains across accounts, sts:GetCallerIdentity recon, account hijack via legacy root-mfa-bypass. | 67 67 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
azure-managed-identity packages/decepticon/decepticon/skills/standard/cloud/azure-managed-identity/SKILL.md Azure Managed Identity abuse — IMDS at 169.254.169.254 from compromised VM / App Service / Function, token exchange for Graph/ARM/KeyVault, federated workload identity abuse, hybrid AAD Connect MSOL credential extraction. | 63 63 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
benchmark packages/decepticon/decepticon/skills/benchmark/SKILL.md Benchmark mode marker — engagement objective is flag capture. Generic engagement rules apply unchanged. | 50 50 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
bfla packages/decepticon/decepticon/skills/standard/exploit/web/bfla/SKILL.md Broken Function Level Authorization (BFLA) — exploit action-level access control failures where lower-privileged principals invoke admin/staff functions across REST, GraphQL, gRPC, WebSocket, and background job paths. | 67 67 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: a04f96b | |
binwalk-extract packages/decepticon/decepticon/skills/standard/iot/binwalk-extract/SKILL.md Firmware image extraction with binwalk and firmware-mod-kit — recursive archive carving, squashfs/jffs2/ubifs mounting, entropy analysis to detect packed/encrypted regions, and nested container handling. Entry point for all static filesystem analysis after a raw binary image is acquired. | 64 64 Impact — No eval scenarios have been run Securityby Medium Suggest reviewing before use Version: a04f96b | |
ble-gatt packages/decepticon/decepticon/skills/standard/iot/ble-gatt/SKILL.md GATT service/characteristic enumeration on BLE peripherals, unauthenticated read/write exploitation, pairing downgrade to Just Works, and over-the-air sniffing with Sniffle or Ubertooth. Covers firmware update channels, hidden debug services, and missing auth on sensitive characteristics. | 65 65 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
blind-sqli packages/decepticon/decepticon/skills/standard/exploit/web/blind-sqli/SKILL.md Blind SQL injection under hostile WAF — manual bypass playbook for when sqlmap fails because common tokens (SUBSTRING, IF, AND, WHERE, single quotes) are filtered. Covers token-fingerprinting probe loops, arithmetic-multiplication boolean evaluation, hex-encoded literals, and exponential-probe binary search. Loaded on top of sqli.md when the binary oracle exists but tampers can't pass the WAF. | 72 72 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
bloodhound-bhce packages/decepticon/decepticon/skills/standard/ad/bloodhound-bhce/SKILL.md Operate BloodHound Community Edition v9.2.2 via Decepticon's bhce_* tools — health check, Cypher passthrough, SharpHound ZIP ingest. Replaces the in-house ingest + ESC* post-process pipeline per ADR-0005. | 69 69 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
bloodhound-query packages/decepticon/decepticon/skills/standard/ad/bloodhound-query/SKILL.md BloodHound ingestion + canonical Cypher queries for AD attack-path enumeration. Run after collector dumps zip; promotes findings into the knowledge graph. | 66 66 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
bootloader-uboot packages/decepticon/decepticon/skills/standard/iot/bootloader-uboot/SKILL.md U-Boot bootloader attack playbook — console interrupt to break the autoboot countdown, environment variable inspection and manipulation, bootargs override to spawn init=/bin/sh, secure-boot bypass techniques, and fault-injection basics (voltage and clock glitching). Covers MIPS, ARM, and AArch64 targets. | 65 65 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
bounty-hunting-methodology packages/decepticon/decepticon/skills/standard/analyst/bounty-hunting/SKILL.md Bug bounty white-box hunting methodology. Load when the target is an open-source project with a security advisory program, bug bounty, or responsible disclosure policy. | 65 65 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a04f96b | |
bounty-report-formatter packages/decepticon/decepticon/skills/plugins/verifier/bounty-report/SKILL.md Bug bounty report formatting for HackerOne, Bugcrowd, Immunefi, and GitHub Security Advisories. Load after validate_finding succeeds and the finding needs to be submitted to a bounty program. | 64 64 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a04f96b | |
business-logic packages/decepticon/decepticon/skills/standard/exploit/web/business-logic/SKILL.md Business logic / authentication bypass / privilege escalation — POST body field tampering (role/is_admin/user_type), 2FA bypass via response manipulation, predictable TOTP seeds, hidden authorization headers, multi-step workflow tampering. For challenges tagged business_logic, privilege_escalation, 2fa_bypass, or auth_bypass that aren't pure IDOR/JWT. | 76 76 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
c2 packages/decepticon/decepticon/skills/standard/post-exploit/c2/SKILL.md Framework-agnostic C2 orchestration — listener types, implant modes, redirector architecture, malleable profiles, jitter strategy, OPSEC guidance. | 60 60 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b |