CtrlK
BlogDocsLog inGet started
Tessl Logo

Decepticon

github.com/PurpleAILAB/Decepticon

SkillAddedReview
apt37-reaper

packages/decepticon/decepticon/skills/shared/adversary-emulation/apt37-reaper/SKILL.md

Adversary-emulation profile for APT37 (G0067 / Reaper / ScarCruft / Ricochet Chollima / InkySquid / Group123), North Korea's RGB cyber-espionage actor.

57

apt41-double-dragon

packages/decepticon/decepticon/skills/shared/adversary-emulation/apt41-double-dragon/SKILL.md

Adversary-emulation profile for APT41 (Double Dragon / Wicked Panda / BARIUM / Brass Typhoon, ATT&CK G0096), a Chinese dual-mandate espionage-and-cybercrime actor.

66

asrep-roasting

packages/decepticon/decepticon/skills/standard/ad/asrep-roasting/SKILL.md

Request AS-REP for accounts with DONT_REQ_PREAUTH set and crack offline — like kerberoast but no auth required.

60

ato-methodology

packages/decepticon/decepticon/skills/standard/exploit/web/ato-methodology/SKILL.md

Account Takeover decision tree — 9 canonical ATO paths, chaining patterns (IDOR→ATO, XSS→ATO, OAuth→ATO), MFA bypass entry points.

64

auth-bypass

packages/decepticon/decepticon/skills/standard/analyst/auth-bypass/SKILL.md

Hunt authentication/authorization bypass in route guards, role checks, tenant boundaries, and state-machine transitions.

61

aws-iam-enum

packages/decepticon/decepticon/skills/standard/cloud/aws-iam-enum/SKILL.md

Enumerate AWS IAM policies, detect privilege escalation paths per Rhino Security Labs canonical 21 primitives.

55

aws-iam-passrole-chain

packages/decepticon/decepticon/skills/standard/cloud/aws-iam-passrole-chain/SKILL.md

AWS IAM privilege escalation via `iam:PassRole` chains — Lambda/Glue/Sagemaker/EC2/ECS PassRole to a higher-priv role, AssumeRole chains across accounts, sts:GetCallerIdentity recon, account hijack via legacy root-mfa-bypass.

67

azure-managed-identity

packages/decepticon/decepticon/skills/standard/cloud/azure-managed-identity/SKILL.md

Azure Managed Identity abuse — IMDS at 169.254.169.254 from compromised VM / App Service / Function, token exchange for Graph/ARM/KeyVault, federated workload identity abuse, hybrid AAD Connect MSOL credential extraction.

63

benchmark

packages/decepticon/decepticon/skills/benchmark/SKILL.md

Benchmark mode marker — engagement objective is flag capture. Generic engagement rules apply unchanged.

50

bfla

packages/decepticon/decepticon/skills/standard/exploit/web/bfla/SKILL.md

Broken Function Level Authorization (BFLA) — exploit action-level access control failures where lower-privileged principals invoke admin/staff functions across REST, GraphQL, gRPC, WebSocket, and background job paths.

67

binwalk-extract

packages/decepticon/decepticon/skills/standard/iot/binwalk-extract/SKILL.md

Firmware image extraction with binwalk and firmware-mod-kit — recursive archive carving, squashfs/jffs2/ubifs mounting, entropy analysis to detect packed/encrypted regions, and nested container handling. Entry point for all static filesystem analysis after a raw binary image is acquired.

64

ble-gatt

packages/decepticon/decepticon/skills/standard/iot/ble-gatt/SKILL.md

GATT service/characteristic enumeration on BLE peripherals, unauthenticated read/write exploitation, pairing downgrade to Just Works, and over-the-air sniffing with Sniffle or Ubertooth. Covers firmware update channels, hidden debug services, and missing auth on sensitive characteristics.

65

blind-sqli

packages/decepticon/decepticon/skills/standard/exploit/web/blind-sqli/SKILL.md

Blind SQL injection under hostile WAF — manual bypass playbook for when sqlmap fails because common tokens (SUBSTRING, IF, AND, WHERE, single quotes) are filtered. Covers token-fingerprinting probe loops, arithmetic-multiplication boolean evaluation, hex-encoded literals, and exponential-probe binary search. Loaded on top of sqli.md when the binary oracle exists but tampers can't pass the WAF.

72

bloodhound-bhce

packages/decepticon/decepticon/skills/standard/ad/bloodhound-bhce/SKILL.md

Operate BloodHound Community Edition v9.2.2 via Decepticon's bhce_* tools — health check, Cypher passthrough, SharpHound ZIP ingest. Replaces the in-house ingest + ESC* post-process pipeline per ADR-0005.

69

bloodhound-query

packages/decepticon/decepticon/skills/standard/ad/bloodhound-query/SKILL.md

BloodHound ingestion + canonical Cypher queries for AD attack-path enumeration. Run after collector dumps zip; promotes findings into the knowledge graph.

66

bootloader-uboot

packages/decepticon/decepticon/skills/standard/iot/bootloader-uboot/SKILL.md

U-Boot bootloader attack playbook — console interrupt to break the autoboot countdown, environment variable inspection and manipulation, bootargs override to spawn init=/bin/sh, secure-boot bypass techniques, and fault-injection basics (voltage and clock glitching). Covers MIPS, ARM, and AArch64 targets.

65

bounty-hunting-methodology

packages/decepticon/decepticon/skills/standard/analyst/bounty-hunting/SKILL.md

Bug bounty white-box hunting methodology. Load when the target is an open-source project with a security advisory program, bug bounty, or responsible disclosure policy.

65

bounty-report-formatter

packages/decepticon/decepticon/skills/plugins/verifier/bounty-report/SKILL.md

Bug bounty report formatting for HackerOne, Bugcrowd, Immunefi, and GitHub Security Advisories. Load after validate_finding succeeds and the finding needs to be submitted to a bounty program.

64

business-logic

packages/decepticon/decepticon/skills/standard/exploit/web/business-logic/SKILL.md

Business logic / authentication bypass / privilege escalation — POST body field tampering (role/is_admin/user_type), 2FA bypass via response manipulation, predictable TOTP seeds, hidden authorization headers, multi-step workflow tampering. For challenges tagged business_logic, privilege_escalation, 2fa_bypass, or auth_bypass that aren't pure IDOR/JWT.

76

c2

packages/decepticon/decepticon/skills/standard/post-exploit/c2/SKILL.md

Framework-agnostic C2 orchestration — listener types, implant modes, redirector architecture, malleable profiles, jitter strategy, OPSEC guidance.

60