CtrlK
BlogDocsLog inGet started
Tessl Logo

Decepticon

github.com/PurpleAILAB/Decepticon

Skill

Added

Review

aws-iam-passrole-chain

packages/decepticon/decepticon/skills/standard/cloud/aws-iam-passrole-chain/SKILL.md

AWS IAM privilege escalation via `iam:PassRole` chains — Lambda/Glue/Sagemaker/EC2/ECS PassRole to a higher-priv role, AssumeRole chains across accounts, sts:GetCallerIdentity recon, account hijack via legacy root-mfa-bypass.

67

aws-iam-enum

packages/decepticon/decepticon/skills/standard/cloud/aws-iam-enum/SKILL.md

Enumerate AWS IAM policies, detect privilege escalation paths per Rhino Security Labs canonical 21 primitives.

59

cloud-overview

packages/decepticon/decepticon/skills/standard/cloud/SKILL.md

Cloud exploitation lane — AWS IAM privesc, S3 takeover, k8s RBAC abuse, Terraform state leaks, cloud metadata pivoting.

64

data-and-model-poisoning

packages/decepticon/decepticon/skills/standard/analyst/data-and-model-poisoning/SKILL.md

Hunt LLM training-data and model poisoning (OWASP LLM04:2025) — adversarial inputs that bias future model behaviour through fine-tuning, RLHF, or continuous-learning loops.

73

command-injection

packages/decepticon/decepticon/skills/standard/analyst/command-injection/SKILL.md

Hunt OS command injection (CWE-78) — user input reaching shell, exec, or system calls. Covers argument-array bypasses, path confusion, and template-string injection in modern frameworks.

73

chain-xss-to-takeover

packages/decepticon/decepticon/skills/standard/analyst/chains/xss-to-takeover/SKILL.md

Build chains from XSS into account takeover or privileged action execution.

56

chain-ssrf-to-rce

packages/decepticon/decepticon/skills/standard/analyst/chains/ssrf-to-rce/SKILL.md

Build and validate SSRF pivot chains toward metadata/infra control and final code execution impact.

56

chain-idor-to-priv-esc

packages/decepticon/decepticon/skills/standard/analyst/chains/idor-to-priv-esc/SKILL.md

Build chains where IDOR enables privilege escalation and high-impact control-plane actions.

58

chain-credential-reuse

packages/decepticon/decepticon/skills/standard/analyst/chains/cred-reuse/SKILL.md

Build chains where leaked or weak credentials pivot across services to privileged access.

56

bounty-hunting-methodology

packages/decepticon/decepticon/skills/standard/analyst/bounty-hunting/SKILL.md

Bug bounty white-box hunting methodology. Load when the target is an open-source project with a security advisory program, bug bounty, or responsible disclosure policy.

76

auth-bypass

packages/decepticon/decepticon/skills/standard/analyst/auth-bypass/SKILL.md

Hunt authentication/authorization bypass in route guards, role checks, tenant boundaries, and state-machine transitions.

64

adversarial-ml-evasion

packages/decepticon/decepticon/skills/standard/analyst/adversarial-ml-evasion/SKILL.md

Craft adversarial examples that cause trained ML classifiers to misclassify at inference time — image recognition, malware detectors, IDS, spam filters.

66

analyst-overview

packages/decepticon/decepticon/skills/standard/analyst/SKILL.md

Root pointer for the analyst's vulnerability research playbooks. Load this first at iteration start to see the full catalog of vuln-class and chain-building skills.

62

ad-ntlm-relay

packages/decepticon/decepticon/skills/standard/ad/ntlm-relay/SKILL.md

NTLM relay deep-dive — `ntlmrelayx` configuration matrix (SMB, LDAP, LDAPS, HTTP, RPC, IMAP, MSSQL), SMB-signing bypass, target selection (DC for DCSync, ADCS for cert, LAPS reader for cleartext), session relay vs cracking trade-off, multi-relay (forward auth from one victim to many).

69

dcsync

packages/decepticon/decepticon/skills/standard/ad/dcsync/SKILL.md

Abuse replication rights (DS-Replication-Get-Changes + GetChangesAll) to dump krbtgt and arbitrary user NT hashes from a DC.

64

ad-coercer

packages/decepticon/decepticon/skills/standard/ad/coercer/SKILL.md

Authentication coercion against Windows / AD — PetitPotam (MS-EFSR), PrinterBug (MS-RPRN), DFSCoerce (MS-DFSNM), ShadowCoerce (MS-FSRVP), Coercer.py meta-tool. Force a Windows machine to NTLM-authenticate to attacker, then relay or crack offline.

67

ad-certipy-esc-chain

packages/decepticon/decepticon/skills/standard/ad/certipy-esc-chain/SKILL.md

ADCS abuse via Certipy — find vulnerable templates (ESC1-ESC15), request a certificate, authenticate as the target, dump the krbtgt. Full chain in 4 commands. Covers ESC1 (any SAN), ESC2 (any-purpose EKU), ESC3 (enrollment-agent), ESC4 (vulnerable ACL), ESC8 (NTLM relay to CA), ESC9/10/11/13.

64

bloodhound-query

packages/decepticon/decepticon/skills/standard/ad/bloodhound-query/SKILL.md

BloodHound ingestion + canonical Cypher queries for AD attack-path enumeration. Run after collector dumps zip; promotes findings into the knowledge graph.

61

bloodhound-bhce

packages/decepticon/decepticon/skills/standard/ad/bloodhound-bhce/SKILL.md

Operate BloodHound Community Edition v9.2.2 via Decepticon's bhce_* tools — health check, Cypher passthrough, SharpHound ZIP ingest. Replaces the in-house ingest + ESC* post-process pipeline per ADR-0005.

60

asrep-roasting

packages/decepticon/decepticon/skills/standard/ad/asrep-roasting/SKILL.md

Request AS-REP for accounts with DONT_REQ_PREAUTH set and crack offline — like kerberoast but no auth required.

60

adcs-esc1

packages/decepticon/decepticon/skills/standard/ad/adcs-esc1/SKILL.md

Exploit Active Directory Certificate Services ESC1 — vulnerable template allows arbitrary SAN, enabling user impersonation up to domain admin.

66

ad-overview

packages/decepticon/decepticon/skills/standard/ad/SKILL.md

Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction.

68

dark-caracal

packages/decepticon/decepticon/skills/shared/adversary-emulation/dark-caracal/SKILL.md

Adversary-emulation profile for Dark Caracal (G0070), a Lebanese state-linked cyber-espionage and surveillance actor attributed to the General Directorate of General Security (GDGS), operating since at least 2012.

49

apt41-double-dragon

packages/decepticon/decepticon/skills/shared/adversary-emulation/apt41-double-dragon/SKILL.md

Adversary-emulation profile for APT41 (Double Dragon / Wicked Panda / BARIUM / Brass Typhoon, ATT&CK G0096), a Chinese dual-mandate espionage-and-cybercrime actor.

49

apt37-reaper

packages/decepticon/decepticon/skills/shared/adversary-emulation/apt37-reaper/SKILL.md

Adversary-emulation profile for APT37 (G0067 / Reaper / ScarCruft / Ricochet Chollima / InkySquid / Group123), North Korea's RGB cyber-espionage actor.

59