CtrlK
BlogDocsLog inGet started
Tessl Logo

Decepticon

github.com/PurpleAILAB/Decepticon

SkillAddedReview
c2-alternative-channels

packages/decepticon/decepticon/skills/standard/post-exploit/c2-alternative-channels/SKILL.md

Non-traditional C2 channels — Discord/Telegram bots, DNS-over-HTTPS, blockchain-based C2, email-based C2, and cloud function dead drops for covert command and control.

64

c2-cobalt-strike

packages/decepticon/decepticon/skills/standard/post-exploit/c2-cobalt-strike/SKILL.md

Cobalt Strike operations — Beacon deployment, Malleable C2 profile creation, listener setup, OPSEC-safe beacon configuration, process injection, and Arsenal kit usage.

66

c2-domain-fronting

packages/decepticon/decepticon/skills/standard/post-exploit/c2-domain-fronting/SKILL.md

Domain fronting and CDN abuse for C2 concealment — CloudFront, Azure CDN, Fastly setup, TLS SNI vs Host header technique, CDN-based redirectors, and integration with Cobalt Strike and Sliver.

61

c2-havoc

packages/decepticon/decepticon/skills/standard/post-exploit/c2/havoc/SKILL.md

Havoc C2 framework (C5pider/Havoc) — modern Sliver/CS alternative, Demon agent with indirect syscalls, sleep obfuscation (Ekko/Zilean/FOLIAGE), Donut PIC loader integration, profile-driven HTTP comms, MaterialUI web client. Best when you need modern OPSEC without Cobalt Strike cost.

60

c2-mythic

packages/decepticon/decepticon/skills/standard/post-exploit/c2/mythic/SKILL.md

Mythic C2 framework operations — multi-agent (Apfell, Apollo, Athena, Poseidon, Medusa), web UI on 7443, RabbitMQ + PostgreSQL backend, JSON-RPC tasking model, building an agent via mythic-cli, profile design (HTTP/SMB/named pipe/peer-to-peer), opsec defaults. Comparison to Sliver: more pluggable, less polished UI.

58

c2-sliver

packages/decepticon/decepticon/skills/standard/post-exploit/c2-sliver/SKILL.md

Sliver C2 framework operations — server connection, listener setup, implant generation, BOF/Armory extensions, post-implant operations, HTTP C2 profiles.

64

cache-deception

packages/decepticon/decepticon/skills/standard/exploit/web/cache-deception/SKILL.md

Web cache deception — trick CDN/proxy into caching authenticated responses under unauthenticated URLs, exposing PII to any visitor.

60

chain-credential-reuse

packages/decepticon/decepticon/skills/standard/analyst/chains/cred-reuse/SKILL.md

Build chains where leaked or weak credentials pivot across services to privileged access.

55

chain-idor-to-priv-esc

packages/decepticon/decepticon/skills/standard/analyst/chains/idor-to-priv-esc/SKILL.md

Build chains where IDOR enables privilege escalation and high-impact control-plane actions.

54

chain-ssrf-to-rce

packages/decepticon/decepticon/skills/standard/analyst/chains/ssrf-to-rce/SKILL.md

Build and validate SSRF pivot chains toward metadata/infra control and final code execution impact.

62

chain-xss-to-takeover

packages/decepticon/decepticon/skills/standard/analyst/chains/xss-to-takeover/SKILL.md

Build chains from XSS into account takeover or privileged action execution.

52

cicd

packages/decepticon/decepticon/skills/standard/exploit/cicd/SKILL.md

CI/CD pipeline attack category — poisoned pipeline execution, GitHub Actions expression injection, self-hosted runner abuse, secrets/OIDC exfil. Routing skill: fingerprint the CI provider + workflow surface, then load the matching leaf.

66

cicd-secrets-exfil

packages/decepticon/decepticon/skills/standard/exploit/cicd/cicd-secrets-exfil/SKILL.md

Extracting CI secrets / OIDC tokens once you have code execution in a build job — echo/printenv exfil, log-masking bypass (base64, char-split, reversal), OIDC token abuse to assume cloud roles, GITHUB_TOKEN / CI_JOB_TOKEN scope abuse, cache / artifact secret leakage, provenance pivot.

65

cleanup-template

packages/decepticon/decepticon/skills/standard/soundwave/cleanup-template/SKILL.md

Cleanup & restoration plan generator — artifact inventory, persistence removal commands, pre-engagement baseline, post-engagement verification.

66

clickjacking

packages/decepticon/decepticon/skills/standard/exploit/web/clickjacking/SKILL.md

UI redressing — missing X-Frame-Options / frame-ancestors, frame-buster bypass, drag-and-drop, cursorjacking, double-clickjacking, and sensitive-action framing.

69

cloud-overview

packages/decepticon/decepticon/skills/standard/cloud/SKILL.md

Cloud exploitation lane — AWS IAM privesc, S3 takeover, k8s RBAC abuse, Terraform state leaks, cloud metadata pivoting.

63

cloud-recon

packages/decepticon/decepticon/skills/standard/recon/cloud-recon/SKILL.md

Cloud infrastructure enumeration — AWS S3 buckets, Azure blob storage, GCP buckets, cloud metadata endpoints, IAM misconfigurations, CDN origin detection.

61

command-injection

packages/decepticon/decepticon/skills/standard/analyst/command-injection/SKILL.md

Hunt OS command injection (CWE-78) — user input reaching shell, exec, or system calls. Covers argument-array bypasses, path confusion, and template-string injection in modern frameworks.

66

conops-template

packages/decepticon/decepticon/skills/standard/soundwave/conops-template/SKILL.md

Concept of Operations document creation — executive summary, threat actor profiling, attack narrative, kill chain design, communication plan, deconfliction.

—

—
contact-template

packages/decepticon/decepticon/skills/standard/soundwave/contact-template/SKILL.md

Contact / communications plan generator — primary operator, escalation chain, abort signal recipient, external SOC endpoint, blackout windows.

61