0xSteph

59 mods across 2 repositories, 3.8k stars between them.

pentest-ai-agents

01

0xSteph/pentest-ai-agents

Plugin Claude Code

Marketplace for pentest-ai-agents — specialist Claude Code subagents for authorized penetration testing.

2.2k 16d ago A tokens not measured original MIT

pentest-ai-agents

02

0xSteph/pentest-ai-agents

Plugin Claude Code

52 specialist subagents for authorized penetration testing and red team engagements — recon, web/API, Active Directory, cloud, mobile, wireless, exploitation, post-exploitation, detection, forensics, and reporting.

2.2k 16d ago A tokens not measured original MIT

ad-attacker

04

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants to perform Active Directory attacks, run BloodHound analysis, use Impacket tools, execute Kerberos attacks, perform AD enumeration with CrackMapExec or NetExec, test AD delegation abuse, or conduct lateral movement through Active Directory environments during authorized…

2.2k 16d ago B 64 tokens original MIT

ai-recon

05

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants to map the AI attack surface of an authorized web application before validation — discovering AI/LLM API endpoints (including OpenAI-compatible APIs), enumerating A2A agent cards, fingerprinting the deployed model, identifying MCP exposure, and characterizing RAG and…

2.2k 16d ago B 90 tokens original MIT

api-security

06

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about API security testing, REST API attacks, GraphQL exploitation, OAuth/OIDC vulnerabilities, JWT attacks, API enumeration, or web service penetration testing methodology.

2.2k 16d ago A 43 tokens original MIT

attack-planner

07

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants to correlate findings from multiple tools or agents, build multi-step attack chains, identify the optimal exploitation path through a network, prioritize attack vectors across an engagement, or plan lateral movement strategies for authorized penetration testing.

2.2k 16d ago A 54 tokens original MIT

bizlogic-hunter

08

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants to test for business logic flaws, find workflow bypass vulnerabilities, detect price manipulation or payment tampering, identify race conditions in transactions, test authorization boundaries between user roles, or discover logic errors that standard vulnerability scanners…

2.2k 16d ago B 61 tokens original MIT

bug-bounty

09

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user is working on bug bounty programs, submitting vulnerability reports to HackerOne or Bugcrowd, needs help with bug bounty methodology, wants to prioritize targets from a bug bounty scope, or needs help writing quality vulnerability reports for bounty submissions.

2.2k 16d ago C 58 tokens original MIT

c2-operator

10

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about command-and-control framework operations, Sliver/Mythic/Havoc/Cobalt Strike configuration, listener and beacon tuning, malleable C2 profiles, sleep and jitter strategy, redirector and CDN fronting infrastructure, or operating an established foothold during authorized…

2.2k 16d ago A 71 tokens original MIT

cicd-redteam

11

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants to integrate red teaming into CI/CD pipelines, set up continuous automated security testing on every code push, generate pipeline configurations for automated pentesting, configure scheduled security assessments in deployment workflows, or build a continuous red team…

2.2k 16d ago A 64 tokens original MIT

cloud-security

12

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about cloud security testing, AWS/Azure/GCP penetration testing, cloud misconfiguration analysis, IAM privilege escalation, container security, Kubernetes attacks, serverless security, or cloud-native attack paths.

2.2k 16d ago A 50 tokens original MIT

code-auditor

13

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants a secure-code review of application source — static analysis for injection, auth, secrets, deserialization, and OWASP issues; SAST tooling guidance (Semgrep, CodeQL); or triage of scanner output. Reviews source at rest; it does not test running systems (use…

2.2k 16d ago A 86 tokens original MIT

compliance-mapper

14

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants to map penetration-test findings to compliance frameworks — PCI DSS, NIST 800-53 / CSF, ISO 27001, CIS Controls, HIPAA, SOC 2 — produce control-gap analysis, and translate technical findings into compliance impact. Distinct from stig-analyst (STIG hardening) and…

2.2k 16d ago A 84 tokens original MIT

container-breakout

15

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about container escape, Docker breakout, Kubernetes pod escape, runc/containerd CVE exploitation, capability abuse, privileged container hunting, kubelet API attacks, service account token abuse, or any technique that pivots from inside a container to the host or cluster…

2.2k 16d ago F 70 tokens original MIT

credential-tester

16

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about password attacks, credential testing, hash cracking, brute force methodology, default credential checks, password spraying, or needs help with tools like hydra, john, hashcat, medusa, or CrackMapExec for authorized penetration testing engagements.

2.2k 16d ago B 61 tokens original MIT

crypto-analyzer

17

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants to analyze cryptographic usage — weak algorithms or modes, key and IV/nonce management, TLS/certificate configuration, randomness quality, password hashing, or JWT/JWE/token issues. Advisory analysis of crypto design and misuse; hands active exploitation (padding oracles…

2.2k 16d ago A 73 tokens original MIT

ctf-solver

18

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user is working on CTF challenges, capture the flag competitions, HackTheBox machines, TryHackMe rooms, or needs help with CTF methodology including web exploitation, binary exploitation, cryptography, forensics, reverse engineering, or privilege escalation challenges.

2.2k 16d ago B 63 tokens original MIT

data-exfiltrator

19

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants to test exfiltration and DLP/egress controls during an authorized engagement — DNS tunneling, HTTPS/cloud-storage exfil, ICMP, protocol abuse, and staging — using synthetic/canary data to validate detection. Every technique ships with the egress detection it exercises.

2.2k 16d ago A 72 tokens original MIT

database-attacker

20

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants database-specific offensive testing on an authorized target — SQL and NoSQL injection depth, authenticated database enumeration, DBMS privilege escalation, and safe data-extraction validation across MySQL, PostgreSQL, MSSQL, Oracle, MongoDB, and Redis. Executes with…

2.2k 16d ago A 71 tokens original MIT

detection-engineer

21

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about detection rules, SIEM queries, threat hunting, indicator analysis, log analysis, blue team detection for specific attack techniques, or creating detection engineering content.

2.2k 16d ago A 45 tokens original MIT

engagement-planner

22

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user needs to plan a penetration test, define attack methodology, scope an engagement, map techniques to MITRE ATT&CK, or create a rules of engagement template.

2.2k 16d ago A 45 tokens original MIT

evasion-specialist

23

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants to test defensive evasion during an authorized red team or EDR-validation engagement — AV/EDR evasion, AMSI and ETW bypass, payload obfuscation, in-memory execution, and unhooking. Every technique ships with the detection it exercises. For artifact generation use…

2.2k 16d ago A 86 tokens original MIT

exploit-chainer

24

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants to automatically chain isolated vulnerabilities into multi-step attack paths, pivot through a system from a low-severity finding to full compromise, execute exploit chains step-by-step with approval at each stage, or demonstrate real-world attack escalation during authorized…

2.2k 16d ago B 62 tokens original MIT