0xSteph

59 mods across 2 repositories, 3.8k stars between them.

exploit-guide

25

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about exploitation techniques, attack methodologies, tool configurations for authorized testing, post-exploitation activities, or specific vulnerability exploitation paths.

2.2k 16d ago A 37 tokens original MIT

fix-verifier

26

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants to retest a vulnerability after a fix has been deployed, prove that a remediation actually closed the issue, verify a patch before closing a finding or a bug bounty report, check whether a fix broke working functionality, or confirm that a security regression has not…

2.2k 16d ago A 73 tokens original MIT

forensics-analyst

27

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about digital forensics, incident response, evidence acquisition, memory forensics, disk forensics, network forensics, timeline analysis, or chain of custody.

2.2k 16d ago D 45 tokens original MIT

iot-pentester

28

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants authorized security testing of IoT/embedded devices — firmware extraction and analysis, hardware interfaces (UART/JTAG/SPI), radio protocols (BLE/Zigbee/sub-GHz), companion-app and cloud-API surface, and default-credential review. Distinct from wireless-pentester (Wi-Fi/RF…

2.2k 16d ago A 94 tokens original MIT

lateral-movement

29

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants post-foothold lateral-movement strategy on an authorized engagement — pass-the-hash/ticket, remote execution (PsExec/WMI/WinRM/DCOM/SSH), token manipulation, RDP, and pivot planning across a compromised network. Distinct from ad-attacker (AD protocol attacks)…

2.2k 16d ago A 94 tokens original MIT

llm-redteam

30

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about LLM and AI system red teaming, prompt injection (direct and indirect), jailbreak techniques, RAG poisoning, model exfiltration, training data extraction, agent and tool-use abuse, MCP server exploitation, AI guardrail bypass, or red teaming a deployed…

2.2k 16d ago E 79 tokens original MIT

malware-analyst

31

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about malware analysis, reverse engineering, binary analysis, disassembly, debugging, sandbox analysis, static analysis, dynamic analysis, or suspicious file triage.

2.2k 16d ago A 44 tokens original MIT

mobile-pentester

32

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about mobile application security testing, Android pentesting, iOS pentesting, APK analysis, IPA analysis, mobile API testing, certificate pinning bypass, or mobile reverse engineering.

2.2k 16d ago A 48 tokens original MIT

network-attacker

33

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants layer-2/layer-3 offensive testing on an authorized internal network — LLMNR/NBT-NS/mDNS poisoning, ARP spoofing and MITM, NTLM relay, IPv6/mitm6 takeover, VLAN hopping, and pivoting. Executes with per-command approval and scope validation. Distinct from recon-advisor…

2.2k 16d ago B 94 tokens original MIT

opsec-anonymizer

34

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about operator-side identity hygiene, source IP separation, traffic anonymization for authorized red team work, Tor and proxy chains, burner infrastructure provisioning, attribution avoidance, or pre-engagement opsec posture before tools are run against scope.

2.2k 16d ago A 60 tokens original MIT

osint-collector

35

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about OSINT, reconnaissance, information gathering, target profiling, email harvesting, subdomain enumeration, social media recon, breach data, open source intelligence, or building a target dossier for authorized engagements.

2.2k 16d ago A 53 tokens original MIT

password-auditor

36

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants to audit password posture — policy review against NIST 800-63B, password-storage/hashing review, breach-exposure checks, and lockout-safe password-spray planning. Advisory and planning only; hands active cracking and live spraying to credential-tester.

2.2k 16d ago A 66 tokens original MIT

payload-crafter

37

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about generating offensive payloads, building shellcode, working with msfvenom, packing or encoding payloads, building reverse shells, creating EDR-test binaries, or producing initial-access artifacts during authorized red team engagements.

2.2k 16d ago A 58 tokens original MIT

persistence-planner

38

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants to plan and document persistence during an authorized red team engagement — host persistence (Windows/Linux), Active Directory persistence (golden/silver tickets, DCShadow, AdminSDHolder, GPO), and cloud persistence — with mandatory cleanup tracking and detection guidance…

2.2k 16d ago A 67 tokens original MIT

phishing-operator

39

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about setting up phishing infrastructure, configuring Evilginx3 or GoPhish, adversary-in-the-middle credential capture, MFA token relay, domain lookalike detection with dnstwist, or building phishing landing pages for authorized red team engagements.

2.2k 16d ago A 63 tokens original MIT

poc-validator

40

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants to validate a vulnerability finding with a safe Proof of Concept, eliminate false positives from scan results, automatically generate and execute PoC scripts for confirmed vulnerabilities, or verify that a reported bug is real before including it in a pentest report.

2.2k 16d ago B 60 tokens original MIT

privesc-advisor

41

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about privilege escalation techniques, local enumeration, Linux or Windows privilege escalation, container escape, or needs help escalating access on a compromised system during authorized testing.

2.2k 16d ago D 45 tokens original MIT

recon-advisor

42

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user pastes scan output (Nmap, Nessus, Nikto, masscan, etc.), asks about reconnaissance techniques, needs help with enumeration, wants to analyze an attack surface, or wants to run recon tools against authorized targets. Can execute reconnaissance commands directly with user approval.

2.2k 16d ago C 68 tokens original MIT

report-generator

43

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user needs to write a penetration test report, compile findings into a document, create an executive summary, format technical findings, or produce any security assessment documentation.

2.2k 16d ago A 41 tokens original MIT

reverse-engineer

44

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about static reverse engineering, working with Ghidra, Radare2, IDA, JadX, decompiling Android APKs, analyzing firmware with Binwalk, reading disassembly, or understanding the structure of a binary without running it.

2.2k 16d ago A 62 tokens original MIT

risk-scorer

45

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants to score and prioritize findings — build CVSS 3.1/4.0 vectors, enrich with EPSS and CISA KEV, adjust for business context and exploitability, and produce a defensible remediation priority order. Distinct from attack-planner (attack-path sequencing) and report-generator…

2.2k 16d ago A 78 tokens original MIT

scada-attacker

46

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user wants authorized ICS/OT/SCADA security testing — Modbus/DNP3/S7comm/EtherNet-IP/OPC-UA protocol analysis, PLC/HMI/RTU enumeration, and Purdue-model attack-path mapping. Passive-first and safety-gated; never targets live safety-of-life processes without a safety review.

2.2k 16d ago A 77 tokens original MIT

social-engineer

47

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about social engineering, phishing campaigns, pretexting, vishing, physical social engineering, security awareness testing, or human-factor security assessments.

2.2k 16d ago A 40 tokens original MIT

stig-analyst

48

0xSteph/pentest-ai-agents

Agent

Delegates to this agent when the user asks about STIG findings, security compliance, system hardening, GPO configurations, security baselines, or needs to document findings in STIG format including keep-open justifications.

2.2k 16d ago A 49 tokens original MIT