blacklanternsecurity

71 mods across 2 repositories, 311 stars between them.

blacklanternsecurity/red-run

Skill Claude CodeCodex

Enumeration of remote access services: FTP, SSH, RDP, VNC, and WinRM. Checks anonymous access, default credentials, version vulnerabilities, and authentication methods. Use after network-recon identifies remote access ports.

263 5mo ago A 50 tokens GPL-3.0

smb-enumeration

51

blacklanternsecurity/red-run

Skill Claude CodeCodex

SMB share enumeration, access testing, password policy extraction, and content searching. Enumerates shares via null session, guest, and authenticated access. Covers share listing, per-share access testing, MANSPIDER content search, and SMB vulnerability detection (signing, EternalBlue). Use after network-recon…

263 5mo ago A 74 tokens GPL-3.0

xmpp-enumeration

53

blacklanternsecurity/red-run

Skill Claude CodeCodex

XMPP/Jabber service enumeration for Openfire, ejabberd, Prosody, and other XMPP servers. Trigger when ports 5222 (client), 5223 (legacy TLS), or 5269 (server-to-server) are found open. Covers authentication testing, user enumeration, MUC room discovery, and server fingerprinting. Do NOT use for AD enumeration or…

263 5mo ago A 92 tokens GPL-3.0

credential-recovery

54

blacklanternsecurity/red-run

Skill Claude CodeCodex

Offline credential and file recovery with hashcat and john. Use when any skill captures hashes (NTLM, Kerberos TGS/AS-REP, shadow, MSCACHE2) or encrypted files (ZIP, Office, PDF, KeePass, SSH key, 7z, RAR). Trigger phrases: "recover this hash", "offline recovery", "john", "hashcat", "zip2john", "password-protected…

263 5mo ago D 117 tokens GPL-3.0

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploit writable critical files, NFS misconfigurations, shared library hijacking, and privileged group membership (docker, lxd, disk, adm, video, staff) for Linux privilege escalation. Use when a user belongs to a privileged group or has write access to sensitive files or paths.

263 5mo ago C 65 tokens GPL-3.0

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploit Windows kernel vulnerabilities, vulnerable drivers, and privileged file operations for local privilege escalation to SYSTEM.

263 5mo ago A 27 tokens GPL-3.0

blacklanternsecurity/red-run

Skill Claude CodeCodex

Analyze custom applications, scripts, and binaries that standard technique skills could not exploit. Performs source code review, attack surface mapping, CVE research, and PoC adaptation. Route here when ANY technique agent returns saying standard patterns do not match, the target uses a custom/unknown application, or…

263 5mo ago A 115 tokens GPL-3.0

retrospective

67

blacklanternsecurity/red-run

Skill Claude CodeCodex

Post-engagement lessons-learned retrospective. Reads the engagement directory, analyzes skill routing decisions, identifies knowledge gaps and missing skills, and produces an actionable improvement report.

263 5mo ago A 37 tokens GPL-3.0

2fa-bypass

68

blacklanternsecurity/red-run

Skill Claude CodeCodex

Bypass two-factor authentication (2FA/MFA) during authorized penetration testing.

263 5mo ago A 21 tokens GPL-3.0

ajp-ghostcat

69

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploit Apache JServ Protocol (AJP) misconfigurations and Ghostcat (CVE-2020-1938) for file read and remote code execution on Apache Tomcat. Use when port 8009 is open or AJP connector is exposed.

263 5mo ago A 59 tokens GPL-3.0

blacklanternsecurity/bbot-server

Instructions file CodexOpenCode

AGENTS.md instructions for blacklanternsecurity/bbot-server, covering agents.md, testing, running tests, start mongodb (if not already running) and start redis (if not already running).

48 7d ago A 609 tokens AGPL-3.0

blacklanternsecurity/bbot-server

Instructions file

Claude Code instructions for blacklanternsecurity/bbot-server, a project described as: A persistent database + CLI for your BBOT scan data 🧡.

48 7d ago A 3 tokens AGPL-3.0