Skill Claude CodeCodex
Network pivoting, port forwarding, and tunneling through compromised hosts to reach internal networks.
Skill Claude CodeCodex
Network pivoting, port forwarding, and tunneling through compromised hosts to reach internal networks.
Skill Claude CodeCodex
Enumeration of remote access services: FTP, SSH, RDP, VNC, and WinRM. Checks anonymous access, default credentials, version vulnerabilities, and authentication methods. Use after network-recon identifies remote access ports.
Skill Claude CodeCodex
SMB share enumeration, access testing, password policy extraction, and content searching. Enumerates shares via null session, guest, and authenticated access. Covers share listing, per-share access testing, MANSPIDER content search, and SMB vulnerability detection (signing, EternalBlue). Use after network-recon…
Skill Claude CodeCodex
Exploit remote SMB vulnerabilities for unauthenticated code execution on Windows hosts.
Skill Claude CodeCodex
XMPP/Jabber service enumeration for Openfire, ejabberd, Prosody, and other XMPP servers. Trigger when ports 5222 (client), 5223 (legacy TLS), or 5269 (server-to-server) are found open. Covers authentication testing, user enumeration, MUC room discovery, and server fingerprinting. Do NOT use for AD enumeration or…
Skill Claude CodeCodex
Offline credential and file recovery with hashcat and john. Use when any skill captures hashes (NTLM, Kerberos TGS/AS-REP, shadow, MSCACHE2) or encrypted files (ZIP, Office, PDF, KeePass, SSH key, 7z, RAR). Trigger phrases: "recover this hash", "offline recovery", "john", "hashcat", "zip2john", "password-protected…
Skill Claude CodeCodex
Exploit cron jobs, systemd timers/services, D-Bus services, and Unix sockets for privilege escalation.
Skill Claude CodeCodex
Linux local privilege escalation enumeration and attack surface mapping.
Skill Claude CodeCodex
Exploit writable critical files, NFS misconfigurations, shared library hijacking, and privileged group membership (docker, lxd, disk, adm, video, staff) for Linux privilege escalation. Use when a user belongs to a privileged group or has write access to sensitive files or paths.
Skill Claude CodeCodex
Exploit Linux kernel vulnerabilities and escape restricted shells for privilege escalation.
Skill Claude CodeCodex
Exploit sudo misconfigurations, SUID/SGID binaries, and Linux capabilities for privilege escalation.
Skill Claude CodeCodex
Harvest stored credentials from a Windows system for privilege escalation or lateral movement.
Skill Claude CodeCodex
Windows local privilege escalation enumeration and attack surface mapping.
Skill Claude CodeCodex
Exploit Windows kernel vulnerabilities, vulnerable drivers, and privileged file operations for local privilege escalation to SYSTEM.
Skill Claude CodeCodex
Exploit Windows service misconfigurations and DLL hijacking for local privilege escalation.
Skill Claude CodeCodex
Exploit Windows token privileges for local privilege escalation to SYSTEM.
Skill Claude CodeCodex
Bypass Windows User Account Control to escalate from medium to high integrity.
Skill Claude CodeCodex
Analyze custom applications, scripts, and binaries that standard technique skills could not exploit. Performs source code review, attack surface mapping, CVE research, and PoC adaptation. Route here when ANY technique agent returns saying standard patterns do not match, the target uses a custom/unknown application, or…
Skill Claude CodeCodex
Post-engagement lessons-learned retrospective. Reads the engagement directory, analyzes skill routing decisions, identifies knowledge gaps and missing skills, and produces an actionable improvement report.
Skill Claude CodeCodex
Bypass two-factor authentication (2FA/MFA) during authorized penetration testing.
Skill Claude CodeCodex
Exploit Apache JServ Protocol (AJP) misconfigurations and Ghostcat (CVE-2020-1938) for file read and remote code execution on Apache Tomcat. Use when port 8009 is open or AJP connector is exposed.
blacklanternsecurity/bbot-server
Instructions file CodexOpenCode
AGENTS.md instructions for blacklanternsecurity/bbot-server, covering agents.md, testing, running tests, start mongodb (if not already running) and start redis (if not already running).
blacklanternsecurity/bbot-server
Instructions file
Claude Code instructions for blacklanternsecurity/bbot-server, a project described as: A persistent database + CLI for your BBOT scan data 🧡.