mukul975

169 mods across 10 repositories, 33k stars between them.

social-engineer

145

mukul975/Threatswarm

Agent Claude Code

Social engineering and phishing simulation specialist. Handles GoPhish campaign setup, spear-phishing email crafting, evilginx2 adversary-in-the-middle phishing, pretexting scripts, vishing scenarios, SMS phishing, and awareness training. Triggers on: phishing, spear phishing, gophish, vishing, smishing, pretexting…

75 4mo ago A 90 tokens original MIT

threat-hunter

146

mukul975/Threatswarm

Agent Claude Code

Proactive threat hunting specialist using ATT&CK-based hypotheses. Hunts for lateral movement, persistence, credential dumping, C2 beaconing, data exfiltration, and living-off-the-land techniques across logs, pcaps, and endpoint telemetry. Triggers on: threat hunt, hunt, hypothesis, ATT&CK, lateral movement detection…

75 4mo ago A 91 tokens original MIT

vuln-researcher

147

mukul975/Threatswarm

Agent Claude Code

Vulnerability research and CVE analysis specialist. Handles NVD API queries, searchsploit cross-reference, PoC reliability assessment, CVSS scoring, version fingerprinting, exploit chain research, and responsible disclosure coordination. Triggers on: CVE, vulnerability research, searchsploit, NVD, exploit, CVSS score…

75 4mo ago A 84 tokens original MIT

web-attacker

148

mukul975/Threatswarm

Agent Claude Code

Web application penetration testing — SQL injection, XSS, SSRF, LFI, IDOR, JWT attacks, GraphQL, API parameter discovery, and OWASP Top 10 exploitation.

75 4mo ago B 41 tokens original MIT

wireless-attacker

149

mukul975/Threatswarm

Agent Claude Code

Wireless network penetration testing specialist. Handles WPA2/WPA3 capture and cracking, PMKID attacks, Evil Twin / rogue AP attacks, WPS PIN attacks, EAP/PEAP credential capture, Bluetooth assessment, and wireless deauthentication. Triggers on: wifi, wireless, WPA2, WPA3, aircrack, airmon, WPS, evil twin, rogue AP…

75 4mo ago A 110 tokens original MIT

attack

150

mukul975/Threatswarm

Command Claude Code

Route an attack vector to the appropriate specialist agent — usage: /project:attack.

75 4mo ago A 22 tokens original MIT

engage

151

mukul975/Threatswarm

Command Claude Code

Start a new engagement for a target — verifies scope, creates evidence directories, and launches recon agent.

75 4mo ago A 19 tokens original MIT

hunt

152

mukul975/Threatswarm

Command Claude Code

Run an ATT&CK-based threat hunt with a specific hypothesis.

75 4mo ago A 12 tokens original MIT

ir

153

mukul975/Threatswarm

Command Claude Code

Incident response workflow — triage, evidence collection, timeline, and IOC extraction.

75 4mo ago A 15 tokens original MIT

pwned

154

mukul975/Threatswarm

Command Claude Code

Post-exploitation workflow after getting shell access — privesc, credential harvest, lateral movement.

75 4mo ago C 18 tokens original MIT

report

155

mukul975/Threatswarm

Command Claude Code

Generate a professional penetration test report from all evidence files.

75 4mo ago A 10 tokens original MIT

PreToolUse

156

mukul975/Threatswarm

Hook Claude Code

Runs before the agent uses a tool for Bash tool calls, executing scope_check.py via python3. From mukul975/Threatswarm.

75 4mo ago A tokens not measured original MIT

PostToolUse

157

mukul975/Threatswarm

Hook Claude Code

Runs after a tool call finishes for Bash tool calls, executing cmd_log.sh via bash. From mukul975/Threatswarm.

75 4mo ago A tokens not measured original MIT

Stop

158

mukul975/Threatswarm

Hook Claude Code

Runs when the agent finishes a response, executing findings_sync.py via python3. From mukul975/Threatswarm.

75 4mo ago A tokens not measured original MIT

Threatswarm

159

mukul975/Threatswarm

Settings file Claude Code

Agent settings declaring 3 hook events (PreToolUse, PostToolUse, Stop) and 103 allowed tools.

75 4mo ago C tokens not measured original MIT

ad-attacks

160

mukul975/Threatswarm

Skill Claude CodeCodex

Active Directory attack reference — BloodHound Cypher queries, Kerberos attack decision tree, ACE/ACL abuse, ADCS ESC1-8, and AD misconfig checklist.

75 4mo ago A 39 tokens original MIT

exploit-db

161

mukul975/Threatswarm

Skill Claude CodeCodex

Exploit-DB and searchsploit reference — EDB→Metasploit module mappings, PoC reliability rubric, CVSS tier quick reference, and searchsploit usage patterns.

75 4mo ago A 40 tokens original MIT

mitre-attack

162

mukul975/Threatswarm

Skill Claude CodeCodex

MITRE ATT&CK framework reference — tactics, techniques, and tool-to-TTP mappings for pentest documentation and detection rule writing.

75 4mo ago A 31 tokens original MIT

report-templates

163

mukul975/Threatswarm

Skill Claude CodeCodex

CVSS 3.1 vector examples, executive summary template, full technical finding template, and remediation language bank for pentest reports.

75 4mo ago B 30 tokens original MIT

wordlists

164

mukul975/Threatswarm

Skill Claude CodeCodex

SecLists path map, hashcat rules, CeWL usage, and custom wordlist generation for all attack categories.

75 4mo ago A 25 tokens original MIT

Threatswarm CLAUDE.md

165

mukul975/Threatswarm

Instructions file

Instructions for mukul975/Threatswarm, covering cybersecurity workspace — master context, scope enforcement (mandatory — zero exceptions), tool paths, agent delegation table and opsec defaults.

75 4mo ago C 4,171 tokens original MIT

threatswarm-plugin

166

mukul975/Threatswarm

Plugin Claude Code

Complete offensive security operator workspace: 27 specialist agents, 6 engagement commands, 5 reference skill libraries, scope-gated hooks, and evidence logging for professional penetration testing and red-team operations.

75 4mo ago A tokens not measured original MIT

mukul975/mcp-windows-automation

MCP server Claude CodeCodexCursor +2

MCP server "unified-windows-server" as configured in mukul975/mcp-windows-automation. Runs D:\MCP\mcpwindows\unified_server.py with python. Needs 1 environment variable to run.

50 3mo ago A tokens not measured original MIT

postgres-mcp-server

168

mukul975/postgres-mcp-server

MCP server Claude CodeCodexCursor +2

MCP server "postgres-mcp-server" as configured in mukul975/postgres-mcp-server. Runs postgres_server.py with python. Needs 1 environment variable to run.

8 5mo ago A tokens not measured original MIT