techniques
25Command
View and search the techniques & reports database.
Command
View and search the techniques & reports database.
Command
Chronological engagement timeline — all events merged by time.
Command
Web vulnerability scanning with multiple engines (nuclei, nikto, AI assessment).
Command
WordPress-specific vulnerability scanning and enumeration.
Hook
Runs when a session starts, executing session-state.js via node. From ogrodev/fsociety.
Hook
Runs before the agent uses a tool for mcp__hexstrike-ai__.* tool calls, executing pre-scan-check.js via node. From ogrodev/fsociety.
Hook
Runs after a tool call finishes for mcp__hexstrike-ai__.* tool calls, executing post-scan-hook.js via node. From ogrodev/fsociety.
Hook
Runs when the agent finishes a response, executing session-state.js via node. From ogrodev/fsociety.
Skill Claude CodeCodex
Activate this skill whenever the user mentions API endpoint, REST API, RESTful, GraphQL, GraphQL introspection, GraphQL mutation, gRPC, gRPC reflection, WebSocket, WebSocket upgrade, WS endpoint, API security, API fuzzing, API enumeration, API versioning, API gateway, API rate limit, JWT, JSON Web Token, bearer token…
Skill Claude CodeCodex
Activate this skill whenever the user mentions cloud lateral movement, cloud privilege escalation, cloud post-exploitation, cloud red team, multi-cloud attack, cloud pentesting, AWS, Amazon Web Services, EC2, S3, Lambda, IAM, STS, SSM, Systems Manager, CloudTrail, GuardDuty, CloudShell, Secrets Manager, Parameter…
Skill Claude CodeCodex
Activate this skill whenever the user mentions port scan, port scanning, nmap, nmap scan, masscan, rustscan, service detection, service enumeration, service fingerprinting, network scan, network scanning, network mapping, network discovery, network topology, open ports, closed ports, filtered ports, banner grabbing…
Skill Claude CodeCodex
This skill should be used when the user mentions "brute force", "password cracking", "hydra", "hashcat", "john the ripper", "credential stuffing", "password spray", "password spraying", "hash cracking", "wordlist", "dictionary attack", "mask attack", "rainbow table", "NTLM", "NTLMv2", "bcrypt", "Kerberoast"…
Skill Claude CodeCodex
This skill should be used when the user mentions "payment", "payment gateway", "checkout", "IDOR payment", "payment bypass", "Stripe", "MercadoPago", "Binance Pay", "PIX", "PayPal", "Adyen", "Braintree", "Square", "Razorpay", "Mollie", "webhook", "payment webhook", "price manipulation", "amount tampering", "currency…
Skill Claude CodeCodex
This skill should be used when the user mentions "generate report", "pentest report", "engagement report", "findings report", "executive summary", "technical report", "vulnerability report", "remediation report", "remediation plan", "retest report", "write up findings", "document findings", "report findings", "create…
Skill Claude CodeCodex
This skill should be used when the user mentions "WAF", "web application firewall", "WAF bypass", "WAF evasion", "WAF detection", "WAF fingerprint", "wafw00f", "firewall bypass", "firewall evasion", "request filtering", "request blocked", "payload blocked", "blocked by WAF", "403 forbidden", "406 not acceptable", "429…
Skill Claude CodeCodex
This skill activates when the user mentions "XSS", "cross-site scripting", "reflected XSS", "stored XSS", "DOM XSS", "blind XSS", "SQL injection", "SQLi", "blind SQLi", "union injection", "error-based injection", "time-based injection", "stacked queries", "second-order injection", "SSRF", "server-side request…
Skill Claude CodeCodex
Activate this skill whenever the user mentions WordPress, WP, WooCommerce, WP plugin, WP theme, wp-admin, wp-content, wp-login, wp-json, wp-includes, xmlrpc, XML-RPC, wp-cron, admin-ajax, wp-config, wpscan, WordPress vulnerability, WordPress exploit, WordPress enumeration, WordPress brute force, WordPress RCE…
Command
Initialize a new engagement workspace — gather targets, select plugins, check tools, generate project files.
Skill Claude CodeCodex
This skill should be used when the user mentions "new engagement", "setup engagement", "initialize workspace", "start operation", "new pentest", "setup project", "create workspace", "engagement setup", "initialize engagement", "new investigation", "start campaign", "new operation", "workspace init", "set up a new…
Agent
Use this agent when the user asks to "reverse engineer a binary", "analyze an executable", "disassemble this file", "decompile a DLL", "find malware indicators", "extract strings from binary", "analyze PE headers", "check for packing", "analyze .NET assembly", "classify this binary", "extract secrets from executable"…
Command
Full static analysis workflow — PE headers, strings, disassembly, classification.
Command
Malware classification — YARA scanning, entropy analysis, packer detection.
Command
Ghidra headless decompilation with function analysis.
Command
Binary diffing — compare two binaries for patch analysis.