Agent Claude Code
Plans Active Directory attack paths from enumeration or BloodHound data. Use on domain-joined Windows rooms.
Agent Claude Code
Plans Active Directory attack paths from enumeration or BloodHound data. Use on domain-joined Windows rooms.
Agent Claude Code
Maps discovered service versions to known CVEs and public exploits. Use after version detection.
Agent Claude Code
Suggests privilege escalation paths from enumeration output. Use once you have a foothold.
Agent Claude Code
Parses raw scan output into structured findings. Use after any nmap/ffuf/nikto run.
Agent Claude Code
Turns notes.md and scans into a clean writeup. Use when a room is solved.
Agent Claude Code
Ranks Windows privilege escalation paths from enum output. Use after winPEAS/whoami/systeminfo on a Windows box.
Command Claude Code
Identify and crack a hash or password-protected file.
Command Claude Code
Enumerate/exploit a database — connect and read first, heavy brute only when justified.
Command Claude Code
Enumerate a Windows / Active Directory target (SMB, LDAP, RPC, users).
Command Claude Code
Enumerate SMB/NetBIOS — cheap listing first, heavy brute/enumeration only when it'll pay off.
Command Claude Code
UDP scan + service follow-up — top ports first, full sweep only when justified.
Command Claude Code
Enumerate a web service — cheap recon first, heavy scans only when they'll pay off.
Command Claude Code
Kerberos attacks — AS-REP roasting and Kerberoasting.
Command Claude Code
Linux local privilege escalation — enumeration checklist and analysis.
Command Claude Code
Set up a reverse shell listener and generate matching payloads.
Command Claude Code
Maintain the ROOM BRAIN — the structured state file the coach reasons from.
Command Claude Code
Network forensics with tshark — creds, files, attacks, exfil; overview first, digs gated.
Command Claude Code
Run staged nmap recon against the target and parse results.
Command Claude Code
Room coach — does setup, then teaches you through the room step by step, adapting to how stuck you are.
Command Claude Code
Offline file / image analysis — steganography, metadata, embedded data.
Command Claude Code
Pivot / tunnel into an internal network through a compromised host.
Command Claude Code
Verify THM VPN is up and the target is reachable.
Command Claude Code
Subdomain / virtual-host / certificate recon (the DNS-side of web enum).
Command Claude Code
Windows local privilege escalation — enumeration checklist and analysis.