PurpleAILAB

60 mods across 1 repository, 5.4k stars between them.

volt-typhoon

49

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Adversary-emulation profile for Volt Typhoon (G1017), a PRC state-sponsored actor pre-positioning in US critical infrastructure via living-off-the-land TTPs.

5.4k +48 2d ago A 42 tokens original Apache-2.0

defense-evasion

50

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Endpoint defense bypass — AMSI/ETW patching, ScareCrow framework, custom loaders, direct/indirect syscalls, LOLBAS execution, process injection.

5.4k +48 2d ago A 40 tokens original Apache-2.0

finding-protocol

51

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Operational-tier finding template — minimal fields for sub-agent decision support. Heavyweight deliverable promotion lives in skills/decepticon/final-report.

5.4k +48 2d ago A 32 tokens original Apache-2.0

opsec

52

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Operational security management — traffic shaping, scan rate limiting, source IP management, tool signature avoidance, evidence handling, anti-detection patterns.

5.4k +48 2d ago A 30 tokens original Apache-2.0

references

53

PurpleAILAB/Decepticon

Skill Claude CodeCodex

External knowledge integration — HackerOne reports, PayloadsAllTheThings, Book of Secret Knowledge, CVE PoC corpora, bug bounty methodologies, and reference pentest agent architectures. Use these to calibrate, look up payloads, and accelerate research.

5.4k +48 2d ago A 54 tokens original Apache-2.0

stealth-infra

54

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Anti-bot evasion, proxy rotation, credential retrieval from password managers, and stealth HTTP tooling for covert web operations.

5.4k +48 2d ago B 29 tokens original Apache-2.0

ad-overview

55

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction.

5.4k +48 2d ago A 31 tokens original Apache-2.0

adcs-esc1

56

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Exploit Active Directory Certificate Services ESC1 — vulnerable template allows arbitrary SAN, enabling user impersonation up to domain admin.

5.4k +48 2d ago A 30 tokens original Apache-2.0

asrep-roasting

57

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Request AS-REP for accounts with DONTREQPREAUTH set and crack offline — like kerberoast but no auth required.

5.4k +48 2d ago A 31 tokens original Apache-2.0

bloodhound-bhce

58

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Operate BloodHound Community Edition v9.2.2 via Decepticon's bhce tools — health check, Cypher passthrough, SharpHound ZIP ingest. Replaces the in-house ingest + ESC post-process pipeline per ADR-0005.

5.4k +48 2d ago A 61 tokens original Apache-2.0

bloodhound-query

59

PurpleAILAB/Decepticon

Skill Claude CodeCodex

BloodHound ingestion + canonical Cypher queries for AD attack-path enumeration. Run after collector dumps zip; promotes findings into the knowledge graph.

5.4k +48 2d ago A 32 tokens original Apache-2.0

PurpleAILAB/Decepticon

Skill Claude CodeCodex

ADCS abuse via Certipy — find vulnerable templates (ESC1-ESC15), request a certificate, authenticate as the target, dump the krbtgt. Full chain in 4 commands. Covers ESC1 (any SAN), ESC2 (any-purpose EKU), ESC3 (enrollment-agent), ESC4 (vulnerable ACL), ESC8 (NTLM relay to CA), ESC9/10/11/13.

5.4k +48 2d ago B 94 tokens original Apache-2.0