Active Directory enumeration and attack techniques. Includes LDAP enumeration, Kerberos attacks (Kerberoasting, AS-REP Roasting), SMB attacks, and domain privilege escalation. Use this when targeting Windows domain environments.
Service-specific enumeration based on discovered ports. Automatically selects appropriate enumeration techniques for each service. Use after /bb-recon to deeply enumerate discovered services.
Privilege escalation enumeration and exploitation for Linux and Windows systems. Automatically detects OS and runs appropriate enumeration tools (linpeas/winpeas). Use this after obtaining initial shell access.
Automated network reconnaissance against a target. Runs comprehensive port scanning with nmap, identifies services, and discovers attack surface. Use this as the first step when attacking an HTB machine.
Manage reverse shell listeners using tmux sessions. Start listeners, receive shells, send commands, and persist across sessions. Essential for maintaining access during exploitation.
Comprehensive web application testing for HTTP/HTTPS services. Includes directory fuzzing, vulnerability scanning, technology fingerprinting, and common exploit checks. Use this when a web service is discovered.
Full automated black-box penetration testing methodology for HTB machines. Runs all phases: setup verification, reconnaissance, enumeration, vulnerability identification, and exploitation guidance. Use this command when starting a new HTB machine challenge.
5 6mo agoB45 tokens
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: