mukul975/Threatswarm

27 scope-enforced AI agents that run the full pentest kill-chain (recon → exploit → post-ex → DFIR → report) as a one-command Claude Code plugin. Backed by 754 MITRE-mapped skills.

77Stars on the repository
43Mods indexed here, across every type
4mo agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

attack

01

mukul975/Threatswarm

Command Claude Code

Route an attack vector to the appropriate specialist agent — usage: /project:attack.

77 +2 4mo ago A 22 tokens original MIT

engage

02

mukul975/Threatswarm

Command Claude Code

Start a new engagement for a target — verifies scope, creates evidence directories, and launches recon agent.

77 +2 4mo ago A 19 tokens original MIT

hunt

03

mukul975/Threatswarm

Command Claude Code

Run an ATT&CK-based threat hunt with a specific hypothesis.

77 +2 4mo ago A 12 tokens original MIT

ir

04

mukul975/Threatswarm

Command Claude Code

Incident response workflow — triage, evidence collection, timeline, and IOC extraction.

77 +2 4mo ago A 15 tokens original MIT

pwned

05

mukul975/Threatswarm

Command Claude Code

Post-exploitation workflow after getting shell access — privesc, credential harvest, lateral movement.

77 +2 4mo ago C 18 tokens original MIT

report

06

mukul975/Threatswarm

Command Claude Code

Generate a professional penetration test report from all evidence files.

77 +2 4mo ago A 10 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: