blacklanternsecurity/red-run

Offensive security toolkit for Claude Code

This repository also configures its own agents. See what red-run tells them →

267Stars on the repository
104Mods indexed here, across every type
5mo agoLast push, which is what freshness is scored on
GPL-3.0Licence, which decides whether bodies are shown

pivoting-tunneling

25

blacklanternsecurity/red-run

Skill Claude CodeCodex

Network pivoting, port forwarding, and tunneling through compromised hosts to reach internal networks.

not rated 267 5mo ago B 24 tokens GPL-3.0

blacklanternsecurity/red-run

Skill Claude CodeCodex

Enumeration of remote access services: FTP, SSH, RDP, VNC, and WinRM. Checks anonymous access, default credentials, version vulnerabilities, and authentication methods. Use after network-recon identifies remote access ports.

not rated 267 5mo ago A 50 tokens GPL-3.0

smb-enumeration

27

blacklanternsecurity/red-run

Skill Claude CodeCodex

SMB share enumeration, access testing, password policy extraction, and content searching. Enumerates shares via null session, guest, and authenticated access. Covers share listing, per-share access testing, MANSPIDER content search, and SMB vulnerability detection (signing, EternalBlue). Use after network-recon…

not rated 267 5mo ago A 74 tokens GPL-3.0

smb-exploitation

28

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploit remote SMB vulnerabilities for unauthenticated code execution on Windows hosts.

not rated 267 5mo ago A 20 tokens GPL-3.0

xmpp-enumeration

29

blacklanternsecurity/red-run

Skill Claude CodeCodex

XMPP/Jabber service enumeration for Openfire, ejabberd, Prosody, and other XMPP servers. Trigger when ports 5222 (client), 5223 (legacy TLS), or 5269 (server-to-server) are found open. Covers authentication testing, user enumeration, MUC room discovery, and server fingerprinting. Do NOT use for AD enumeration or…

not rated 267 5mo ago A 92 tokens GPL-3.0

credential-recovery

30

blacklanternsecurity/red-run

Skill Claude CodeCodex

Offline credential and file recovery with hashcat and john. Use when any skill captures hashes (NTLM, Kerberos TGS/AS-REP, shadow, MSCACHE2) or encrypted files (ZIP, Office, PDF, KeePass, SSH key, 7z, RAR). Trigger phrases: "recover this hash", "offline recovery", "john", "hashcat", "zip2john", "password-protected…

not rated 267 5mo ago D 117 tokens GPL-3.0

linux-discovery

32

blacklanternsecurity/red-run

Skill Claude CodeCodex

Linux local privilege escalation enumeration and attack surface mapping.

not rated 267 5mo ago A ✓ AI review 14 tokens GPL-3.0

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploit writable critical files, NFS misconfigurations, shared library hijacking, and privileged group membership (docker, lxd, disk, adm, video, staff) for Linux privilege escalation. Use when a user belongs to a privileged group or has write access to sensitive files or paths.

not rated 267 5mo ago C 65 tokens GPL-3.0

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploit Windows kernel vulnerabilities, vulnerable drivers, and privileged file operations for local privilege escalation to SYSTEM.

not rated 267 5mo ago A 27 tokens GPL-3.0

blacklanternsecurity/red-run

Skill Claude CodeCodex

Analyze custom applications, scripts, and binaries that standard technique skills could not exploit. Performs source code review, attack surface mapping, CVE research, and PoC adaptation. Route here when ANY technique agent returns saying standard patterns do not match, the target uses a custom/unknown application, or…

not rated 267 5mo ago A 115 tokens GPL-3.0

retrospective

43

blacklanternsecurity/red-run

Skill Claude CodeCodex

Post-engagement lessons-learned retrospective. Reads the engagement directory, analyzes skill routing decisions, identifies knowledge gaps and missing skills, and produces an actionable improvement report.

not rated 267 5mo ago A 37 tokens GPL-3.0

2fa-bypass

44

blacklanternsecurity/red-run

Skill Claude CodeCodex

Bypass two-factor authentication (2FA/MFA) during authorized penetration testing.

not rated 267 5mo ago A 21 tokens GPL-3.0

ajp-ghostcat

45

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploit Apache JServ Protocol (AJP) misconfigurations and Ghostcat (CVE-2020-1938) for file read and remote code execution on Apache Tomcat. Use when port 8009 is open or AJP connector is exposed.

not rated 267 5mo ago A 59 tokens GPL-3.0

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploit browser-based attack surfaces: malicious extension crafting for bot interaction scenarios, Chrome DevTools Protocol abuse on exposed debug ports, and browser profile/cache data extraction from compromised hosts.

not rated 267 5mo ago B 39 tokens GPL-3.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: