The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation improves the next.
About the project
CyberStrikeAI is a security operations workspace that turns natural-language plans into governed, auditable actions while recording evidence and results for later reuse. Authorized security teams use it to manage agents, tools, vulnerabilities, knowledge, and attack-chain analysis. Catalogue add-ons provide agent and skill workflows for working with the platform.
Helps users discover and install agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities. This skill should be used when the user is looking for functionality that might exist as an installable skill.
A collection of methods for testing and attacking Windows Active Directory networks, which manage users, computers, and permissions inside many organizations.
A security-testing skill for applications that use artificial-intelligence models, agents, retrieval systems, tool plugins, or model files. It focuses on risks such as prompt injection, unsafe tool use, data poisoning, and dangerous model-file loading.
A security-recon workflow for finding a domain’s internet-facing assets, such as subdomains, services, ports, and technology fingerprints. It uses passive sources first, then active checks.
A method for finding attack chains by combining smaller capabilities such as reading files, writing files, making server requests, or using credentials. It treats a serious outcome as a sequence of separately gained abilities.
A security-research workflow for an identified software component and version. It searches vulnerability databases, search engines, security communities, code repositories, and asset sources before exploitation is attempted.
A demonstration package for testing how an agent skill and its supporting files can be listed, retrieved, and read through HTTP and Eino tools. Eino is an agent-development framework.
A guide to gaining initial access to computer systems through phishing, stolen credentials, device-code scams, malicious app permissions, and social engineering.
A persistent security-testing notebook that stores project facts, evidence, relationships, and confirmed vulnerabilities in a SQLite database. SQLite is a small database kept with the project’s working environment.
A formatting standard for penetration testing, which is authorized security testing that looks for vulnerabilities. It defines Chinese reporting, evidence, negative results, change tracking, and status summaries.
A post-exploitation playbook for authorised security testing after access has been gained. It covers privilege escalation, credential recovery, movement between systems, tunnelling, evasion, command-and-control, and persistence.
A workflow for changing network routes and preparing tools when requests are blocked or local tools are missing. It covers SOCKS5 and HTTP proxies, Tor, Python-based tool setup, and out-of-band confirmation infrastructure.
A set of operational-security practices for authorised red-team work, meaning simulated attacks used to test defences. It covers avoiding detection, controlling request speed, reducing traces, and gradually increasing exposure.
A collection of cybersecurity playbooks for investigating and exploiting specific systems, including GoEdge CDN, ARP man-in-the-middle attacks, BT Panel, OCS, MinIO, and CDN-to-S3 access chains.
A security-testing principle for investigating targets across many areas, including websites, mobile apps, cloud systems, wireless devices, and social engineering.
A reference guide to testing common web security weaknesses, including database injection, cross-site scripting, authentication flaws, server-side request forgery, and file-handling issues.
A toolkit and guide for testing wireless and physical device interfaces, including Wi‑Fi, Bluetooth Low Energy, Zigbee, NFC/RFID, software-defined radio, and hardware ports.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: