jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Active Directory penetration testing — BloodHound enumeration, Kerberos attacks (Kerberoasting, AS-REP, Golden/Silver Ticket), NTLM relay, DCSync, lateral movement, domain dominance.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Active Directory penetration testing — BloodHound enumeration, Kerberos attacks (Kerberoasting, AS-REP, Golden/Silver Ticket), NTLM relay, DCSync, lateral movement, domain dominance.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Skill "advanced-redteam" from jessefmoore/offensive-claude-code, covering advanced red team operations, when to activate, c2 infrastructure design, redirectors (never expose team server directly) and cobalt strike team server (bind locally).
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
AI/ML security assessment — prompt injection, jailbreak detection, RAG poisoning, model extraction, adversarial examples, supply chain risks in ML pipelines.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Cloud penetration testing — AWS/Azure/GCP privilege escalation, container escape, Kubernetes attacks, serverless exploitation, IaC misconfigurations.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Advanced software engineering — systems programming, exploit development tooling, automation scripting, network programming, cryptography implementation.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Cryptographic assessment — cipher identification, TLS auditing, hash analysis, key strength evaluation, side-channel detection, crypto implementation review.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
EDR/AV bypass — hook unhooking, direct/indirect syscalls, PPID spoofing, process injection, AMSI bypass, ETW patching, memory encryption, behavioral evasion.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
PoC development, payload crafting, shellcode generation, ROP chains, heap exploitation, bypass techniques for modern mitigations (ASLR, DEP, CFI, stack canaries).
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
HackSmarter labs (VPN-attached training range) — environment conventions, the recurring lab archetypes, opening recon playbook, and a per-lab technique index for the 2025 set. Use when attacking any HackSmarter lab over the VPN.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Hack The Box is a single-machine environment. There is no internal network to laterally traverse (except on Pro Labs / Fortress), no client to report to, and no engagement window. The objective is always the same: retrieve user.txt then root.txt. Every action is aimed at those two flags.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
IR playbook execution — evidence collection, timeline analysis, memory forensics, disk forensics, containment strategies, post-incident reporting.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Modern initial access techniques — phishing, payload delivery, HTML smuggling, ISO/IMG bypass, supply chain attacks, credential stuffing, exposed service exploitation.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Skill "keylogger-arch" from jessefmoore/offensive-claude-code, covering keylogger architecture, when to activate, method 1: setwindowshookex (whkeyboardll), how it works and internal mechanism.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Static/dynamic malware analysis, YARA rules, sandbox evasion detection, behavioral profiling, unpacking, anti-analysis bypass.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Mobile application penetration testing — Android/iOS static/dynamic analysis, Frida instrumentation, SSL pinning bypass, root/jailbreak detection bypass, deep-link abuse, exported components, insecure storage, biometric bypass.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
NetExec (nxc) is a network service exploitation tool for assessing large networks. It supports SMB, LDAP, WinRM, MSSQL, SSH, FTP, RDP, WMI, NFS, and VNC protocols.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Network penetration testing — lateral movement, pivoting, protocol attacks, traffic interception, Active Directory exploitation, wireless attacks.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Engagement orchestration — drives a comprehensive pentest as a decision loop (orient via kb/INDEX.md → load the phase runbook → load the domain skill → execute → validate → capture finding → re-assess next steps). Invoke at the start of any engagement/lab/HTB box, or whenever you want Claude to figure out the next…
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Linux privilege escalation and persistence — SUID/SGID abuse, kernel exploits, capabilities, sudo misconfig, cron jobs, writable paths, library hijacking, credential hunting, container escape, LXD/LXC, systemd timers, PAM skeleton key, polkit, MOTD, udev, git hooks, shell profile, NetworkManager, package manager…
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Windows privilege escalation — token abuse, service exploitation, UAC bypass, credential harvesting, AD escalation paths.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Comprehensive reconnaissance and OSINT — subdomain enumeration, CVE lookup, breach intelligence, DNS history, social profiling, attack surface mapping.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Full red team engagement — initial access, persistence, privilege escalation, defense evasion, C2 infrastructure, EDR bypass, living-off-the-land.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Binary analysis, disassembly, decompilation, firmware RE, protocol reverse engineering, anti-reversing bypass, malware unpacking.
jessefmoore/offensive-claude-code
Skill Claude CodeCodex
Shellcode development — PIC techniques, PEB walking, API hashing, null-byte avoidance, encoders, loaders, PE-to-shellcode conversion, cross-platform shellcode.