lateral-movement
121Skill Claude Code
Network lateral movement — Pass-the-Hash, Pass-the-Ticket, WMI/WinRM/PsExec/RDP execution, SMB operations, network tunneling with Ligolo-ng and Chisel.
Harness-driven terminal AI agent for authorized security assessment, with TUI, headless automation, persistent context, 150 built-in skills, and a dedicated pentest mode.
This repository also configures its own agents. See what Mingyi-Atlas tells them →
Skill Claude Code
Network lateral movement — Pass-the-Hash, Pass-the-Ticket, WMI/WinRM/PsExec/RDP execution, SMB operations, network tunneling with Ligolo-ng and Chisel.
Skill Claude Code
Post-exploitation finding documentation — credential access, privilege escalation, lateral movement reports, detection gap analysis, attack path documentation, CVSS v4.0 scoring.
Skill Claude Code
Active target probing — port scanning, service detection, vulnerability scanning, banner grabbing, web directory fuzzing, SSL/TLS analysis.
Skill Claude Code
Cloud infrastructure enumeration — AWS S3 buckets, Azure blob storage, GCP buckets, cloud metadata endpoints, IAM misconfigurations, CDN origin detection.
Skill Claude Code
Open-source intelligence gathering — email harvesting, social media profiling, breach data checking, employee enumeration, GitHub secret scanning, organizational mapping.
Skill Claude Code
Passive intelligence gathering without touching the target — DNS, WHOIS, subdomain enumeration, Certificate Transparency, technology fingerprinting, ASN mapping.
Skill Claude Code
Recon output formatting — report structure, CVSS v4.0 scoring (primary), MITRE ATT&CK mapping, finding prioritization, Markdown output, detection gap tracking, handoff checklists.
Skill Claude Code
Web application enumeration hub — directory/file fuzzing, vhost discovery, API enumeration, CMS scanning, WAF detection, auth surface mapping, cookie audit.
Skill Claude Code
REST API discovery, GraphQL detection, parameter fuzzing.
Skill Claude Code
Authentication surface — login endpoints, JWT/OAuth/SAML/SSO/API-key mechanism identification.
Skill Claude Code
CMS-specific scans — WordPress (wpscan), Joomla, Drupal version detection.
Skill Claude Code
Cookie-conditional sink discovery — bisect required cookies per sink, session-write timeline for race-condition challenges.
Skill Claude Code
Web app discovery — directory/file fuzzing, vhost discovery, JavaScript endpoint extraction.
Skill Claude Code
Web Application Firewall fingerprinting — Cloudflare, AWS WAF, Akamai, Imperva, etc.
Skill Claude CodeCodex
Root pointer for the binary reversing lane. Covers triage, string extraction, packer unpacking, symbol risk, ROP, Ghidra deep analysis, and firmware extraction.
Skill Claude CodeCodex
Detect and neutralize anti-debug / anti-VM checks — IsDebuggerPresent, ptrace, NtGlobalFlag, timing, hardware-breakpoint detection.
Skill Claude CodeCodex
Router / IoT firmware extraction pipeline — unpack nested filesystems, locate web server, identify backdoor credentials.
Skill Claude CodeCodex
Deep binary analysis via Ghidra — headless analyzeHeadless or live MCP bridge with 245 tools. Decompilation, xrefs, function listing, batch operations, P-code emulation, convention enforcement.
Skill Claude Code
Skill "ios-static" from MingyiSecLab/Mingyi-Atlas, covering ios ipa static analysis, acquire the ipa, option 2: ipatool — pulls ipas from your apple id, option 3: frida-ios-dump (jailbroken device required) and pulls a decrypted ipa from the device's memory.
Skill Claude Code
Fast malware triage workflow — static (PE/Mach-O/ELF format, strings, imports, signatures, entropy/packed indicators), dynamic (sandbox with INetSim, Wireshark, Process Monitor, Procmon, time-shift), unpack (Scylla/PE-sieve), then full RE with Ghidra/IDA. Designed for ≤15 min initial verdict.
Skill Claude CodeCodex
Identify and unpack common binary packers — UPX, ASPack, Themida, VMProtect, MPRESS, PECompact, Enigma.
Skill Claude CodeCodex
ROP/JOP gadget hunting and exploit-chain construction — for NX/DEP bypass on x86/x64/ARM binaries.
Skill Claude CodeCodex
Fast-path binary triage — identify format/arch/mitigations, grab high-signal strings and imports in under a minute.
Skill Claude Code
YARA rule authoring + hunting — condition: syntax, hex patterns with wildcards, for/any of them, PE module, ELF module, hash module, math module. Build per-family signatures, hunt at scale via VT/MalwareBazaar/Hybrid Analysis. Avoid common pitfalls (collisions, slow rules, regex traps).
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: