volt-typhoon
49Skill Claude Code
Adversary-emulation profile for Volt Typhoon (G1017), a PRC state-sponsored actor pre-positioning in US critical infrastructure via living-off-the-land TTPs.
Autonomous Hacking Agent for Red Team
Decepticon is an autonomous red-team agent that coordinates AI agents, security tools, sandboxes, and supporting services for authorized cybersecurity assessments. Security researchers and red teams can run it through its Docker stack, cloud service, command-line interface, or Python SDK, with the catalogue entries representing its available skills.
Skill Claude Code
Adversary-emulation profile for Volt Typhoon (G1017), a PRC state-sponsored actor pre-positioning in US critical infrastructure via living-off-the-land TTPs.
Skill Claude Code
Endpoint defense bypass — AMSI/ETW patching, ScareCrow framework, custom loaders, direct/indirect syscalls, LOLBAS execution, process injection.
Skill Claude Code
Operational-tier finding template — minimal fields for sub-agent decision support. Heavyweight deliverable promotion lives in skills/decepticon/final-report.
Skill Claude Code
Operational security management — traffic shaping, scan rate limiting, source IP management, tool signature avoidance, evidence handling, anti-detection patterns.
Skill Claude CodeCodex
External knowledge integration — HackerOne reports, PayloadsAllTheThings, Book of Secret Knowledge, CVE PoC corpora, bug bounty methodologies, and reference pentest agent architectures. Use these to calibrate, look up payloads, and accelerate research.
Skill Claude Code
Anti-bot evasion, proxy rotation, credential retrieval from password managers, and stealth HTTP tooling for covert web operations.
Skill Claude CodeCodex
Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction.
Skill Claude CodeCodex
Exploit Active Directory Certificate Services ESC1 — vulnerable template allows arbitrary SAN, enabling user impersonation up to domain admin.
Skill Claude CodeCodex
Request AS-REP for accounts with DONTREQPREAUTH set and crack offline — like kerberoast but no auth required.
Skill Claude CodeCodex
Operate BloodHound Community Edition v9.2.2 via Decepticon's bhce tools — health check, Cypher passthrough, SharpHound ZIP ingest. Replaces the in-house ingest + ESC post-process pipeline per ADR-0005.
Skill Claude CodeCodex
BloodHound ingestion + canonical Cypher queries for AD attack-path enumeration. Run after collector dumps zip; promotes findings into the knowledge graph.
Skill Claude Code
ADCS abuse via Certipy — find vulnerable templates (ESC1-ESC15), request a certificate, authenticate as the target, dump the krbtgt. Full chain in 4 commands. Covers ESC1 (any SAN), ESC2 (any-purpose EKU), ESC3 (enrollment-agent), ESC4 (vulnerable ACL), ESC8 (NTLM relay to CA), ESC9/10/11/13.
Skill Claude Code
Authentication coercion against Windows / AD — PetitPotam (MS-EFSR), PrinterBug (MS-RPRN), DFSCoerce (MS-DFSNM), ShadowCoerce (MS-FSRVP), Coercer.py meta-tool. Force a Windows machine to NTLM-authenticate to attacker, then relay or crack offline.
Skill Claude CodeCodex
Abuse replication rights (DS-Replication-Get-Changes + GetChangesAll) to dump krbtgt and arbitrary user NT hashes from a DC.
Skill Claude CodeCodex
Request Kerberos TGS tickets for SPN-bound service accounts and crack offline with hashcat — classic AD priv-esc primitive.
Skill Claude CodeCodex
Extract LAPS-managed local administrator passwords from AD computer objects (ms-Mcs-AdmPwd / msLAPS-Password).
Skill Claude CodeCodex
NetExec (CrackMapExec successor) — unified SMB/LDAP/MSSQL/WinRM/RDP/SSH/FTP/VNC protocol auth + post-auth modules. 200+ modules incl. BloodHound auto-ingest, ESC1-15 scanning, PrintNightmare, LDAP relay.
Skill Claude Code
NTLM relay deep-dive — ntlmrelayx configuration matrix (SMB, LDAP, LDAPS, HTTP, RPC, IMAP, MSSQL), SMB-signing bypass, target selection (DC for DCSync, ADCS for cert, LAPS reader for cleartext), session relay vs cracking trade-off, multi-relay (forward auth from one victim to many).
Skill Claude CodeCodex
Root pointer for the analyst's vulnerability research playbooks. Load this first at iteration start to see the full catalog of vuln-class and chain-building skills.
Skill Claude Code
Craft adversarial examples that cause trained ML classifiers to misclassify at inference time — image recognition, malware detectors, IDS, spam filters.
Skill Claude CodeCodex
Hunt authentication/authorization bypass in route guards, role checks, tenant boundaries, and state-machine transitions.
Skill Claude CodeCodex
Bug bounty white-box hunting methodology. Load when the target is an open-source project with a security advisory program, bug bounty, or responsible disclosure policy.
Skill Claude CodeCodex
Build chains where leaked or weak credentials pivot across services to privileged access.
Skill Claude CodeCodex
Build chains where IDOR enables privilege escalation and high-impact control-plane actions.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: