PurpleAILAB/Decepticon

Autonomous Hacking Agent for Red Team

About the project

Decepticon is an autonomous red-team agent that coordinates AI agents, security tools, sandboxes, and supporting services for authorized cybersecurity assessments. Security researchers and red teams can run it through its Docker stack, cloud service, command-line interface, or Python SDK, with the catalogue entries representing its available skills.

5.5kStars on the repository
200Mods indexed here, across every type
13d agoLast push, which is what freshness is scored on
Apache-2.0Licence, which decides whether bodies are shown

volt-typhoon

49

PurpleAILAB/Decepticon

Skill Claude Code

Adversary-emulation profile for Volt Typhoon (G1017), a PRC state-sponsored actor pre-positioning in US critical infrastructure via living-off-the-land TTPs.

not rated 5.5k +40 13d ago A SkillSpector: warn 42 tokens original Apache-2.0

defense-evasion

50

PurpleAILAB/Decepticon

Skill Claude Code

Endpoint defense bypass — AMSI/ETW patching, ScareCrow framework, custom loaders, direct/indirect syscalls, LOLBAS execution, process injection.

not rated 5.5k +40 13d ago A SkillSpector: warn 40 tokens original Apache-2.0

finding-protocol

51

PurpleAILAB/Decepticon

Skill Claude Code

Operational-tier finding template — minimal fields for sub-agent decision support. Heavyweight deliverable promotion lives in skills/decepticon/final-report.

not rated 5.5k +40 13d ago A SkillSpector: pass 32 tokens original Apache-2.0

opsec

52

PurpleAILAB/Decepticon

Skill Claude Code

Operational security management — traffic shaping, scan rate limiting, source IP management, tool signature avoidance, evidence handling, anti-detection patterns.

not rated 5.5k +40 13d ago A SkillSpector: warn 30 tokens original Apache-2.0

references

53

PurpleAILAB/Decepticon

Skill Claude CodeCodex

External knowledge integration — HackerOne reports, PayloadsAllTheThings, Book of Secret Knowledge, CVE PoC corpora, bug bounty methodologies, and reference pentest agent architectures. Use these to calibrate, look up payloads, and accelerate research.

not rated 5.5k +40 13d ago A SkillSpector: pass 54 tokens original Apache-2.0

stealth-infra

54

PurpleAILAB/Decepticon

Skill Claude Code

Anti-bot evasion, proxy rotation, credential retrieval from password managers, and stealth HTTP tooling for covert web operations.

not rated 5.5k +40 13d ago B SkillSpector: warn 29 tokens original Apache-2.0

ad-overview

55

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction.

not rated 5.5k +40 13d ago A SkillSpector: warn 31 tokens original Apache-2.0

adcs-esc1

56

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Exploit Active Directory Certificate Services ESC1 — vulnerable template allows arbitrary SAN, enabling user impersonation up to domain admin.

not rated 5.5k +40 13d ago A SkillSpector: pass 30 tokens original Apache-2.0

asrep-roasting

57

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Request AS-REP for accounts with DONTREQPREAUTH set and crack offline — like kerberoast but no auth required.

not rated 5.5k +40 13d ago A SkillSpector: warn 31 tokens original Apache-2.0

bloodhound-bhce

58

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Operate BloodHound Community Edition v9.2.2 via Decepticon's bhce tools — health check, Cypher passthrough, SharpHound ZIP ingest. Replaces the in-house ingest + ESC post-process pipeline per ADR-0005.

not rated 5.5k +40 13d ago A SkillSpector: warn 61 tokens original Apache-2.0

bloodhound-query

59

PurpleAILAB/Decepticon

Skill Claude CodeCodex

BloodHound ingestion + canonical Cypher queries for AD attack-path enumeration. Run after collector dumps zip; promotes findings into the knowledge graph.

not rated 5.5k +40 13d ago A SkillSpector: warn 32 tokens original Apache-2.0

PurpleAILAB/Decepticon

Skill Claude Code

ADCS abuse via Certipy — find vulnerable templates (ESC1-ESC15), request a certificate, authenticate as the target, dump the krbtgt. Full chain in 4 commands. Covers ESC1 (any SAN), ESC2 (any-purpose EKU), ESC3 (enrollment-agent), ESC4 (vulnerable ACL), ESC8 (NTLM relay to CA), ESC9/10/11/13.

not rated 5.5k +40 13d ago B SkillSpector: warn 94 tokens original Apache-2.0

ad-coercer

61

PurpleAILAB/Decepticon

Skill Claude Code

Authentication coercion against Windows / AD — PetitPotam (MS-EFSR), PrinterBug (MS-RPRN), DFSCoerce (MS-DFSNM), ShadowCoerce (MS-FSRVP), Coercer.py meta-tool. Force a Windows machine to NTLM-authenticate to attacker, then relay or crack offline.

not rated 5.5k +40 13d ago B SkillSpector: warn 72 tokens original Apache-2.0

dcsync

62

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Abuse replication rights (DS-Replication-Get-Changes + GetChangesAll) to dump krbtgt and arbitrary user NT hashes from a DC.

not rated 5.5k +40 13d ago A SkillSpector: warn 35 tokens original Apache-2.0

kerberoasting

63

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Request Kerberos TGS tickets for SPN-bound service accounts and crack offline with hashcat — classic AD priv-esc primitive.

not rated 5.5k +40 13d ago A SkillSpector: warn 30 tokens original Apache-2.0

laps

64

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Extract LAPS-managed local administrator passwords from AD computer objects (ms-Mcs-AdmPwd / msLAPS-Password).

not rated 5.5k +40 13d ago A SkillSpector: warn 27 tokens original Apache-2.0

netexec

65

PurpleAILAB/Decepticon

Skill Claude CodeCodex

NetExec (CrackMapExec successor) — unified SMB/LDAP/MSSQL/WinRM/RDP/SSH/FTP/VNC protocol auth + post-auth modules. 200+ modules incl. BloodHound auto-ingest, ESC1-15 scanning, PrintNightmare, LDAP relay.

not rated 5.5k +40 13d ago A SkillSpector: warn 64 tokens original Apache-2.0

ad-ntlm-relay

66

PurpleAILAB/Decepticon

Skill Claude Code

NTLM relay deep-dive — ntlmrelayx configuration matrix (SMB, LDAP, LDAPS, HTTP, RPC, IMAP, MSSQL), SMB-signing bypass, target selection (DC for DCSync, ADCS for cert, LAPS reader for cleartext), session relay vs cracking trade-off, multi-relay (forward auth from one victim to many).

not rated 5.5k +40 13d ago B SkillSpector: warn 86 tokens original Apache-2.0

analyst-overview

67

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Root pointer for the analyst's vulnerability research playbooks. Load this first at iteration start to see the full catalog of vuln-class and chain-building skills.

not rated 5.5k +40 13d ago A SkillSpector: pass 35 tokens original Apache-2.0

PurpleAILAB/Decepticon

Skill Claude Code

Craft adversarial examples that cause trained ML classifiers to misclassify at inference time — image recognition, malware detectors, IDS, spam filters.

not rated 5.5k +40 13d ago A SkillSpector: warn 36 tokens original Apache-2.0

auth-bypass

69

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Hunt authentication/authorization bypass in route guards, role checks, tenant boundaries, and state-machine transitions.

not rated 5.5k +40 13d ago A SkillSpector: pass 25 tokens original Apache-2.0

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Bug bounty white-box hunting methodology. Load when the target is an open-source project with a security advisory program, bug bounty, or responsible disclosure policy.

not rated 5.5k +40 13d ago A SkillSpector: warn 37 tokens original Apache-2.0

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Build chains where leaked or weak credentials pivot across services to privileged access.

not rated 5.5k +40 13d ago A SkillSpector: pass 20 tokens original Apache-2.0

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Build chains where IDOR enables privilege escalation and high-impact control-plane actions.

not rated 5.5k +40 13d ago A SkillSpector: pass 24 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: