# System

> System exploitation testing - Active Directory attacks, privilege escalation (Linux/Windows), and exploit development.

- **Type:** Skill
- **Install:** `agentstack add skill-transilienceai-communitytools-system`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [transilienceai](https://agentstack.voostack.com/s/transilienceai)
- **Installs:** 0
- **Category:** [Security](https://agentstack.voostack.com/c/security)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [transilienceai](https://github.com/transilienceai)
- **Source:** https://github.com/transilienceai/communitytools/tree/main/skills/system
- **Website:** https://www.transilience.ai/

## Install

```sh
agentstack add skill-transilienceai-communitytools-system
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# System

Test system-level security including Active Directory, privilege escalation, and exploit development.

## Techniques

| Type | Key Vectors |
|------|-------------|
| **Active Directory** | Kerberoasting, AS-REP roasting, DCSync, PtH, Golden/RODC Ticket, RBCD, ACL abuse, KeyList, Shadow Credentials, ADCS (ESC1-9/16) |
| **Privilege Escalation** | SUID/sudo abuse, kernel exploits, service misconfig, token manipulation |
| **Exploit Development** | Buffer overflow, format string, ROP chains, shellcode, heap exploitation |

## Workflow

1. Enumerate system and domain information
2. Identify escalation paths and misconfigurations
3. Exploit with appropriate techniques
4. Demonstrate impact (domain admin, root access)
5. Document attack chain with evidence

## Reference

- `reference/INDEX.md` - Router for AD attacks, privilege escalation, and exploit-dev scenarios (see `reference/scenarios/`)
- `reference/format-string-exploitation.md` - Format string read/write primitives, architecture differences, mitigation bypass
- `reference/heap-exploitation.md` - Modern glibc heap techniques (tcache poison, unsorted bin leak, environ stack leak, ROP)

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [transilienceai](https://github.com/transilienceai)
- **Source:** [transilienceai/communitytools](https://github.com/transilienceai/communitytools)
- **License:** MIT
- **Homepage:** https://www.transilience.ai/

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-transilienceai-communitytools-system
- Seller: https://agentstack.voostack.com/s/transilienceai
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
