K8s
Kubernetes and container exploitation: identity/RBAC, secrets, kubelet/etcd, managed-cloud workload identities, container-to-node escape including CVE-2026-31431 Copy Fail, and Kubernetes-native persistence. Use when already in a Pod/container or holding kubeconfig. Own the chain to cluster-admin, node root, or a usable cloud identity. Operator chooses next modules. Endpoint blocks after OS execu…
Web Attack
HTTP/Web exploitation until a server shell or equivalent OS execution. Use after /web-recon has mapped the application. Covers injection, upload, LFI, SSRF/XXE, SSTI, deserialization, JWT/SAML, API logic, desync/cache/parser, and Web-controlled backend abuse. WAF stays here. Endpoint blocks after OS execution hand off to /edr-bypass then return. Direct non-HTTP service ports belong to /recon or /…
Ad Recon
Active Directory reconnaissance with or without credentials: user/group/computer enumeration, ACL/delegation, ADCS, modern Windows LAPS, BloodHound, Server 2025/dMSA/Ghost SPN candidates, and trust mapping. Recon only — do not exploit Kerberoast-to-DA, DCSync, or change passwords. Operator may select /ad-attack after cards are ready.
Cicd
CI/CD pipeline and software-supply-chain exploitation: Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps, Gitea/Forgejo, self-hosted runners/agents, poisoned pipeline execution, artifact/cache abuse, dependency confusion, third-party Action trust, GitOps/registry poisoning, workload identity/OIDC, and emerging agentic CI/CD. Use this skill when the operator has access to a CI/CD system, source…
Tunnel
Network reachability and pivoting after an operator already has a foothold. Use to make previously unreachable hosts, subnets, services or listener directions reachable via Ligolo-ng, Chisel, GOST v3, SSH/native forwarding, socat/netsh, Microsoft Dev Tunnels, DNS/HTTP/QUIC fallback transports, and multi-hop routing. This module does not exploit services, obtain credentials, or own C2/persistence.…
Edr Bypass
Endpoint defense evasion after an operator-selected chain already has a valid execution path but AV/EDR/AMSI/WDAC/PPL/memory/kernel telemetry blocks the intended action. Originating modules include /web-attack /ad-attack /cloud-attack /k8s /cicd /service-attack /phishing /privesc-win /privesc-linux /creds /post /shell. Success is the blocked action becoming executable, then resume the originating…
Post
OS post-exploitation after a stable host foothold: quiet host recon, host-native persistence (Windows Run/tasks/services/COM/WMI and Linux SSH/cron/systemd/SUID), long-term C2 (Sliver primary, Mythic/Havoc optional), targeted collection and exfil, and engagement cleanup. Does not own AD/cloud/K8s native persistence, Ligolo pivoting, LSASS dumping, or EDR bypass. Operator selects objectives; succe…
Shell
Shell and session operations after an attack module already established command execution, a raw shell, webshell channel, container/runner shell, or remote session. This module does not own exploitation and should not pull SSH/WinRM/RDP authentication or vulnerability-to-shell chains out of Web/AD/Cloud/K8s/CI-CD/Service/Phishing. Use it to bootstrap a usable callback from existing command execut…
Creds
Credential operations: secret discovery, classification, extraction, conversion, offline cracking of hashes the operator already has as a credential job, policy-aware spraying, NetNTLM capture, generic SMB relay, and Windows/Linux harvest. Do not hijack an in-progress /ad-attack Kerberoast/AS-REP chain (that module cracks and uses the ticket itself). Do not DCSync, read LAPS LDAP, or escalate clo…
Web Recon
HTTP/HTTPS application-layer reconnaissance after a web service is identified: fingerprinting, content/API discovery, JS/source maps, proxy/cache topology, WAF, CMS, and known CVE/PoC candidates. Recon only — do not exploit, write files, or obtain a shell. Hand CVE candidates and attack surface to the operator, who may select /web-attack. Non-HTTP ports belong to /recon.
Ad Attack
Active Directory exploitation after domain credentials exist: Kerberos (AS-REP/Kerberoast including cracking the ticket then using the account), delegation, NTLM coercion/relay, lateral movement, ACL abuse, ADCS ESC1-ESC17 and CVE paths, dMSA/BadSuccessor, Kerberos reflection, identity confusion, management-plane, domain trust, and domain persistence. Own the current AD chain through crack-and-us…
Cloud Attack
Cloud control-plane exploitation for AWS, Azure/Entra, GCP, and Alibaba Cloud: IAM/RAM privilege escalation, impersonation, cross-account trust, serverless/compute control, and cloud-native persistence. Host OS persistence/C2 after root/SYSTEM belongs to /post. K8s RBAC belongs to /k8s. Operator chooses next modules; new identities default to /cloud-recon first.
Recon
通用网络与资产信息收集。面向 IP、CIDR、主机名、企业/域名等尚未明确攻击面的目标,完成资产扩展、主机发现、TCP/UDP端口发现、服务/版本/协议识别、只读服务枚举、网络设备识别和漏洞候选研判。Recon only:不执行漏洞利用、口令爆破、服务配置修改或持久化。
Cloud Recon
Cloud control-plane reconnaissance for AWS, Azure/Entra, GCP, and Alibaba Cloud: identity, IAM/RAM, trust, resources, metadata, and managed-Kubernetes cloud-side boundary. Recon only — no policy changes, no privilege escalation. Operator may select /cloud-attack or /k8s.
Privesc Win
Windows local privilege escalation from a low-privilege shell to Administrator or SYSTEM. Covers quiet vs loud enumeration, SeImpersonate/Potato family including LocalPotato, token privileges (SeBackup/SeRestore/SeManageVolume/SeLoadDriver/SeDebug), service/DLL/COM/scheduled-task abuse, AlwaysInstallElevated and UAC boundary, KrbRelayUp-style domain-joined local admin, and version-gated kernel LP…
Phishing
Client-side initial access and social-engineering attack module. Use when the operator selects a human/client/browser/identity-delivery attack direction: ClickFix/FileFix, AiTM session phishing, OAuth device-code or consent abuse, Teams/helpdesk social engineering, HTML/file delivery, QR/mobile handoff, legacy HTA/OLE/Office paths. This is an Attack module: own the chain until host shell or remot…
Service Attack
直连网络服务攻击链。用于已经识别/枚举的非专门领域服务,从数据库、数据存储、文件/远程访问、基础设施、消息队列、DNS/网络服务、打印机/MFP/NAS/BMC/网络设备等服务入口继续利用到凭据、代码执行、主机控制、横向能力或新的独立身份。由操作者选择具体攻击链;不自动切换模块。
Privesc Linux
Linux local privilege escalation from a low-privilege shell to root. Covers quiet vs loud enumeration, sudo/GTFOBins, CVE-2025-32463 chwoot and CVE-2025-32462 host bypass, polkit/udisks CVE-2025-6018/6019, SUID/capabilities, systemd timers/units, cron/PATH/LD_PRELOAD, dangerous groups and docker.sock, host-local container escape, and version-gated kernel LPE including Copy Fail CVE-2026-31431. Us…