← all publishers

blacklanternsecurity

@blacklanternsecurity source repo

80 published skills

  1. Red Run Ctf · blacklanternsecurity
    Multi-phase penetration test orchestrator. Handles recon, assessment surface mapping, vulnerability chaining, and routes to technique skills for execution. Invoke via /red-run-ctf slash command only.
    0
    installs
  2. Red Run Legacy · blacklanternsecurity
    Legacy subagent-based orchestrator. Superseded by /red-run-ctf (agent teams). Use /red-run-legacy to invoke manually. Does not auto-trigger.
    0
    installs
  3. Lfi · blacklanternsecurity
    Guide Local File Inclusion (LFI) and Remote File Inclusion (RFI) exploitation during authorized penetration testing.
    0
    installs
  4. Xxe · blacklanternsecurity
    Guide XML External Entity (XXE) injection exploitation during authorized penetration testing.
    0
    installs
  5. Csrf · blacklanternsecurity
    Exploit Cross-Site Request Forgery (CSRF) vulnerabilities during authorized penetration testing.
    0
    installs
  6. Idor · blacklanternsecurity
    Exploit Insecure Direct Object Reference (IDOR) and broken access control vulnerabilities during authorized penetration testing.
    0
    installs
  7. Ssrf · blacklanternsecurity
    Guide server-side request forgery (SSRF) exploitation during authorized penetration testing.
    0
    installs
  8. Skill Name · blacklanternsecurity
    <What this skill does in 2-3 sentences. Focus on technique scope and when to use it. No trigger phrases, negative conditions, or OPSEC details here.>
    0
    installs
  9. Xss Dom · blacklanternsecurity
    Guide DOM-based XSS exploitation during authorized penetration testing.
    0
    installs
  10. Acl Abuse · blacklanternsecurity
    Exploits misconfigured Active Directory ACLs for privilege escalation. Covers GenericAll, GenericWrite, WriteDACL, WriteOwner, ForceChangePassword, targeted Kerberoasting via SPN manipulation, shadow credentials (msDS-KeyCredentialLink → PKINIT), and AdminSDHolder persistence.
    0
    installs
  11. Gpo Abuse · blacklanternsecurity
    Exploits Group Policy Objects for code execution, privilege escalation, and lateral movement in Active Directory. Covers GPO enumeration (GPOHound, BloodHound, PowerView), exploitation via immediate tasks, logon scripts, and registry modifications (SharpGPOAbuse, PowerGPOAbuse, pyGPOAbuse, GroupPolicyBackdoor), SYSVOL/NETLOGON logon script poisoning, and GPP password extraction.
    0
    installs
  12. Retrospective · blacklanternsecurity
    Post-engagement lessons-learned retrospective. Reads the engagement directory, analyzes skill routing decisions, identifies knowledge gaps and missing skills, and produces an actionable improvement report.
    0
    installs
  13. Ssti Twig · blacklanternsecurity
    Guide Twig/PHP server-side template injection exploitation during authorized penetration testing.
    0
    installs
  14. 2fa Bypass · blacklanternsecurity
    Bypass two-factor authentication (2FA/MFA) during authorized penetration testing.
    0
    installs
  15. Xss Stored · blacklanternsecurity
    Guide stored (persistent) and blind XSS exploitation during authorized penetration testing.
    0
    installs
  16. Ad Discovery · blacklanternsecurity
    Enumerates Active Directory domains and maps attack surface for penetration testing.
    0
    installs
  17. JWT Attacks · blacklanternsecurity
    Exploit JWT (JSON Web Token) vulnerabilities during authorized penetration testing.
    0
    installs
  18. Ssti Jinja2 · blacklanternsecurity
    Guide Jinja2/Python server-side template injection exploitation during authorized penetration testing.
    0
    installs
  19. Pass The Hash · blacklanternsecurity
    Authenticates to AD services using NTLM hashes, AES keys, or Kerberos tickets without cracking passwords. Covers Pass-the-Hash, Over-Pass-the-Hash, Pass-the-Key, and Pass-the-Ticket for lateral movement.
    0
    installs
  20. Trust Attacks · blacklanternsecurity
    Enumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation. Covers trust enumeration (nltest, PowerView, BloodHound), SID history injection (child domain to forest root via golden/diamond ticket with extra SIDs), inter-realm TGT forging using trust keys, TGT delegation coercion capture (Rubeus monitor + SpoolSample/DFSCoerce across forest trusts with ENABLE_TGT_DELEGATION), cross-forest trust abuse (SID filtering bypass, RBCD, Kerberoasting via trust account), and PAM trust exploitation (shadow principals in bastion forests).
    0
    installs
  21. Ajp Ghostcat · blacklanternsecurity
    Exploit Apache JServ Protocol (AJP) misconfigurations and Ghostcat (CVE-2020-1938) for file read and remote code execution on Apache Tomcat. Use when port 8009 is open or AJP connector is exposed.
    0
    installs
  22. Ad Persistence · blacklanternsecurity
    Establishes persistent access in Active Directory environments after domain compromise. Covers DCShadow (rogue DC attribute modification), Skeleton Key (LSASS master password), custom SSP injection (credential logging via mimilib/memssp), security descriptor backdoors (WMI/WinRM/ DCOM/registry ACL modification), ADFS Golden SAML (DKM key extraction and forged SAML tokens), SID history persistence (DA SID in regular user), and certificate-based persistence (golden certificate, renewal, enrollment agent).
    0
    installs
  23. OAUTH Attacks · blacklanternsecurity
    Exploit OAuth 2.0 and OpenID Connect vulnerabilities during authorized penetration testing.
    0
    installs
  24. Web Discovery · blacklanternsecurity
    Discover web application injection points and route to the correct exploitation skill during authorized penetration testing.
    0
    installs
  25. Xss Reflected · blacklanternsecurity
    Guide reflected XSS exploitation during authorized penetration testing.
    0
    installs
  26. Ldap Injection · blacklanternsecurity
    Exploit LDAP injection vulnerabilities during authorized penetration testing.
    0
    installs
  27. Race Condition · blacklanternsecurity
    Exploit race conditions and TOCTOU vulnerabilities in web applications during authorized penetration testing.
    0
    installs
  28. Adcs Persistence · blacklanternsecurity
    Establishes persistence and exploits weak certificate mapping in AD CS. Covers ESC9 (no security extension), ESC10 (weak certificate mapping), ESC12-15 (YubiHSM, issuance policy, altSecIdentities, application policies), Golden Certificate (forge with stolen CA key), certificate theft (DPAPI/CAPI/CNG), and account persistence via certificate mapping.
    0
    installs
  29. Nosql Injection · blacklanternsecurity
    Guide NoSQL injection exploitation during authorized penetration testing.
    0
    installs
  30. Ssti Freemarker · blacklanternsecurity
    Guide Freemarker/Java server-side template injection exploitation during authorized penetration testing.
    0
    installs
  31. Kerberos Roasting · blacklanternsecurity
    Extracts and cracks Kerberos service tickets (Kerberoasting) and AS-REP hashes (AS-REP Roasting) for offline password recovery.
    0
    installs
  32. Sccm Exploitation · blacklanternsecurity
    Enumerates and exploits Microsoft SCCM/MECM (System Center Configuration Manager / Microsoft Endpoint Configuration Manager) infrastructure for credential harvesting, lateral movement, and domain escalation. Covers SCCM enumeration (sccmhunter, SharpSCCM), Network Access Account (NAA) credential extraction (policy request, WMI DPAPI, WMI repository), management point NTLM relay to MSSQL (TAKEOVER1), client push relay (ELEVATE2), PXE boot media credential harvesting (CRED1), SCCM database credential extraction, application deployment for lateral movement, and SCCM share looting.
    0
    installs
  33. Credential Dumping · blacklanternsecurity
    Extracts credentials from Active Directory: DCSync replication, NTDS.dit database extraction, SAM hive dump, Azure AD Connect (ADSync) credential extraction, LAPS passwords (legacy + Windows LAPS), gMSA passwords (KDS root key + GoldenGMSA), dMSA exploitation (BadSuccessor CVE-2025-21293), DSRM credentials, and EFS-encrypted file decryption.
    0
    installs
  34. Network Recon · blacklanternsecurity
    Network reconnaissance, host discovery, port scanning, and OS fingerprinting. Produces a port/service map that the orchestrator uses to route to service-specific enumeration skills.
    0
    installs
  35. Command Injection · blacklanternsecurity
    Guide OS command injection exploitation during authorized penetration testing.
    0
    installs
  36. Request Smuggling · blacklanternsecurity
    Guide HTTP request smuggling exploitation during authorized penetration testing.
    0
    installs
  37. Adcs Template Abuse · blacklanternsecurity
    Exploits misconfigured AD CS certificate templates to impersonate any domain user via SAN manipulation or enrollment agent abuse. Covers ESC1 (enrollee supplies subject), ESC2 (any-purpose/no EKU), ESC3 (enrollment agent), ESC6 (EDITF_ATTRIBUTESUBJECTALTNAME2 CA flag).
    0
    installs
  38. Auth Coercion Relay · blacklanternsecurity
    Forces remote systems to authenticate back to attacker-controlled listeners and relays captured authentication to escalate privileges or move laterally. Covers authentication coercion (PetitPotam, PrinterBug, DFSCoerce, ShadowCoerce, CheeseOunce), NTLM relay (ntlmrelayx to LDAP/SMB/AD CS/MSSQL), Kerberos relay (krbrelayx, mitm6), and name resolution poisoning (LLMNR/NBNS/WPAD via Responder).
    0
    installs
  39. Kerberos Delegation · blacklanternsecurity
    Exploits Kerberos delegation misconfigurations for privilege escalation and lateral movement in Active Directory. Covers Unconstrained Delegation (TGT harvesting via coercion), Constrained Delegation (S4U2Self + S4U2Proxy with SPN swapping), and Resource-Based Constrained Delegation (RBCD via writable machine accounts).
    0
    installs
  40. Av Edr Evasion · blacklanternsecurity
    Bypass antivirus and EDR detection for payload delivery during exploitation. Covers custom payload compilation (mingw C, Go), AMSI bypass, shellcode alternatives, and ETW patching. Route here when an agent reports a payload was quarantined, blocked, or detected by endpoint protection.
    0
    installs
  41. File Upload Bypass · blacklanternsecurity
    Guide file upload restriction bypass during authorized penetration testing.
    0
    installs
  42. PHP Code Injection · blacklanternsecurity
    Exploit PHP code evaluation injection via eval(), assert(), preg_replace /e, create_function(), call_user_func(), usort() callbacks, and runtime function creation (runkit, uopz). Distinct from OS command injection (shell operators) and SSTI (template engines) — this targets direct PHP code evaluation of user input.
    0
    installs
  43. Smb Share Webshell · blacklanternsecurity
    Deploy webshells to IIS, Apache, or Tomcat web roots via SMB share write access. Use when a domain user has write access to a file share that maps to a web server's document root — write a webshell via smbclient/net use, then trigger it via HTTP for RCE. Covers PHP, ASPX, and JSP webshells, .NET impersonation for same-host lateral movement, and internal site discovery.
    0
    installs
  44. Source Code Review · blacklanternsecurity
    Security-focused source code review. Identifies hardcoded credentials, injection sinks, authentication weaknesses, and framework-specific vulnerabilities. Use when application source code is available for review.
    0
    installs
  45. Smb Enumeration · blacklanternsecurity
    SMB share enumeration, access testing, password policy extraction, and content searching. Enumerates shares via null session, guest, and authenticated access. Covers share listing, per-share access testing, MANSPIDER content search, and SMB vulnerability detection (signing, EternalBlue). Use after network-recon identifies SMB ports (139/445).
    0
    installs
  46. Linux Discovery · blacklanternsecurity
    Linux local privilege escalation enumeration and attack surface mapping.
    0
    installs
  47. Deserialization PHP · blacklanternsecurity
    Exploit PHP deserialization vulnerabilities during authorized penetration testing.
    0
    installs
  48. SQL Injection Blind · blacklanternsecurity
    Guide blind SQL injection exploitation (boolean-based, time-based, and out-of-band) during authorized penetration testing.
    0
    installs
  49. SQL Injection Error · blacklanternsecurity
    Guide error-based SQL injection exploitation during authorized penetration testing.
    0
    installs
  50. SQL Injection Union · blacklanternsecurity
    Guide UNION-based SQL injection exploitation during authorized penetration testing.
    0
    installs
  51. Adcs Access And Relay · blacklanternsecurity
    Exploits ADCS through ACL abuse on templates/CA objects and NTLM relay to enrollment endpoints. Covers ESC4 (template ACL → modify to ESC1), ESC5 (PKI object ACLs), ESC7 (ManageCA/ManageCertificates abuse), ESC8 (NTLM relay to HTTP enrollment), ESC11 (NTLM relay to ICPR RPC).
    0
    installs
  52. Smb Exploitation · blacklanternsecurity
    Exploit remote SMB vulnerabilities for unauthenticated code execution on Windows hosts.
    0
    installs
  53. Xmpp Enumeration · blacklanternsecurity
    XMPP/Jabber service enumeration for Openfire, ejabberd, Prosody, and other XMPP servers. Trigger when ports 5222 (client), 5223 (legacy TLS), or 5269 (server-to-server) are found open. Covers authentication testing, user enumeration, MUC room discovery, and server fingerprinting. Do NOT use for AD enumeration or credential spraying — route those to the appropriate skills.
    0
    installs
  54. Browser Exploitation · blacklanternsecurity
    Exploit browser-based attack surfaces: malicious extension crafting for bot interaction scenarios, Chrome DevTools Protocol abuse on exposed debug ports, and browser profile/cache data extraction from compromised hosts.
    0
    installs
  55. Deserialization Java · blacklanternsecurity
    Exploit Java deserialization vulnerabilities during authorized penetration testing.
    0
    installs
  56. Container Escapes · blacklanternsecurity
    Container escape, Docker breakout, and Kubernetes exploitation.
    0
    installs
  57. Windows Discovery · blacklanternsecurity
    Windows local privilege escalation enumeration and attack surface mapping.
    0
    installs
  58. Cors Misconfiguration · blacklanternsecurity
    Exploit CORS (Cross-Origin Resource Sharing) misconfigurations during authorized penetration testing.
    0
    installs
  59. Python Code Injection · blacklanternsecurity
    Exploit Python eval(), exec(), and compile() injection in web applications. Distinct from OS command injection (shell operators) and SSTI (template engines) — this targets direct Python code evaluation of user input.
    0
    installs
  60. SQL Injection Stacked · blacklanternsecurity
    Guide stacked query SQL injection and second-order injection exploitation during authorized penetration testing.
    0
    installs
  61. Tomcat Manager Deploy · blacklanternsecurity
    Deploy WAR files via Apache Tomcat Manager for remote code execution. Use when Tomcat Manager is accessible with valid credentials (manager-script or manager-gui role). Covers WAR generation, deployment via text API and HTML interface, reverse shell delivery, and cleanup. Common initial access vector after credential discovery via LFI, default creds, or config file exposure.
    0
    installs
  62. Kerberos Ticket Forging · blacklanternsecurity
    Forges Kerberos tickets for domain persistence and privilege escalation. Covers Golden Ticket (krbtgt hash → forged TGT), Silver Ticket (service hash → forged TGS), Diamond Ticket (decrypt/modify/re-encrypt legitimate TGT for stealth), Sapphire Ticket (U2U PAC swap), and Pass-the-Ticket injection.
    0
    installs
  63. Pivoting Tunneling · blacklanternsecurity
    Network pivoting, port forwarding, and tunneling through compromised hosts to reach internal networks.
    0
    installs
  64. Windows Uac Bypass · blacklanternsecurity
    Bypass Windows User Account Control to escalate from medium to high integrity.
    0
    installs
  65. Deserialization Dotnet · blacklanternsecurity
    Exploit .NET deserialization vulnerabilities during authorized penetration testing.
    0
    installs
  66. Password Spraying · blacklanternsecurity
    Performs password spraying against authentication services with lockout-safe techniques. Works against AD (SMB/Kerberos/LDAP), SSH, web login forms, OWA, and any service with username/password auth. Service-agnostic — the orchestrator passes target services and spray intensity tier.
    0
    installs
  67. Database Enumeration · blacklanternsecurity
    Database service enumeration and quick-win access checks for MSSQL, MySQL, PostgreSQL, Oracle, MongoDB, and Redis. Checks default/empty passwords, unauthenticated access, and command execution capabilities. Use after network-recon identifies database ports.
    0
    installs
  68. Password Reset Poisoning · blacklanternsecurity
    Exploit password reset vulnerabilities during authorized penetration testing.
    0
    installs
  69. Linux File Path Abuse · blacklanternsecurity
    Exploit writable critical files, NFS misconfigurations, shared library hijacking, and privileged group membership (docker, lxd, disk, adm, video, staff) for Linux privilege escalation. Use when a user belongs to a privileged group or has write access to sensitive files or paths.
    0
    installs
  70. Linux Kernel Exploits · blacklanternsecurity
    Exploit Linux kernel vulnerabilities and escape restricted shells for privilege escalation.
    0
    installs
  71. Windows Kernel Exploits · blacklanternsecurity
    Exploit Windows kernel vulnerabilities, vulnerable drivers, and privileged file operations for local privilege escalation to SYSTEM.
    0
    installs
  72. Credential Recovery · blacklanternsecurity
    Offline credential and file recovery with hashcat and john. Use when any skill captures hashes (NTLM, Kerberos TGS/AS-REP, shadow, MSCACHE2) or encrypted files (ZIP, Office, PDF, KeePass, SSH key, 7z, RAR). Trigger phrases: "recover this hash", "offline recovery", "john", "hashcat", "zip2john", "password-protected file". Do NOT use for online password attacks (spraying, brute force against services) — use password-spraying instead.
    0
    installs
  73. Linux Cron Service Abuse · blacklanternsecurity
    Exploit cron jobs, systemd timers/services, D-Bus services, and Unix sockets for privilege escalation.
    0
    installs
  74. Unknown Vector Analysis · blacklanternsecurity
    Analyze custom applications, scripts, and binaries that standard technique skills could not exploit. Performs source code review, attack surface mapping, CVE research, and PoC adaptation. Route here when ANY technique agent returns saying standard patterns do not match, the target uses a custom/unknown application, or no existing technique skill covers the vector. Trigger phrases: "standard patterns don't match", "custom script", "unknown binary", "no matching technique", "unrecognized application". Do NOT use for known vulnerability classes that have dedicated technique skills — route to those instead.
    0
    installs
  75. Remote Access Enumeration · blacklanternsecurity
    Enumeration of remote access services: FTP, SSH, RDP, VNC, and WinRM. Checks anonymous access, default credentials, version vulnerabilities, and authentication methods. Use after network-recon identifies remote access ports.
    0
    installs
  76. Windows Service Dll Abuse · blacklanternsecurity
    Exploit Windows service misconfigurations and DLL hijacking for local privilege escalation.
    0
    installs
  77. Infrastructure Enumeration · blacklanternsecurity
    Enumeration of infrastructure services: DNS, SMTP, SNMP, IPMI, NFS, TFTP, RPC/MSRPC, and HTTP/HTTPS surface detection. Checks zone transfers, open relays, default community strings, cipher zero, NFS exports, and web technology fingerprinting. Use after network-recon identifies infrastructure ports.
    0
    installs
  78. Windows Token Impersonation · blacklanternsecurity
    Exploit Windows token privileges for local privilege escalation to SYSTEM.
    0
    installs
  79. Linux Sudo Suid Capabilities · blacklanternsecurity
    Exploit sudo misconfigurations, SUID/SGID binaries, and Linux capabilities for privilege escalation.
    0
    installs
  80. Windows Credential Harvesting · blacklanternsecurity
    Harvest stored credentials from a Windows system for privilege escalation or lateral movement.
    0
    installs