blacklanternsecurity
- 80 skills
- 0 followers
- 11 hours ago last updated
- ▌ Red Run Ctf · blacklanternsecurityMulti-phase penetration test orchestrator. Handles recon, assessment surface mapping, vulnerability chaining, and routes to technique skills for execution. Invoke via /red-run-ctf slash command only.
- ▌ Red Run Legacy · blacklanternsecurityLegacy subagent-based orchestrator. Superseded by /red-run-ctf (agent teams). Use /red-run-legacy to invoke manually. Does not auto-trigger.
- ▌ Lfi · blacklanternsecurityGuide Local File Inclusion (LFI) and Remote File Inclusion (RFI) exploitation during authorized penetration testing.
- ▌ Xxe · blacklanternsecurityGuide XML External Entity (XXE) injection exploitation during authorized penetration testing.
- ▌ Csrf · blacklanternsecurityExploit Cross-Site Request Forgery (CSRF) vulnerabilities during authorized penetration testing.
- ▌ Idor · blacklanternsecurityExploit Insecure Direct Object Reference (IDOR) and broken access control vulnerabilities during authorized penetration testing.
- ▌ Ssrf · blacklanternsecurityGuide server-side request forgery (SSRF) exploitation during authorized penetration testing.
- ▌ Skill Name · blacklanternsecurity<What this skill does in 2-3 sentences. Focus on technique scope and when to use it. No trigger phrases, negative conditions, or OPSEC details here.>
- ▌ Xss Dom · blacklanternsecurityGuide DOM-based XSS exploitation during authorized penetration testing.
- ▌ Acl Abuse · blacklanternsecurityExploits misconfigured Active Directory ACLs for privilege escalation. Covers GenericAll, GenericWrite, WriteDACL, WriteOwner, ForceChangePassword, targeted Kerberoasting via SPN manipulation, shadow credentials (msDS-KeyCredentialLink → PKINIT), and AdminSDHolder persistence.
- ▌ Gpo Abuse · blacklanternsecurityExploits Group Policy Objects for code execution, privilege escalation, and lateral movement in Active Directory. Covers GPO enumeration (GPOHound, BloodHound, PowerView), exploitation via immediate tasks, logon scripts, and registry modifications (SharpGPOAbuse, PowerGPOAbuse, pyGPOAbuse, GroupPolicyBackdoor), SYSVOL/NETLOGON logon script poisoning, and GPP password extraction.
- ▌ Retrospective · blacklanternsecurityPost-engagement lessons-learned retrospective. Reads the engagement directory, analyzes skill routing decisions, identifies knowledge gaps and missing skills, and produces an actionable improvement report.
- ▌ Ssti Twig · blacklanternsecurityGuide Twig/PHP server-side template injection exploitation during authorized penetration testing.
- ▌ 2fa Bypass · blacklanternsecurityBypass two-factor authentication (2FA/MFA) during authorized penetration testing.
- ▌ Xss Stored · blacklanternsecurityGuide stored (persistent) and blind XSS exploitation during authorized penetration testing.
- ▌ Ad Discovery · blacklanternsecurityEnumerates Active Directory domains and maps attack surface for penetration testing.
- ▌ JWT Attacks · blacklanternsecurityExploit JWT (JSON Web Token) vulnerabilities during authorized penetration testing.
- ▌ Ssti Jinja2 · blacklanternsecurityGuide Jinja2/Python server-side template injection exploitation during authorized penetration testing.
- ▌ Pass The Hash · blacklanternsecurityAuthenticates to AD services using NTLM hashes, AES keys, or Kerberos tickets without cracking passwords. Covers Pass-the-Hash, Over-Pass-the-Hash, Pass-the-Key, and Pass-the-Ticket for lateral movement.
- ▌ Trust Attacks · blacklanternsecurityEnumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation. Covers trust enumeration (nltest, PowerView, BloodHound), SID history injection (child domain to forest root via golden/diamond ticket with extra SIDs), inter-realm TGT forging using trust keys, TGT delegation coercion capture (Rubeus monitor + SpoolSample/DFSCoerce across forest trusts with ENABLE_TGT_DELEGATION), cross-forest trust abuse (SID filtering bypass, RBCD, Kerberoasting via trust account), and PAM trust exploitation (shadow principals in bastion forests).
- ▌ Ajp Ghostcat · blacklanternsecurityExploit Apache JServ Protocol (AJP) misconfigurations and Ghostcat (CVE-2020-1938) for file read and remote code execution on Apache Tomcat. Use when port 8009 is open or AJP connector is exposed.
- ▌ Ad Persistence · blacklanternsecurityEstablishes persistent access in Active Directory environments after domain compromise. Covers DCShadow (rogue DC attribute modification), Skeleton Key (LSASS master password), custom SSP injection (credential logging via mimilib/memssp), security descriptor backdoors (WMI/WinRM/ DCOM/registry ACL modification), ADFS Golden SAML (DKM key extraction and forged SAML tokens), SID history persistence (DA SID in regular user), and certificate-based persistence (golden certificate, renewal, enrollment agent).
- ▌ OAUTH Attacks · blacklanternsecurityExploit OAuth 2.0 and OpenID Connect vulnerabilities during authorized penetration testing.
- ▌ Web Discovery · blacklanternsecurityDiscover web application injection points and route to the correct exploitation skill during authorized penetration testing.
- ▌ Xss Reflected · blacklanternsecurityGuide reflected XSS exploitation during authorized penetration testing.
- ▌ Ldap Injection · blacklanternsecurityExploit LDAP injection vulnerabilities during authorized penetration testing.
- ▌ Race Condition · blacklanternsecurityExploit race conditions and TOCTOU vulnerabilities in web applications during authorized penetration testing.
- ▌ Adcs Persistence · blacklanternsecurityEstablishes persistence and exploits weak certificate mapping in AD CS. Covers ESC9 (no security extension), ESC10 (weak certificate mapping), ESC12-15 (YubiHSM, issuance policy, altSecIdentities, application policies), Golden Certificate (forge with stolen CA key), certificate theft (DPAPI/CAPI/CNG), and account persistence via certificate mapping.
- ▌ Nosql Injection · blacklanternsecurityGuide NoSQL injection exploitation during authorized penetration testing.
- ▌ Ssti Freemarker · blacklanternsecurityGuide Freemarker/Java server-side template injection exploitation during authorized penetration testing.
- ▌ Kerberos Roasting · blacklanternsecurityExtracts and cracks Kerberos service tickets (Kerberoasting) and AS-REP hashes (AS-REP Roasting) for offline password recovery.
- ▌ Sccm Exploitation · blacklanternsecurityEnumerates and exploits Microsoft SCCM/MECM (System Center Configuration Manager / Microsoft Endpoint Configuration Manager) infrastructure for credential harvesting, lateral movement, and domain escalation. Covers SCCM enumeration (sccmhunter, SharpSCCM), Network Access Account (NAA) credential extraction (policy request, WMI DPAPI, WMI repository), management point NTLM relay to MSSQL (TAKEOVER1), client push relay (ELEVATE2), PXE boot media credential harvesting (CRED1), SCCM database credential extraction, application deployment for lateral movement, and SCCM share looting.
- ▌ Credential Dumping · blacklanternsecurityExtracts credentials from Active Directory: DCSync replication, NTDS.dit database extraction, SAM hive dump, Azure AD Connect (ADSync) credential extraction, LAPS passwords (legacy + Windows LAPS), gMSA passwords (KDS root key + GoldenGMSA), dMSA exploitation (BadSuccessor CVE-2025-21293), DSRM credentials, and EFS-encrypted file decryption.
- ▌ Network Recon · blacklanternsecurityNetwork reconnaissance, host discovery, port scanning, and OS fingerprinting. Produces a port/service map that the orchestrator uses to route to service-specific enumeration skills.
- ▌ Command Injection · blacklanternsecurityGuide OS command injection exploitation during authorized penetration testing.
- ▌ Request Smuggling · blacklanternsecurityGuide HTTP request smuggling exploitation during authorized penetration testing.
- ▌ Adcs Template Abuse · blacklanternsecurityExploits misconfigured AD CS certificate templates to impersonate any domain user via SAN manipulation or enrollment agent abuse. Covers ESC1 (enrollee supplies subject), ESC2 (any-purpose/no EKU), ESC3 (enrollment agent), ESC6 (EDITF_ATTRIBUTESUBJECTALTNAME2 CA flag).
- ▌ Auth Coercion Relay · blacklanternsecurityForces remote systems to authenticate back to attacker-controlled listeners and relays captured authentication to escalate privileges or move laterally. Covers authentication coercion (PetitPotam, PrinterBug, DFSCoerce, ShadowCoerce, CheeseOunce), NTLM relay (ntlmrelayx to LDAP/SMB/AD CS/MSSQL), Kerberos relay (krbrelayx, mitm6), and name resolution poisoning (LLMNR/NBNS/WPAD via Responder).
- ▌ Kerberos Delegation · blacklanternsecurityExploits Kerberos delegation misconfigurations for privilege escalation and lateral movement in Active Directory. Covers Unconstrained Delegation (TGT harvesting via coercion), Constrained Delegation (S4U2Self + S4U2Proxy with SPN swapping), and Resource-Based Constrained Delegation (RBCD via writable machine accounts).
- ▌ Av Edr Evasion · blacklanternsecurityBypass antivirus and EDR detection for payload delivery during exploitation. Covers custom payload compilation (mingw C, Go), AMSI bypass, shellcode alternatives, and ETW patching. Route here when an agent reports a payload was quarantined, blocked, or detected by endpoint protection.
- ▌ File Upload Bypass · blacklanternsecurityGuide file upload restriction bypass during authorized penetration testing.
- ▌ PHP Code Injection · blacklanternsecurityExploit PHP code evaluation injection via eval(), assert(), preg_replace /e, create_function(), call_user_func(), usort() callbacks, and runtime function creation (runkit, uopz). Distinct from OS command injection (shell operators) and SSTI (template engines) — this targets direct PHP code evaluation of user input.
- ▌ Smb Share Webshell · blacklanternsecurityDeploy webshells to IIS, Apache, or Tomcat web roots via SMB share write access. Use when a domain user has write access to a file share that maps to a web server's document root — write a webshell via smbclient/net use, then trigger it via HTTP for RCE. Covers PHP, ASPX, and JSP webshells, .NET impersonation for same-host lateral movement, and internal site discovery.
- ▌ Source Code Review · blacklanternsecuritySecurity-focused source code review. Identifies hardcoded credentials, injection sinks, authentication weaknesses, and framework-specific vulnerabilities. Use when application source code is available for review.
- ▌ Smb Enumeration · blacklanternsecuritySMB share enumeration, access testing, password policy extraction, and content searching. Enumerates shares via null session, guest, and authenticated access. Covers share listing, per-share access testing, MANSPIDER content search, and SMB vulnerability detection (signing, EternalBlue). Use after network-recon identifies SMB ports (139/445).
- ▌ Linux Discovery · blacklanternsecurityLinux local privilege escalation enumeration and attack surface mapping.
- ▌ Deserialization PHP · blacklanternsecurityExploit PHP deserialization vulnerabilities during authorized penetration testing.
- ▌ SQL Injection Blind · blacklanternsecurityGuide blind SQL injection exploitation (boolean-based, time-based, and out-of-band) during authorized penetration testing.
- ▌ SQL Injection Error · blacklanternsecurityGuide error-based SQL injection exploitation during authorized penetration testing.
- ▌ SQL Injection Union · blacklanternsecurityGuide UNION-based SQL injection exploitation during authorized penetration testing.
- ▌ Adcs Access And Relay · blacklanternsecurityExploits ADCS through ACL abuse on templates/CA objects and NTLM relay to enrollment endpoints. Covers ESC4 (template ACL → modify to ESC1), ESC5 (PKI object ACLs), ESC7 (ManageCA/ManageCertificates abuse), ESC8 (NTLM relay to HTTP enrollment), ESC11 (NTLM relay to ICPR RPC).
- ▌ Smb Exploitation · blacklanternsecurityExploit remote SMB vulnerabilities for unauthenticated code execution on Windows hosts.
- ▌ Xmpp Enumeration · blacklanternsecurityXMPP/Jabber service enumeration for Openfire, ejabberd, Prosody, and other XMPP servers. Trigger when ports 5222 (client), 5223 (legacy TLS), or 5269 (server-to-server) are found open. Covers authentication testing, user enumeration, MUC room discovery, and server fingerprinting. Do NOT use for AD enumeration or credential spraying — route those to the appropriate skills.
- ▌ Browser Exploitation · blacklanternsecurityExploit browser-based attack surfaces: malicious extension crafting for bot interaction scenarios, Chrome DevTools Protocol abuse on exposed debug ports, and browser profile/cache data extraction from compromised hosts.
- ▌ Deserialization Java · blacklanternsecurityExploit Java deserialization vulnerabilities during authorized penetration testing.
- ▌ Container Escapes · blacklanternsecurityContainer escape, Docker breakout, and Kubernetes exploitation.
- ▌ Windows Discovery · blacklanternsecurityWindows local privilege escalation enumeration and attack surface mapping.
- ▌ Cors Misconfiguration · blacklanternsecurityExploit CORS (Cross-Origin Resource Sharing) misconfigurations during authorized penetration testing.
- ▌ Python Code Injection · blacklanternsecurityExploit Python eval(), exec(), and compile() injection in web applications. Distinct from OS command injection (shell operators) and SSTI (template engines) — this targets direct Python code evaluation of user input.
- ▌ SQL Injection Stacked · blacklanternsecurityGuide stacked query SQL injection and second-order injection exploitation during authorized penetration testing.
- ▌ Tomcat Manager Deploy · blacklanternsecurityDeploy WAR files via Apache Tomcat Manager for remote code execution. Use when Tomcat Manager is accessible with valid credentials (manager-script or manager-gui role). Covers WAR generation, deployment via text API and HTML interface, reverse shell delivery, and cleanup. Common initial access vector after credential discovery via LFI, default creds, or config file exposure.
- ▌ Kerberos Ticket Forging · blacklanternsecurityForges Kerberos tickets for domain persistence and privilege escalation. Covers Golden Ticket (krbtgt hash → forged TGT), Silver Ticket (service hash → forged TGS), Diamond Ticket (decrypt/modify/re-encrypt legitimate TGT for stealth), Sapphire Ticket (U2U PAC swap), and Pass-the-Ticket injection.
- ▌ Pivoting Tunneling · blacklanternsecurityNetwork pivoting, port forwarding, and tunneling through compromised hosts to reach internal networks.
- ▌ Windows Uac Bypass · blacklanternsecurityBypass Windows User Account Control to escalate from medium to high integrity.
- ▌ Deserialization Dotnet · blacklanternsecurityExploit .NET deserialization vulnerabilities during authorized penetration testing.
- ▌ Password Spraying · blacklanternsecurityPerforms password spraying against authentication services with lockout-safe techniques. Works against AD (SMB/Kerberos/LDAP), SSH, web login forms, OWA, and any service with username/password auth. Service-agnostic — the orchestrator passes target services and spray intensity tier.
- ▌ Database Enumeration · blacklanternsecurityDatabase service enumeration and quick-win access checks for MSSQL, MySQL, PostgreSQL, Oracle, MongoDB, and Redis. Checks default/empty passwords, unauthenticated access, and command execution capabilities. Use after network-recon identifies database ports.
- ▌ Password Reset Poisoning · blacklanternsecurityExploit password reset vulnerabilities during authorized penetration testing.
- ▌ Linux File Path Abuse · blacklanternsecurityExploit writable critical files, NFS misconfigurations, shared library hijacking, and privileged group membership (docker, lxd, disk, adm, video, staff) for Linux privilege escalation. Use when a user belongs to a privileged group or has write access to sensitive files or paths.
- ▌ Linux Kernel Exploits · blacklanternsecurityExploit Linux kernel vulnerabilities and escape restricted shells for privilege escalation.
- ▌ Windows Kernel Exploits · blacklanternsecurityExploit Windows kernel vulnerabilities, vulnerable drivers, and privileged file operations for local privilege escalation to SYSTEM.
- ▌ Credential Recovery · blacklanternsecurityOffline credential and file recovery with hashcat and john. Use when any skill captures hashes (NTLM, Kerberos TGS/AS-REP, shadow, MSCACHE2) or encrypted files (ZIP, Office, PDF, KeePass, SSH key, 7z, RAR). Trigger phrases: "recover this hash", "offline recovery", "john", "hashcat", "zip2john", "password-protected file". Do NOT use for online password attacks (spraying, brute force against services) — use password-spraying instead.
- ▌ Linux Cron Service Abuse · blacklanternsecurityExploit cron jobs, systemd timers/services, D-Bus services, and Unix sockets for privilege escalation.
- ▌ Unknown Vector Analysis · blacklanternsecurityAnalyze custom applications, scripts, and binaries that standard technique skills could not exploit. Performs source code review, attack surface mapping, CVE research, and PoC adaptation. Route here when ANY technique agent returns saying standard patterns do not match, the target uses a custom/unknown application, or no existing technique skill covers the vector. Trigger phrases: "standard patterns don't match", "custom script", "unknown binary", "no matching technique", "unrecognized application". Do NOT use for known vulnerability classes that have dedicated technique skills — route to those instead.
- ▌ Remote Access Enumeration · blacklanternsecurityEnumeration of remote access services: FTP, SSH, RDP, VNC, and WinRM. Checks anonymous access, default credentials, version vulnerabilities, and authentication methods. Use after network-recon identifies remote access ports.
- ▌ Windows Service Dll Abuse · blacklanternsecurityExploit Windows service misconfigurations and DLL hijacking for local privilege escalation.
- ▌ Infrastructure Enumeration · blacklanternsecurityEnumeration of infrastructure services: DNS, SMTP, SNMP, IPMI, NFS, TFTP, RPC/MSRPC, and HTTP/HTTPS surface detection. Checks zone transfers, open relays, default community strings, cipher zero, NFS exports, and web technology fingerprinting. Use after network-recon identifies infrastructure ports.
- ▌ Windows Token Impersonation · blacklanternsecurityExploit Windows token privileges for local privilege escalation to SYSTEM.
- ▌ Linux Sudo Suid Capabilities · blacklanternsecurityExploit sudo misconfigurations, SUID/SGID binaries, and Linux capabilities for privilege escalation.
- ▌ Windows Credential Harvesting · blacklanternsecurityHarvest stored credentials from a Windows system for privilege escalation or lateral movement.