DouglasRao
- 8 skills
- 0 followers
- 7 hours ago last updated
- ▌ Ad Recon · douglasrao bundleActive Directory reconnaissance skill — host discovery and comprehensive AD enumeration. Activate when the user wants to map an AD environment, enumerate users, groups, shares, trusts, SPNs, or BloodHound data before attacking. Also activate for phrases like "map the domain", "enumerate AD", "find AD users", "collect BloodHound data", or any variation of "start an AD pentest" on a domain target. Outputs feed directly into the ad-exploitation skill.
- ▌ Ad Report · douglasraoActive Directory penetration testing report generation skill. Activate when the user wants to write, generate, or finalize a report for an AD pentest engagement. Consolidates outputs from ad-recon, ad-exploitation, and ad-postexploitation skills into a structured technical and executive report. Produces findings in standardized format (name, criticality, CVSS, description, impact, recommendation, evidence). Default mode: combined technical + executive. Publishes to Notion via MCP when available.
- ▌ Web Recon · douglasrao bundleFull offensive reconnaissance skill for Web Pentest and Bug Bounty. Activate when the user mentions recon, reconnaissance, subdomain enumeration, attack surface mapping, bug bounty recon, or any variation of "start a pentest" on a domain/target. Covers: subdomain enumeration, DNS resolution, live detection, screenshots, URL/parameter discovery, JS analysis (source maps + secrets), content discovery, nuclei scan, CMS scan (WordPress/Drupal/Joomla), and intelligence report generation. All output is saved in a subdirectory named after the target within the current project directory.
- ▌ Web Report · douglasraoWeb penetration testing report generation skill. Activate when the user wants to write, generate, or finalize a report for a web pentest or bug bounty engagement. Consolidates outputs from web-recon, web-exploitation, and web-postexploitation skills into a structured technical and executive report. Produces findings in standardized format (name, criticality, CVSS, description, impact, recommendation, evidence). Default mode: combined technical + executive report. Publishes to Notion via MCP when available.
- ▌ Ad Exploitation · douglasrao bundleActive Directory exploitation skill — credential attacks, lateral movement, privilege escalation, and domain domination. Activate when the user wants to exploit an AD environment after enumeration, or mentions: Kerberoasting, AS-REP Roasting, pass-the-hash, pass-the-ticket, lateral movement, DCSync, Golden Ticket, BloodHound attack paths, evil-winrm, PSExec, or any variation of "attack the domain", "escalate in AD", "get domain admin". Picks up from ad-recon output when available.
- ▌ Web Exploitation · douglasrao bundleWeb application exploitation skill — offensive kill chain for confirming and exploiting vulnerabilities discovered during web recon. Activate when the user mentions exploiting, testing, or confirming vulnerabilities such as SQLi, XSS, LFI, RFI, SSRF, SSTI, XXE, broken access control, IDOR, JWT attacks, OAuth abuse, file upload bypass, deserialization, RCE, CSRF, or any variation of "exploit this endpoint", "test this param", or "web exploitation" after a recon phase. Picks up where web-recon leaves off — reuses recon output when available.
- ▌ Ad Postexploitation · douglasraoActive Directory post-exploitation skill — covers everything after gaining initial access to a Windows domain environment. Activate when the user has valid domain credentials, a shell on a domain-joined machine, or escalated privileges and wants to: move laterally across the network, escalate to Domain Admin, harvest credentials from memory or disk, establish domain persistence, dump LSASS, abuse privilege tokens, or pivot through the domain. Also activate for: pass-the-hash, pass-the-ticket, Mimikatz, LSASS dump, token impersonation, SAM dump, scheduled task persistence, Skeleton Key, Diamond Ticket, AdminSDHolder, or any post-compromise AD activity.
- ▌ Web Postexploitation · douglasraoWeb post-exploitation skill — covers everything after achieving code execution on a web server. Activate when the user has a webshell, reverse shell, or confirmed RCE on a web server and wants to: stabilize the shell, escalate privileges, enumerate the server, exfiltrate data, move laterally, or establish persistence. Also covers PHP disable_functions bypass, webshell obfuscation, and reverse shell generation. Assumes the user has already exploited a vulnerability and needs to maximize access from within the web server context.