pale-knight
- 18 skills
- 0 followers
- 9 hours ago last updated
- ▌ K8S · pale-knight bundleKubernetes and container exploitation: identity/RBAC, secrets, kubelet/etcd, managed-cloud workload identities, container-to-node escape including CVE-2026-31431 Copy Fail, and Kubernetes-native persistence. Use when already in a Pod/container or holding kubeconfig. Own the chain to cluster-admin, node root, or a usable cloud identity. Operator chooses next modules. Endpoint blocks after OS execution hand off to /edr-bypass then return.
- ▌ Cicd · pale-knight bundleCI/CD pipeline and software-supply-chain exploitation: Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps, Gitea/Forgejo, self-hosted runners/agents, poisoned pipeline execution, artifact/cache abuse, dependency confusion, third-party Action trust, GitOps/registry poisoning, workload identity/OIDC, and emerging agentic CI/CD. Use this skill when the operator has access to a CI/CD system, source repository, build/deploy configuration, runner/agent, artifact/package/registry path, or software delivery trust chain.
- ▌ Post · pale-knight bundleOS post-exploitation after a stable host foothold: quiet host recon, host-native persistence (Windows Run/tasks/services/COM/WMI and Linux SSH/cron/systemd/SUID), long-term C2 (Sliver primary, Mythic/Havoc optional), targeted collection and exfil, and engagement cleanup. Does not own AD/cloud/K8s native persistence, Ligolo pivoting, LSASS dumping, or EDR bypass. Operator selects objectives; success is a live callback, verified persistence, delivered loot, or restored host — not generating an unused implant.
- ▌ Creds · pale-knight bundleCredential operations: secret discovery, classification, extraction, conversion, offline cracking of hashes the operator already has as a credential job, policy-aware spraying, NetNTLM capture, generic SMB relay, and Windows/Linux harvest. Do not hijack an in-progress /ad-attack Kerberoast/AS-REP chain (that module cracks and uses the ticket itself). Do not DCSync, read LAPS LDAP, or escalate cloud IAM. Usable credentials are recorded; the operator chooses the next module.
- ▌ Recon · pale-knight bundle通用网络与资产信息收集。面向 IP、CIDR、主机名、企业/域名等尚未明确攻击面的目标,完成资产扩展、主机发现、TCP/UDP端口发现、服务/版本/协议识别、只读服务枚举、网络设备识别和漏洞候选研判。Recon only:不执行漏洞利用、口令爆破、服务配置修改或持久化。
- ▌ Shell · pale-knight bundleShell and session operations after an attack module already established command execution, a raw shell, webshell channel, container/runner shell, or remote session. This module does not own exploitation and should not pull SSH/WinRM/RDP authentication or vulnerability-to-shell chains out of Web/AD/Cloud/K8s/CI-CD/Service/Phishing. Use it to bootstrap a usable callback from existing command execution, stabilize Linux PTY, upgrade Windows sessions with ConPTY where applicable, manage listeners, recover fragile sessions, and exchange files for continued operations.
- ▌ Tunnel · pale-knight bundleNetwork reachability and pivoting after an operator already has a foothold. Use to make previously unreachable hosts, subnets, services or listener directions reachable via Ligolo-ng, Chisel, GOST v3, SSH/native forwarding, socat/netsh, Microsoft Dev Tunnels, DNS/HTTP/QUIC fallback transports, and multi-hop routing. This module does not exploit services, obtain credentials, or own C2/persistence. Its success condition is changed reachability: the operator can route/connect to the intended internal network/service through the selected foothold.
- ▌ Ad Recon · pale-knight bundleActive Directory reconnaissance with or without credentials: user/group/computer enumeration, ACL/delegation, ADCS, modern Windows LAPS, BloodHound, Server 2025/dMSA/Ghost SPN candidates, and trust mapping. Recon only — do not exploit Kerberoast-to-DA, DCSync, or change passwords. Operator may select /ad-attack after cards are ready.
- ▌ Phishing · pale-knight bundleClient-side initial access and social-engineering attack module. Use when the operator selects a human/client/browser/identity-delivery attack direction: ClickFix/FileFix, AiTM session phishing, OAuth device-code or consent abuse, Teams/helpdesk social engineering, HTML/file delivery, QR/mobile handoff, legacy HTA/OLE/Office paths. This is an Attack module: own the chain until host shell or remote interactive foothold. Credential/token/session are intermediate results, not the stop condition. If endpoint AV/EDR/AMSI/application-control blocks an otherwise-valid client execution path, the operator may temporarily select /edr-bypass and then resume this phishing chain until shell.
- ▌ Ad Attack · pale-knight bundleActive Directory exploitation after domain credentials exist: Kerberos (AS-REP/Kerberoast including cracking the ticket then using the account), delegation, NTLM coercion/relay, lateral movement, ACL abuse, ADCS ESC1-ESC17 and CVE paths, dMSA/BadSuccessor, Kerberos reflection, identity confusion, management-plane, domain trust, and domain persistence. Own the current AD chain through crack-and-use to DA, equivalent domain control, or the targeted host SYSTEM. Do not stop after requesting TGS. Host C2 belongs to /post. Operator chooses next modules.
- ▌ Web Recon · pale-knight bundleHTTP/HTTPS application-layer reconnaissance after a web service is identified: fingerprinting, content/API discovery, JS/source maps, proxy/cache topology, WAF, CMS, and known CVE/PoC candidates. Recon only — do not exploit, write files, or obtain a shell. Hand CVE candidates and attack surface to the operator, who may select /web-attack. Non-HTTP ports belong to /recon.
- ▌ Edr Bypass · pale-knight bundleEndpoint defense evasion after an operator-selected chain already has a valid execution path but AV/EDR/AMSI/WDAC/PPL/memory/kernel telemetry blocks the intended action. Originating modules include /web-attack /ad-attack /cloud-attack /k8s /cicd /service-attack /phishing /privesc-win /privesc-linux /creds /post /shell. Success is the blocked action becoming executable, then resume the originating module — not obtaining a shell here.
- ▌ Web Attack · pale-knight bundleHTTP/Web exploitation until a server shell or equivalent OS execution. Use after /web-recon has mapped the application. Covers injection, upload, LFI, SSRF/XXE, SSTI, deserialization, JWT/SAML, API logic, desync/cache/parser, and Web-controlled backend abuse. WAF stays here. Endpoint blocks after OS execution hand off to /edr-bypass then return. Direct non-HTTP service ports belong to /recon or /service-attack.
- ▌ Cloud Recon · pale-knight bundleCloud control-plane reconnaissance for AWS, Azure/Entra, GCP, and Alibaba Cloud: identity, IAM/RAM, trust, resources, metadata, and managed-Kubernetes cloud-side boundary. Recon only — no policy changes, no privilege escalation. Operator may select /cloud-attack or /k8s.
- ▌ Privesc Win · pale-knight bundleWindows local privilege escalation from a low-privilege shell to Administrator or SYSTEM. Covers quiet vs loud enumeration, SeImpersonate/Potato family including LocalPotato, token privileges (SeBackup/SeRestore/SeManageVolume/SeLoadDriver/SeDebug), service/DLL/COM/scheduled-task abuse, AlwaysInstallElevated and UAC boundary, KrbRelayUp-style domain-joined local admin, and version-gated kernel LPE. Use when the operator already has a Windows foothold and needs local SYSTEM. Endpoint blocks hand off to /edr-bypass then return here.
- ▌ Cloud Attack · pale-knight bundleCloud control-plane exploitation for AWS, Azure/Entra, GCP, and Alibaba Cloud: IAM/RAM privilege escalation, impersonation, cross-account trust, serverless/compute control, and cloud-native persistence. Host OS persistence/C2 after root/SYSTEM belongs to /post. K8s RBAC belongs to /k8s. Operator chooses next modules; new identities default to /cloud-recon first.
- ▌ Privesc Linux · pale-knight bundleLinux local privilege escalation from a low-privilege shell to root. Covers quiet vs loud enumeration, sudo/GTFOBins, CVE-2025-32463 chwoot and CVE-2025-32462 host bypass, polkit/udisks CVE-2025-6018/6019, SUID/capabilities, systemd timers/units, cron/PATH/LD_PRELOAD, dangerous groups and docker.sock, host-local container escape, and version-gated kernel LPE including Copy Fail CVE-2026-31431. Use when the operator has a Linux foothold and needs root. Kubernetes RBAC stays in /k8s. Endpoint blocks hand off to /edr-bypass then return here.
- ▌ Service Attack · pale-knight bundle直连网络服务攻击链。用于已经识别/枚举的非专门领域服务,从数据库、数据存储、文件/远程访问、基础设施、消息队列、DNS/网络服务、打印机/MFP/NAS/BMC/网络设备等服务入口继续利用到凭据、代码执行、主机控制、横向能力或新的独立身份。由操作者选择具体攻击链;不自动切换模块。