← all publishers

purpleailab

@purpleailab source repo

351 published skills · page 2 of 4

  1. Anti Debug Bypass · purpleailab
    Detect and neutralize anti-debug / anti-VM checks — IsDebuggerPresent, ptrace, NtGlobalFlag, timing, hardware-breakpoint detection.
    0
    installs
  2. Windows Driver Assessment · purpleailab
    Defensive Windows internals and driver exposure assessment for owner-authorized systems and disposable research VMs.
    0
    installs
  3. Cleanup Template · purpleailab
    Cleanup & restoration plan generator — artifact inventory, persistence removal commands, pre-engagement baseline, post-engagement verification.
    0
    installs
  4. Contact Template · purpleailab
    Contact / communications plan generator — primary operator, escalation chain, abort signal recipient, external SOC endpoint, blackout windows.
    0
    installs
  5. Opplan Converter · purpleailab bundle
    Convert engagement documents into machine-readable OPPLAN for the ralph loop — objective decomposition, acceptance criteria, MITRE mapping, priority ordering.
    0
    installs
  6. Krack Fragattacks · purpleailab
    KRACK key-reinstallation (CVE-2017-13077..13082) and FragAttacks fragmentation/aggregation flaws (CVE-2020-24586..24588, CVE-2020-26139..26147) against legacy or embedded 802.11 supplicants with poor patch cadence.
    0
    installs
  7. Aatmf T07 Output Exfil · purpleailab
    AATMF T7 — Output Manipulation & Exfiltration. Covert channels in output, schema break, exfil via image gen, side-channel via timing.
    0
    installs
  8. Aatmf T13 Supply Chain · purpleailab
    AATMF T13 — AI Supply Chain & Artifact Trust. Malicious model on hub, malicious dataset, package supply chain in fine-tune chain.
    0
    installs
  9. Seven Question Gate · purpleailab
    7-question gate run before promoting a finding to FINDING + opening a report. Kills weak/non-impactful findings before they reach the report stage and damage validity ratio.
    0
    installs
  10. Patchwork Dropping Elephant · purpleailab
    Adversary-emulation profile for Patchwork (G0040 / Dropping Elephant / Chinastrats / MONSOON / Hangover Group / Operation Hangover), an India-linked cyber-espionage actor.
    0
    installs
  11. Ml Model Extraction · purpleailab
    Extract a functional clone of a black-box ML model via prediction API queries, and infer whether specific records were in the training set (membership inference).
    0
    installs
  12. Prototype Pollution · purpleailab
    Hunt JavaScript prototype pollution (CWE-1321) — the 2023-2026 meta-vulnerability that chains into RCE, auth bypass, and SSRF on most Node.js stacks.
    0
    installs
  13. Contracts Governance Attack · purpleailab
    DAO governance attack — flash-loan-backed vote manipulation, delegation hijack, quorum dilution, proposal-spam DoS, time-lock bypass via emergency multisig, snapshot vs. on-chain vote desync, Compound/Aave/Uniswap-style GovernorBravo abuse.
    0
    installs
  14. Upgradeable Proxy · purpleailab
    Proxy upgrade patterns and their bugs — uninitialized implementation, storage slot collisions, selector clashes, unprotected upgrade auth.
    0
    installs
  15. Ato Methodology · purpleailab
    Account Takeover decision tree — 9 canonical ATO paths, chaining patterns (IDOR→ATO, XSS→ATO, OAuth→ATO), MFA bypass entry points.
    0
    installs
  16. Cache Deception · purpleailab
    Web cache deception — trick CDN/proxy into caching authenticated responses under unauthenticated URLs, exposing PII to any visitor.
    0
    installs
  17. Exploit Deserialization · purpleailab
    Insecure deserialization — RCE via malicious serialized objects in Java (ysoserial), PHP (PHPGGC), .NET (ysoserial.net), and Python (pickle). Covers gadget chain selection, payload generation, and injection into cookies, POST bodies, ViewState, and API endpoints.
    0
    installs
  18. Mass Assignment · purpleailab
    Mass assignment + ORM leak — inject extra fields into create/update requests, escalate to admin, leak protected fields via response.
    0
    installs
  19. Proxy Misconfig · purpleailab
    Reverse proxy misconfigurations — nginx alias traversal, Apache mod_rewrite SSRF, Spring Boot Actuator exposure, Tomcat manager, IIS short-name disclosure.
    0
    installs
  20. HTML Smuggling Lure · purpleailab
    HTML smuggling payloads for initial access — embed base64-encoded binaries inside an HTML attachment that reconstructs and auto-downloads the file client-side via JavaScript Blob, bypassing email gateway and proxy file-type inspection.
    0
    installs
  21. Pretext Engineering · purpleailab
    Design a credible phishing pretext and target shortlist from OSINT before any campaign is built — sender persona, scenario, timing, and the minimal target set.
    0
    installs
  22. Network Replay · purpleailab
    PCAP-based network replay attacks: capture auth sequences, session tokens, and protocol frames, then replay or inject to achieve unauthorized access or session hijack.
    0
    installs
  23. Wpa Enterprise Eap · purpleailab
    WPA/WPA2/WPA3-Enterprise (802.1X/EAP) rogue-RADIUS evil-twin for MSCHAPv2 capture, GTC downgrade, and PEAP relay. MSCHAPv2 capture equals a NetNTLM hash — the primary wireless on-ramp to Active Directory.
    0
    installs
  24. Aatmf T12 RAG Poisoning · purpleailab
    AATMF T12 — RAG & Knowledge Base Manipulation. PoisonedRAG, vector store flood, embedding collision, retrieval-bias attacks.
    0
    installs
  25. Aatmf T14 Infra Warfare · purpleailab
    AATMF T14 — Infrastructure & Economic Warfare. Endpoint DoS via expensive prompts, model-API account exhaustion, GPU resource starvation, billing weaponization.
    0
    installs
  26. Muddywater Mango Sandstorm · purpleailab
    Adversary-emulation profile for MuddyWater (G0069 / Mercury / Mango Sandstorm / Static Kitten / TEMP.Zagros / Seedworm), Iran's MOIS cyber-espionage actor.
    0
    installs
  27. Sidewinder Rattlesnake · purpleailab
    Adversary-emulation profile for SideWinder (G0121 / Rattlesnake / T-APT-04 / Razor Tiger), India's suspected state-sponsored cyber-espionage actor.
    0
    installs
  28. AWS Iam Passrole Chain · purpleailab
    AWS IAM privilege escalation via `iam:PassRole` chains — Lambda/Glue/Sagemaker/EC2/ECS PassRole to a higher-priv role, AssumeRole chains across accounts, sts:GetCallerIdentity recon, account hijack via legacy root-mfa-bypass.
    0
    installs
  29. Azure Managed Identity · purpleailab
    Azure Managed Identity abuse — IMDS at 169.254.169.254 from compromised VM / App Service / Function, token exchange for Graph/ARM/KeyVault, federated workload identity abuse, hybrid AAD Connect MSOL credential extraction.
    0
    installs
  30. Pentest Task Tree · purpleailab
    Iterative PTT (Penetration Testing Tree) session reasoning — build, update, and traverse a live numbered task tree to drive LLM-guided pentest decisions across a full session.
    0
    installs
  31. Header Injection · purpleailab
    HTTP header injection — CRLF/response splitting, Host-header cache poisoning, X-Forwarded-* abuse, Content-Disposition/Set-Cookie injection, and password-reset link poisoning via unvalidated header values.
    0
    installs
  32. Web Auth Mapping · purpleailab
    Authentication surface — login endpoints, JWT/OAuth/SAML/SSO/API-key mechanism identification.
    0
    installs
  33. Web Cms Scanning · purpleailab
    CMS-specific scans — WordPress (wpscan), Joomla, Drupal version detection.
    0
    installs
  34. Web Cookie Audit · purpleailab
    Cookie-conditional sink discovery — bisect required cookies per sink, session-write timeline for race-condition challenges.
    0
    installs
  35. Reverser Ransomware Analysis · purpleailab
    Ransomware family identification and analysis — encryption scheme identification, key recovery techniques, ransom note parsing, shadow copy/recovery inhibition analysis, decryptor availability check, and IOC extraction for common ransomware families.
    0
    installs
  36. Apt33 Elfin · purpleailab
    Adversary-emulation profile for APT33 (Elfin, Peach Sandstorm, HOLMIUM), a suspected Iranian state-sponsored espionage group, mapped to MITRE ATT&CK G0064 with Decepticon emulation guidance.
    0
    installs
  37. System Prompt Leakage · purpleailab
    Hunt LLM system-prompt leakage (OWASP LLM07:2025) — exfiltration of the privileged system prompt revealing internal rules, secrets baked in, tool inventory, and business logic that should not be client-visible.
    0
    installs
  38. Unbounded Consumption · purpleailab
    Hunt LLM unbounded consumption (OWASP LLM10:2025) — denial-of-wallet and denial-of-service against LLM endpoints via unrestricted prompt size, runaway tool loops, expensive model selection, and unauthenticated fan-out.
    0
    installs
  39. Container Cve · purpleailab
    High-impact container-runtime CVE catalog — runC Leaky Vessels (CVE-2024-21626/-23651/-23652/-23653), CVE-2022-0185 (FUSE/legacy-fs), CVE-2019-5736 (runC binary replace), CRI-O Dirty COW analogs, Kubernetes API server CVE-2019-11247 (custom-resource RBAC bypass). Fingerprint → match → exploit.
    0
    installs
  40. M365 Mailbox Compromise · purpleailab
    Microsoft 365 mailbox compromise chain — OAuth consent phishing, delegate access abuse, mail rule persistence, and token theft via device code phishing. Full kill chain from initial access to persistent email collection.
    0
    installs
  41. Oracle Manipulation · purpleailab
    Hunt single-block oracle manipulation — spot-price AMM oracles, manipulable TWAP, dependent calculations, missing staleness checks.
    0
    installs
  42. Engagement Startup · purpleailab
    Mandatory first-turn startup procedure — checks for existing engagements, resume/new selection, workspace initialization.
    0
    installs
  43. Exploit Command Injection · purpleailab
    OS Command Injection — exploiting applications that pass user input to OS commands without sanitization. Covers injection operators (;, |, ||, &&, $(), backticks, newline), blind detection (time-based, OOB callback), and bypass techniques (space, keyword, encoding).
    0
    installs
  44. PHP Type Juggling · purpleailab
    PHP type juggling and magic hash attacks — exploit loose comparison (==) with 0e-prefixed hash collisions and NULL returns to bypass authentication.
    0
    installs
  45. C2 Cobalt Strike · purpleailab
    Cobalt Strike operations — Beacon deployment, Malleable C2 profile creation, listener setup, OPSEC-safe beacon configuration, process injection, and Arsenal kit usage.
    0
    installs
  46. Lateral Movement · purpleailab
    Network lateral movement — Pass-the-Hash, Pass-the-Ticket, WMI/WinRM/PsExec/RDP execution, SMB operations, network tunneling with Ligolo-ng and Chisel.
    0
    installs
  47. Web Waf Detection · purpleailab
    Web Application Firewall fingerprinting — Cloudflare, AWS WAF, Akamai, Imperva, etc.
    0
    installs
  48. Aatmf T11 Agentic Exploit · purpleailab
    AATMF T11 — Agentic & Orchestrator Exploitation. MCP tool poisoning, agent-to-agent prompt injection, tool-result spoofing, orchestrator state confusion.
    0
    installs
  49. Apt34 Oilrig · purpleailab
    Adversary-emulation profile for APT34 / OilRig (G0049), an Iranian state-sponsored espionage group, mapping its ATT&CK TTPs to Decepticon tooling for authorized red-team emulation.
    0
    installs
  50. Apt37 Reaper · purpleailab
    Adversary-emulation profile for APT37 (G0067 / Reaper / ScarCruft / Ricochet Chollima / InkySquid / Group123), North Korea's RGB cyber-espionage actor.
    0
    installs
  51. Dark Caracal · purpleailab
    Adversary-emulation profile for Dark Caracal (G0070), a Lebanese state-linked cyber-espionage and surveillance actor attributed to the General Directorate of General Security (GDGS), operating since at least 2012.
    0
    installs
  52. Salt Typhoon Earth Estries · purpleailab
    Adversary-emulation profile for Salt Typhoon (G1045 / Earth Estries / GhostEmperor / FamousSparrow / UNC2286 / RedMike / OPERATOR PANDA), a PRC state-sponsored cyber-espionage actor targeting telecommunications and critical infrastructure worldwide.
    0
    installs
  53. Volt Typhoon · purpleailab
    Adversary-emulation profile for Volt Typhoon (G1017), a PRC state-sponsored actor pre-positioning in US critical infrastructure via living-off-the-land TTPs.
    0
    installs
  54. Adversarial Ml Evasion · purpleailab
    Craft adversarial examples that cause trained ML classifiers to misclassify at inference time — image recognition, malware detectors, IDS, spam filters.
    0
    installs
  55. Chain Xss To Takeover · purpleailab
    Build chains from XSS into account takeover or privileged action execution.
    0
    installs
  56. K8S Pod Escape · purpleailab
    Kubernetes pod escape to node — privileged container abuse, hostPath mount escape, hostPID/hostIPC, capability misuse (SYS_ADMIN, SYS_PTRACE), runC CVE chains. Pivots from RCE-in-pod to full node compromise.
    0
    installs
  57. K8S Rbac Abuse · purpleailab
    Kubernetes RBAC privilege escalation paths — ClusterRole/Role enumeration via `kubectl auth can-i --list`, abuse of pods/exec, pods/portforward, secrets get, escalate verb, bind verb, impersonate verb, system:masters group abuse, ServiceAccount token theft and reuse.
    0
    installs
  58. Kill Chain Analysis · purpleailab
    Kill chain analysis and attack path decision-making — findings analysis, attack vector selection, target prioritization, phase transitions.
    0
    installs
  59. API Server Sent Events · purpleailab
    Server-Sent Events (SSE / EventSource) exploitation — origin abuse for cross-site streaming exfil, prompt-injection via SSE messages into LLM clients, retry-after token leak, fragmenting events to bypass content-type sniffers.
    0
    installs
  60. PDF Credential Harvest · purpleailab
    Weaponized PDF attachments that redirect victims to fake authentication portals (SharePoint, M365, Google Workspace) — no exploit, no macro, just a convincing document with embedded links to a credential-capture page.
    0
    installs
  61. Credential Access · purpleailab bundle
    Credential extraction and capture — LSASS dumping, SAM/SECURITY hive extraction, DPAPI decryption, NTLM relay, Responder poisoning, password spraying, hash cracking.
    0
    installs
  62. Structured Questions · purpleailab
    How to use ask_user_question — the single operator-input channel for every interview question, including free-form fields via allow_other=true.
    0
    installs
  63. Aatmf T01 Prompt Injection · purpleailab
    AATMF T1 — Prompt & Context Subversion. Direct + indirect prompt injection, ASCII smuggling, payload-in-image, prompt-leaking via reflection.
    0
    installs
  64. Aatmf T05 API Exploitation · purpleailab
    AATMF T5 — Model & API Exploitation. Rate-limit abuse, token-cost amplification, schema bypass, model-version manipulation.
    0
    installs
  65. Fin7 Carbanak · purpleailab
    Adversary-emulation profile for FIN7 (G0046; aka Carbanak, Carbon Spider, Sangria Tempest, GOLD NIAGARA, ELBRUS) — a financially motivated Russian-speaking crime group, mapping its TTPs to Decepticon tooling for authorized red-team emulation.
    0
    installs
  66. Lazarus Group · purpleailab
    Adversary-emulation profile for Lazarus Group (G0032, aka Hidden Cobra / Diamond Sleet / Labyrinth Chollima), a North Korean RGB-linked actor conducting espionage, destructive, and financially motivated operations.
    0
    installs
  67. Mustang Panda Bronze President · purpleailab
    Adversary-emulation profile for Mustang Panda (G0129 / Bronze President / Stately Taurus / RedDelta / TA416 / TEMP.Hex), a China-based state-sponsored cyber-espionage actor operating since at least 2012.
    0
    installs
  68. Sandworm Team · purpleailab
    Adversary-emulation profile for Sandworm Team (Voodoo Bear / Seashell Blizzard / APT44 / ELECTRUM), Russia's GRU Unit 74455 destructive ICS/OT and influence actor (ATT&CK G0034).
    0
    installs
  69. Chain Idor To Priv Esc · purpleailab
    Build chains where IDOR enables privilege escalation and high-impact control-plane actions.
    0
    installs
  70. Engagement Lifecycle · purpleailab
    Red team engagement lifecycle management — initiation, phase transitions, go/no-go gates, deconfliction, emergency procedures, completion.
    0
    installs
  71. Cicd Secrets Exfil · purpleailab
    Extracting CI secrets / OIDC tokens once you have code execution in a build job — echo/printenv exfil, log-masking bypass (base64, char-split, reversal), OIDC token abuse to assume cloud roles, GITHUB_TOKEN / CI_JOB_TOKEN scope abuse, cache / artifact secret leakage, provenance pivot.
    0
    installs
  72. Web Cache Poisoning · purpleailab
    Unkeyed-input cache poisoning — X-Forwarded-Host/Scheme/Port, X-Original-URL, fat-GET, parameter cloaking, oversized-header DoS, and chains to stored-XSS / open redirect via shared caches.
    0
    installs
  73. O365 Credential Harvest · purpleailab
    Harvest and replay O365 / Entra ID access via the OAuth device-code flow and captured tokens (TokenTactics-style), skipping the password + MFA prompts.
    0
    installs
  74. C2 Domain Fronting · purpleailab
    Domain fronting and CDN abuse for C2 concealment — CloudFront, Azure CDN, Fastly setup, TLS SNI vs Host header technique, CDN-based redirectors, and integration with Cobalt Strike and Sliver.
    0
    installs
  75. Linux Privesc Enum · purpleailab
    Systematic Linux privilege-escalation enumeration methodology — ordered phases covering sudo, SUID/SGID, capabilities, cron, writable paths, NFS, kernel CVEs, and GTFOBins lookup, grounded in LLM-assisted autonomous privesc research (hackingBuddyGPT/ipa-lab).
    0
    installs
  76. Web API Enumeration · purpleailab
    REST API discovery, GraphQL detection, parameter fuzzing.
    0
    installs
  77. Reverser Virtualized Protectors · purpleailab
    VMProtect, VMP2, Themida, and CodeVirtualizer reversing workflow using Radare2/Ghidra facts and Back Engineering Labs research guidance.
    0
    installs
  78. Aatmf T03 Reasoning Exploit · purpleailab
    AATMF T3 — Reasoning & Constraint Exploitation. System prompt override, constraint negation, role-reversal, instruction conflict exploit.
    0
    installs
  79. Aatmf T15 Human AI Coupling · purpleailab
    AATMF T15 — Human-AI Coupling. Deepfake escalation, voice clone vishing, deepfake-image-driven social engineering, automation of human-targeted attacks.
    0
    installs
  80. Pink Sandstorm Agrius · purpleailab
    Adversary-emulation profile for Pink Sandstorm (G1030 / Agrius / Agonizing Serpens / AMERICIUM / BlackShadow / DEV-0227), Iran's MOIS-linked destructive wiper and pseudo-ransomware operator.
    0
    installs
  81. Data And Model Poisoning · purpleailab
    Hunt LLM training-data and model poisoning (OWASP LLM04:2025) — adversarial inputs that bias future model behaviour through fine-tuning, RLHF, or continuous-learning loops.
    0
    installs
  82. Improper Output Handling · purpleailab
    Hunt improper LLM output handling (OWASP LLM05:2025) — downstream code that trusts unstructured model output and renders / executes / shells it without sanitisation, producing XSS, SSRF, SQL injection, RCE, and SSTI via the model channel.
    0
    installs
  83. Entra Device Code Phishing · purpleailab
    Entra ID OAuth device-code phishing for token theft, illicit consent grant via malicious app registration with delegated Graph scopes, refresh-token replay, and primary-refresh-token (PRT) abuse concepts.
    0
    installs
  84. Edge Device Exploitation · purpleailab
    Edge device exploitation — routers, firewalls, VPN appliances (Cisco IOS XE, Fortinet, Ivanti, Palo Alto). Covers CVE exploitation chains, post-exploitation on network devices, config extraction, and implant deployment on perimeter infrastructure.
    0
    installs
  85. Data Handling Template · purpleailab
    Data handling plan generator — evidence retention, encryption, chain-of-custody, compliance frameworks (GDPR / HIPAA / PCI-DSS / SOC2).
    0
    installs
  86. Aatmf T02 Linguistic Evasion · purpleailab
    AATMF T2 — Semantic & Linguistic Evasion. Foreign-language pivot, encoded payloads, esolang, fictional framing, jailbreak via translation.
    0
    installs
  87. Aatmf T06 Training Poisoning · purpleailab
    AATMF T6 — Training & Feedback Poisoning. Data poisoning, RLHF reward hacks, fine-tune-time exfil, embedding poisoning.
    0
    installs
  88. Apt29 Cozy Bear · purpleailab
    Adversary-emulation profile for APT29 (Cozy Bear / Midnight Blizzard / NOBELIUM / The Dukes), Russia's SVR-attributed cyber-espionage group, mapping its ATT&CK TTPs to Decepticon emulation tooling.
    0
    installs
  89. Dep Confusion · purpleailab
    Dependency confusion — publish a higher-version internal package name on public registry (npm/PyPI/Maven/Crates) to coerce CI/CD into pulling attacker code.
    0
    installs
  90. Privilege Escalation · purpleailab
    Host privilege escalation — Windows token impersonation, UAC bypass, service abuse, DLL hijacking, Linux SUID/sudo/kernel exploits, automated enumeration.
    0
    installs
  91. Aatmf T04 Memory Manipulation · purpleailab
    AATMF T4 — Multi-Turn & Memory Manipulation. Persistent memory injection, conversation-state poisoning, cross-session contamination, ghost-context leak.
    0
    installs
  92. Apt28 Fancy Bear · purpleailab
    Adversary-emulation profile for APT28 (G0007 / Fancy Bear / Forest Blizzard / Sofacy / STRONTIUM), Russia's GRU Unit 26165 cyber-espionage actor.
    0
    installs
  93. Scattered Spider · purpleailab
    Adversary-emulation profile for Scattered Spider (UNC3944/Octo Tempest), a financially motivated social-engineering-led intrusion group, mapped to ATT&CK G1015 and Decepticon tooling.
    0
    installs
  94. Web Subdomain Takeover · purpleailab
    Subdomain takeover via dangling DNS/CNAME — GitHub Pages, Heroku, Azure, Fastly, Shopify, Netlify, Surge, Tumblr, Beanstalk, Zendesk, etc.
    0
    installs
  95. Emulation Overview · purpleailab
    Adversary-emulation playbook catalog — per-actor kill chains that turn an APT/eCrime threat profile into Decepticon CONOPS phases + OPPLAN objectives. Routing skill: pick the actor, seed plan/threat-profile.json, then map each kill-chain phase to the operational skill the executing agent runs. Triggers on: 'emulate', 'adversary emulation', 'APT playbook', 'threat actor playbook', 'emulation plan', 'attack flow'.
    0
    installs
  96. Apt10 Stone Panda · purpleailab
    Adversary-emulation profile for APT10 (G0045 / Stone Panda / menuPass / POTASSIUM / Red Apollo / CVNX), China's MSS Tianjin State Security Bureau cyber-espionage actor.
    0
    installs
  97. Docker Socket Mount · purpleailab
    Docker / containerd socket mounted into a container → host RCE. Common in CI runners, GitOps controllers (ArgoCD, Flux), and 'Docker-in-Docker' setups. Single-command escape via `docker run --rm --privileged -v /:/host alpine chroot /host`.
    0
    installs
  98. GCP Svc Account Impersonation · purpleailab
    GCP service account impersonation chain — IAM `roles/iam.serviceAccountTokenCreator`, `roles/iam.serviceAccountUser`, `actAs` on Cloud Functions / Cloud Run / Compute Engine. Pivot from low-priv SA to org-admin via chained impersonation.
    0
    installs
  99. C2 Alternative Channels · purpleailab
    Non-traditional C2 channels — Discord/Telegram bots, DNS-over-HTTPS, blockchain-based C2, email-based C2, and cloud function dead drops for covert command and control.
    0
    installs
  100. Aatmf T10 Confidentiality Breach · purpleailab
    AATMF T10 — Integrity & Confidentiality Breach. System prompt extraction, training-data extraction, model-weight leakage, private-key recovery.
    0
    installs