ad-attacks
Active Directory attack reference — BloodHound Cypher queries, Kerberos attack decision tree, ACE/ACL abuse, ADCS ESC1-8, and AD misconfig checklist
CVSS 3.1 vector examples, executive summary template, full technical finding template, and remediation language bank for pentest reports
$ npx -y skills add mukul975/Threatswarm --skill report-templates --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/report-templatesContext preview
The summary Claude sees to decide when to auto-load this skill.
CVSS 3.1 vector examples, executive summary template, full technical finding template, and remediation language bank for pentest reports
name: report-templates description: CVSS 3.1 vector examples, executive summary template, full technical finding template, and remediation language bank for pentest reports allowed-tools: Read
CVSS:3.1/AV:[N|A|L|P]/AC:[L|H]/PR:[N|L|H]/UI:[N|R]/S:[U|C]/C:[N|L|H]/I:[N|L|H]/A:[N|L|H]
| Severity | Score Range | Typical Vector Example | Score | |---|---|---|---| | CRITICAL | 9.0–10.0 | `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H` | 9.8 | | CRITICAL | 9.0–10.0 | `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H` | 10.0 | | HIGH | 7.0–8.9 | `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H` | 8.8 | | HIGH | 7.0–8.9 | `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N` | 7.5 | | HIGH | 7.0–8.9 | `CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H` | 7.8 | | MEDIUM | 4.0–6.9 | `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N` | 6.5 | | MEDIUM | 4.0–6.9 | `CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N` | 5.4 | | MEDIUM | 4.0–6.9 | `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N` | 5.9 | | LOW | 0.1–3.9 | `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N` | 4.3 | | LOW | 0.1–3.9 | `CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N` | 2.5 | | INFO | 0.0 | N/A — informational only | 0.0 |
Pre-auth RCE (internet-facing): AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H = 9.8 Post-auth RCE (authenticated): AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H = 8.8 SQLi (data exfil possible): AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N = 8.1 SQLi (read-only): AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N = 6.5 Stored XSS (unauthenticated): AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N = 6.1 Stored XSS (post-auth): AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N = 5.4 Reflected XSS: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N = 6.1 SSRF (internal access): AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N = 7.2 SSRF (cloud metadata): AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N = 9.6 Path traversal (file read): AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N = 7.5 LPE (local exploit): AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H = 7.8 Insecure deserialization: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H = 8.1 IDOR (sensitive data): AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N = 6.5 IDOR (data modification): AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N = 8.1 Auth bypass (admin access): AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N = 9.1 Weak JWT (crackable secret): AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N = 7.4 Hardcoded credentials: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N = 9.1 Open redirect: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N = 6.1 Directory listing: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N = 5.3 Information disclosure: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N = 5.3 Missing HTTPS: AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N = 4.8 CSRF (state-changing): AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N = 6.5
---
## Executive Summary [CLIENT NAME] engaged [FIRM NAME] to conduct a [TYPE: internal/external/web application/full-scope] penetration test of [SCOPE DESCRIPTION] between [START DATE] and [END DATE]. ### Risk Posture During the assessment, [FIRM NAME] identified **[N] findings** across [M] systems, including **[X] Critical**, **[Y] High**, **[Z] Medium**, **[W] Low**, and **[V] Informational** vulnerabilities. The overall risk posture is assessed as: **[CRITICAL | HIGH | MEDIUM | LOW]** ### Key Findings The most significant finding was **[FINDING TITLE]**, which allowed testers to [IMPACT DESCRIPTION — e.g., "gain unauthenticated remote code execution on the production API server and access the customer database containing [N] records"]. Additional critical findings included: - **[Finding 2]**: [One-sentence impact] - **[Finding 3]**: [One-sentence impact] ### Business Impact Exploitation of the identified vulnerabilities could result in: - Unauthorized access to sensitive customer data (regulatory impact: GDPR, PCI-DSS) - Complete compromise of [SYSTEM] infrastructure - Reputational damage and loss of customer trust - [SPECIFIC DOLLAR/OPERATIONAL IMPACT IF QUANTIFIABLE] ### Remediation Priority | Priority | Timeline | Actions | |----------|----------|---------| | Immediate (0-7 days) | Patch [CVE], revoke [credential], disable [service] | | Short-term (8-30 days) | Implement [control], remediate [N] High findings | | Medium-term (31-90 days) | Address [N] Medium findings, establish [process] | [FIRM NAME] is available to provide remediation guidance and conduct a retest upon completion.
---
--- ## [ID]: [SEVERITY] — [Vulnerability Title] | Field | Value | |-------|-------| | **Severity** | CRITICAL / HIGH / MEDIUM / LOW / INFO | | **CVSS 3.1 Score** | [SCORE] ([CVSS:3.1/AV:.../...]) | | **CWE** | CWE-[NUMBER]: [NAME] | | **ATT&CK TTP** | [T-NUMBER]: [TECHNIQUE NAME] | | **Affected Asset** | [IP / URL / Component] | | **CVE** | CVE-XXXX-XXXXX (if applicable) | | **Date Identified** | [UTC DATE] | ### Description [2-4 sentence technical description of the vulnerability. Explain what it is, why it exists, and what conditions allow it to be exploited. Avoid jargon that a non-technical reader cannot follow in the executive summary.] ### Business Impact [1-2 sentences describing the business consequence if this vulnerability is exploited. Frame in terms of data confidentiality, regulatory requirements, operational availability, or financial impact.] ### Steps to Reproduce **Prerequisites:** [Access level required, e.g., "Unauthenticated" / "Valid user account"] 1. Navigate to `[URL]` using a web browser or send the following request: ```http [REQUEST METHOD] [PATH] HTTP/1.1 Host: [HOST] [HEADERS] [BODY IF APPLICABLE]
2. [Step 2 description]
3. The application responds with:
[RESPONSE SNIPPET or COMMAND OUTPUT]
4. [St
27 scope-enforced AI agents that run the full pentest kill-chain (recon → exploit → post-ex → DFIR → report) as a one-command Claude Code plugin. Backed by 754 MITRE-mapped skills.
Repo: mukul975/Threatswarm
Active Directory attack reference — BloodHound Cypher queries, Kerberos attack decision tree, ACE/ACL abuse, ADCS ESC1-8, and AD misconfig checklist
Exploit-DB and searchsploit reference — EDB→Metasploit module mappings, PoC reliability rubric, CVSS tier quick reference, and searchsploit usage patterns
MITRE ATT&CK framework reference — tactics, techniques, and tool-to-TTP mappings for pentest documentation and detection rule writing