reverse-skill-router
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized Active Directory and Windows identity attacks including Kerberos, AD CS, BloodHound paths, NTLM relay, and domain privilege escalation research.
$ npx -y skills add zhaoxuya520/reverse-skill --skill windows-ad --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/windows-adContext preview
The summary Claude sees to decide when to auto-load this skill.
Use for authorized Active Directory and Windows identity attacks including Kerberos, AD CS, BloodHound paths, NTLM relay, and domain privilege escalation research.
name: windows-ad description: Use for authorized Active Directory and Windows identity attacks including Kerberos, AD CS, BloodHound paths, NTLM relay, and domain privilege escalation research.
1. `NOW`: 读取 `../field-journal/precedent-pentest.md` 2. `NOW`: **域/AD 测试必须明确授权范围**(含 DC、是否允许投毒/中继) 3. `NOW`: case-init;network_profile 与禁止动作写清 4. `NEXT`: tool-index(impacket/certipy/bloodhound 等常手动) 5. `ACT`: 从身份枚举与 BloodHound 图开始,不先上破坏性利用
# 示例 Impacket / 内置(需凭据与授权) nxc smb <range> -u user -p pass bloodhound-python -d domain.local -u user -p pass -c All -ns <DC>
□ Kerberoast / AS-REP → 离线破解 □ ACL 滥用(GenericAll/WriteDacl) □ 委派(非约束/约束/基于资源) □ AD CS 模板错误 → Certipy □ 中继:LLMNR/NBT-NS + ntlmrelayx(确认授权)
□ secretsdump / lsassy / mimikatz(严格授权与清理) □ PtH / PtT / 黄金票仅在授权红队范围 □ 每步写 Evidence;高危等用户确认
| 工具 | 用途 | |------|------| | BloodHound / SharpHound | 路径图 | | Certipy | AD CS | | Impacket / NetExec | 横向与枚举 | | Rubeus / Mimikatz | 票据与凭证(授权) | | Coercer / Responder | 强制认证 / 投毒 |
**上游**: MASTER R24 **下游**: 报告 `docs-generator`;需 EDR 研究 `edr-bypass-re` **MUST NOT**: 无授权 DCSync / 黄金票打生产
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
Repo: zhaoxuya520/reverse-skill
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including…
在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native…
Use for authorized multi-stage attack-path planning and orchestration when a task spans…
跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…
Use for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection,…