Search
Red teaming and adversary simulation
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries. | Tencent/ | 6.8k | — | ~753 | Automated safety check: Pass | Apache-2.0 | today |
| 2 | Run an ASSERT evaluation against a described risk. An agent skill from responsibleai/ASSERT. | responsibleai/ | 330 | — | ~11k | Automated safety check: Notes | MIT | yesterday |
| 3 | Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. | elementalsouls/ | 2.8k | — | ~8.7k | Automated safety check: Notes | MIT | 1 mo ago |
| 4 | Design a loss function and harness for a long-running /goal optimization run (loss-function development, LFD). | elvisun/ | 176 | — | ~2.9k | Automated safety check: Notes | MIT | 4 mo ago |
| 5 | Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication… | ADScanPro/ | 211 | — | ~2.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 6 | Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths. | Tencent/ | 6.8k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 7 | Probes whether an agent can be hijacked by instructions hidden in documents, retrieved chunks or fetched web pages, using test prompts that embed a hidden instruction. | Tencent/ | 6.8k | — | ~1.1k | Automated safety check: Warn | Apache-2.0 | today |
| 8 | Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding… | ADScanPro/ | 211 | — | ~2.9k | Automated safety check: Notes | MIT | 1 mo ago |
| 9 | Run a spec-driven agent loop where coding tasks live as markdown specs that move through inbox → active → archive, get implemented by Claude Code or Codex, and pass a review gate before they count… | JuliusBrussee/ | 162 | — | ~2k | Automated safety check: Pass | MIT | 2 mo ago |
| 10 | Plan, execute, document, and retest authorized security assessments of AI agents and multi-agent workflows using safe adversarial cases, synthetic identities, canaries, and evidence-based findings. | seb1n/ | 206 | — | ~2.8k | Automated safety check: Pass | MIT | 2 mo ago |
| 11 | The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the… | ADScanPro/ | 211 | — | ~2.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 12 | 12.Blue Team A skill your agent uses when the user has concrete failing cases in code or a guardrail/classifier/filter/prompt/API they own — a red-team failure catalogue OR a CI/CD test-failure report (failing… | gaasher/ | 174 | — | ~3.6k | Automated safety check: Pass | MIT | 3 mo ago |
| 13 | Analyzes authentication and authorization events for failed-login clustering, privilege-escalation chains, credential-stuffing patterns, and MFA-bypass indicators. | ahmadvh/ | 376 | — | ~1.3k | Automated safety check: Pass | Unknown | 1 mo ago |
| 14 | Probes an AI agent for supply-chain weaknesses: whether it loads untrusted plugins, tools or models, updates dependencies without pinning, or trusts user-supplied artifacts. | Tencent/ | 6.8k | — | ~760 | Automated safety check: Pass | Apache-2.0 | today |
| 15 | 15.Adcs Attacks Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k). | ADScanPro/ | 211 | — | ~3.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 16 | 16.Council Run a model-diverse subagent council to investigate the same problem from multiple perspectives, compare findings, and produce a final recommendation. | warpdotdev/ | 611 | 1 repo | ~1.8k | Automated safety check: Pass | MIT | 2 days ago |
| 17 | Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB. | ADScanPro/ | 211 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 18 | Tests a target AI agent for sensitive information disclosure, such as its system prompt, credentials, personal data and internal configuration, using escalating dialogue probes. | Tencent/ | 6.8k | — | ~954 | Automated safety check: Pass | Apache-2.0 | today |
| 19 | Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD). | ADScanPro/ | 211 | — | ~2.9k | Automated safety check: Notes | MIT | 1 mo ago |
| 20 | Audit Entra ID app registration and service principal security posture. | SCStelz/ | 250 | — | ~21k | Automated safety check: Pass | MIT | yesterday |
| 21 | Configure SAML 2.0 identity federation between on-premises Active Directory (via AD FS or a third-party IdP) and Microsoft Entra ID, covering federation models (AD FS, password hash sync… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 22 | Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations. | ArabelaTso/ | 253 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 23 | A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch. | ADScanPro/ | 211 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 24 | Administer Windows Server systems. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~2.9k | Automated safety check: Pass | MIT | today |
| 25 | Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml). | github/ | 40k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | today |
| 26 | Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e… | ohmyjahh/ | 277 | — | ~895 | Automated safety check: Pass | MIT | 10 days ago |
| 27 | Answer general or cross-domain questions with a non-pleasing rational mode: adversarial red-team and blue-team expert analysis, mutually exclusive conclusions, up to five debate rounds, saved… | digoal/ | 8.6k | — | ~2.2k | Automated safety check: Pass | GPL-2.0 | today |
| 28 | 28.Wargame Multi-turn adversary simulation. An agent skill from NovusEdge/palpatine. | NovusEdge/ | 110 | — | ~1.1k | Automated safety check: Pass | Unknown | 25 days ago |
| 29 | Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 30 | Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 31 | Detect DCSync attacks (MITRE T1003.006) where adversaries abuse Active Directory replication privileges to extract password hashes, by auditing Event ID 4662 for the DS-Replication-Get-Changes GUIDs… | mukul975/ | 34k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 32 | Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests (Event ID 4769) targeting service accounts with SPNs, which attackers request offline to crack service account passwords. | mukul975/ | 34k | — | ~914 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 33 | Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service (WMI/PsExec/RDP) abuse. | mukul975/ | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 34 | Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse detection, network traffic monitoring, and dynamic instrumentation. | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 35 | Detect Pass-the-Hash (T1550.002) attacks by analyzing NTLM authentication patterns, flagging Type 3 logons using NTLM where Kerberos would be expected, and correlating with credential-dumping… | mukul975/ | 34k | — | ~904 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 36 | Detect privilege escalation attempts across Windows and Linux, including access token manipulation, UAC bypass, unquoted service path abuse, kernel exploits, and sudo/doas abuse. | mukul975/ | 34k | — | ~922 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 37 | Detects and prevents privilege escalation inside Kubernetes pods by combining admission control (OPA policies), runtime monitoring (Falco), and audit log analysis of security contexts, Linux… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 38 | Detect abuse of service accounts by hunting for anomalous interactive logons, privilege escalation, and lateral movement using EDR/SIEM telemetry (CrowdStrike Falcon, Microsoft Defender, Splunk… | mukul975/ | 34k | — | ~904 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 39 | Detect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry… | mukul975/ | 34k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 40 | Uses the Metasploit Framework (msfconsole and its exploit, auxiliary, and post-exploitation modules) to validate that identified CVEs and vulnerabilities are actually exploitable, gather… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 41 | Hardens the Docker daemon (dockerd) through /etc/docker/daemon.json with user namespace remapping, TLS client authentication, seccomp profiles, and CIS Docker Benchmark controls such as icc… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 42 | Hunts for adversary abuse of legitimate cloud services (Azure, AWS, GCP, and SaaS platforms) for command-and-control, data staging, and exfiltration, i.e. | mukul975/ | 34k | — | ~925 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 43 | Runs a hypothesis-driven threat hunt for command-and-control activity (T1071) by querying SIEM/EDR network telemetry for anomalous outbound traffic, rare destinations, non-standard ports, and… | mukul975/ | 34k | — | ~914 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 44 | Hardens Kubernetes RBAC by designing least-privilege Roles and ClusterRoles, auditing RoleBindings, eliminating cluster-admin sprawl, separating service accounts, and integrating an external OIDC… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 45 | Execute cloud-native incident containment across AWS, Azure, and GCP using platform CLIs to revoke or disable compromised IAM credentials, isolate resources with security groups and network ACLs… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 46 | Evaluates Kubernetes cluster security by actively simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policy, and secrets, using kube-hunter, Kubescape… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 47 | Perform structured log source onboarding into SIEM platforms (Splunk, Elastic, Sentinel, QRadar, or similar) by prioritizing sources with a tiered value framework, configuring collectors, building… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 48 | Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |