Claude Skills · Research

通用网络与资产信息收集。面向 IP、CIDR、主机名、企业/域名等尚未明确攻击面的目标,完成资产扩展、主机发现、TCP/UDP端口发现、服务/版本/协议识别、只读服务枚举、网络设备识别和漏洞候选研判。Recon only:不执行漏洞利用、口令爆破、服务配置修改或持久化。

★ 27 Synced 1 hour ago View SKILL.md

At a glance

Research Manual install

This skill is for Research and helps you discover network assets and infrastructure, identify services and versions on hosts, and enumerate open ports and protocols.

Install git clone --depth 1 https://github.com/pale-knight/redteam-skill cp -r redteam-skill/skills/recon ~/.claude/skills/recon
Can use Not declared by the author

Network ReconnaissanceAsset DiscoveryPort ScanningService EnumerationSecurity Assessment

Also in pale-knight/redteam-skill

View the repo
Ad Attack Support

Active Directory exploitation after domain credentials exist: Kerberos (AS-REP/Kerberoast including cracking the ticket then using the accou...

Ad Recon DevOps & Infrastructure

Active Directory reconnaissance with or without credentials: user/group/computer enumeration, ACL/delegation, ADCS, modern Windows LAPS, Blo...

Cicd DevOps & Infrastructure

CI/CD pipeline and software-supply-chain exploitation: Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps, Gitea/Forgejo, self-hosted runne...

Cloud Attack DevOps & Infrastructure

Cloud control-plane exploitation for AWS, Azure/Entra, GCP, and Alibaba Cloud: IAM/RAM privilege escalation, impersonation, cross-account tr...

Cloud Recon DevOps & Infrastructure

Cloud control-plane reconnaissance for AWS, Azure/Entra, GCP, and Alibaba Cloud: identity, IAM/RAM, trust, resources, metadata, and managed-...

Creds Support

Credential operations: secret discovery, classification, extraction, conversion, offline cracking of hashes the operator already has as a cr...

Edr Bypass DevOps & Infrastructure

Endpoint defense evasion after an operator-selected chain already has a valid execution path but AV/EDR/AMSI/WDAC/PPL/memory/kernel telemetr...

K8S DevOps & Infrastructure

Kubernetes and container exploitation: identity/RBAC, secrets, kubelet/etcd, managed-cloud workload identities, container-to-node escape inc...

Phishing Support

Client-side initial access and social-engineering attack module. Use when the operator selects a human/client/browser/identity-delivery atta...

Post DevOps & Infrastructure

OS post-exploitation after a stable host foothold: quiet host recon, host-native persistence (Windows Run/tasks/services/COM/WMI and Linux S...

Privesc Linux DevOps & Infrastructure

Linux local privilege escalation from a low-privilege shell to root. Covers quiet vs loud enumeration, sudo/GTFOBins, CVE-2025-32463 chwoot...

Privesc Win Legal

Windows local privilege escalation from a low-privilege shell to Administrator or SYSTEM. Covers quiet vs loud enumeration, SeImpersonate/Po...

Other Research skills

Research mattpocock/skills

Investigate a question against high-trust primary sources and capture the findings as a Markdown file in the repo. Use when the user wants a...

Last30days nexu-io/open-design

Recent community and social trend research over the last 30 days. Use when the brief asks what people are saying now, recent sentiment, comm...

X Research nexu-io/open-design

X/Twitter public sentiment research for recent market, company, product, or community discourse. Use when the brief asks what people are say...

Persona Researcher googleworkspace/cli

Organize research — manage references, notes, and collaboration.

Aihot KKKKhazix/khazix-skills

查询 AI HOT 的中文 AI 资讯、精选、当前热点和日报。用户询问今天或最近的 AI 新闻、AI 圈动态、大模型或产品发布、OpenAI/Anthropic/Google 最新...

Council 0xNyk/council-of-high-intelligence

Convene the Council of High Intelligence — multi-persona deliberation with historical thinkers for deeper analysis of complex problems.