with one click
Aurora-AI-Agency
Aurora-AI-Agency contains 17 collected skills from az0307, with repository-level occupation coverage and site-owned skill detail pages.
Skills in this repository
Active Directory and Windows domain attack techniques including domain enumeration, Kerberos attacks, credential relay, lateral movement, and domain privilege escalation for internal penetration testing engagements. Use this skill whenever the user mentions Active Directory, AD attacks, domain enumeration, BloodHound, Kerberoasting, AS-REP roasting, pass the hash, pass the ticket, overpass the hash, golden ticket, silver ticket, DCSync, DCShadow, NTDS.dit extraction, LDAP enumeration, domain controller, Group Policy abuse, ACL abuse, delegation abuse, constrained delegation, unconstrained delegation, resource-based constrained delegation, ADCS attacks, certificate abuse, LAPS, gMSA, domain trust attacks, forest trust, or any Windows domain-focused penetration testing activity. Also trigger for: impacket, crackmapexec, evil-winrm, bloodhound-python, kerbrute, responder, ntlmrelayx, petitpotam, certipy, rubeus, mimikatz, powerview, sharphound, enum4linux, smbclient, rpcclient, "enumerate the domain", "dump doma
Security engagement audit logging, evidence chain management, and compliance trail for penetration testing. Use this skill whenever the user mentions audit log, audit trail, engagement logging, evidence collection, chain of custody, compliance logging, pentest logging, tool execution logging, JSONL log, activity log, forensic evidence, engagement timeline, or any request to log, track, or document security testing activities. Also trigger for: "log this action", "create audit trail", "evidence chain", "what did we do", "engagement timeline", "export activity log", or when any other security skill needs to record its actions for compliance. This skill is called BY other skills — it is the universal logging layer.
Password cracking, credential brute force, hash analysis, and authentication testing for penetration testing engagements. Use this skill whenever the user mentions password cracking, hash cracking, brute force attack, credential spraying, password spray, dictionary attack, hashcat, john the ripper, hydra, medusa, credential stuffing, NTLM hash, NTHash, NetNTLMv2, Kerberos ticket cracking, AS-REP roasting, Kerberoasting, hash identification, rainbow tables, wordlist generation, custom wordlists, CeWL, crunch, cupp, password policy analysis, or any request to crack, guess, or test credentials. Also trigger for: "crack these hashes", "brute force this login", "test default credentials", "generate a wordlist", "what hash type is this", "password audit", or any credential-related testing activity. Expert tools: hashcat (GPU), john (CPU), hydra (online brute force), crackmapexec (network cred testing), medusa (parallel brute force).
Generate structured CTF walkthrough writeups from engagement data, findings, and attack paths. Use this skill whenever the user mentions CTF writeup, walkthrough, write-up, CTF solution, box writeup, challenge writeup, HackTheBox writeup, TryHackMe writeup, "write up this box", "document how I solved", "create a walkthrough for", or any request to document a CTF/lab solution in educational format. Also trigger for: "writeup for HTB", "THM walkthrough", "document the attack path", "how did we solve this", or when red-team-report is called with engagement type CTF. Produces clean Markdown writeups with technique explanations, command output, and learning notes — suitable for blog posts or portfolio.
Exploit research, proof-of-concept development, controlled exploitation, and initial access verification for penetration testing engagements. Use this skill whenever the user mentions exploit development, PoC creation, Metasploit module execution, searchsploit, payload generation, msfvenom, exploit testing, vulnerability exploitation, initial access, shell access, reverse shell, bind shell, exploit chain, privilege escalation exploits, buffer overflow, web shell upload, or "can we exploit this finding". Also trigger for: ExploitDB search, Metasploit framework usage, custom exploit writing, payload encoding, exploit adaptation, weaponization, or any request to move from identified vulnerability to confirmed access. This is phase three of a pentest — trigger after vuln-analysis confirms exploitable findings, or standalone when the operator has a specific CVE. CRITICAL: All exploitation requires human approval before execution. The AI prepares commands and payloads but the operator confirms each run.
Network traffic capture, packet analysis, protocol dissection, and digital evidence preservation for security engagements. Use this skill whenever the user mentions packet capture, pcap analysis, Wireshark, tshark, tcpdump, network forensics, traffic analysis, protocol analysis, packet inspection, network evidence, DNS analysis from captures, HTTP traffic extraction, credential sniffing from pcap, malware traffic analysis, C2 detection, network timeline reconstruction, or any task involving captured network data. Also trigger for: "capture traffic", "analyze this pcap", "what's in this capture", "extract files from pcap", "find credentials in traffic", "reconstruct network session", or any network evidence analysis task. Expert tools: tshark (CLI analysis), tcpdump (capture), Wireshark (GUI), NetworkMiner (artifact extraction), zeek (protocol logging).
Custom payload generation, encoding, obfuscation, and delivery mechanism design for authorized penetration testing. Use this skill when the user mentions payload generation, msfvenom, reverse shell, bind shell, web shell, shellcode, payload encoding, AV evasion, payload obfuscation, custom exploit payload, stager, stageless, meterpreter payload, shell payload, PowerShell payload, Python payload, macro payload, HTA payload, or any request to generate code that establishes remote access on an authorized target. Also trigger for: "generate a reverse shell", "create a payload for", "encode this payload", "bypass AV", "craft a dropper", "listener setup", or any payload engineering task during an authorized engagement. Expert tools: msfvenom (Metasploit payloads), custom Python/Bash generators. CRITICAL: All payloads are for authorized testing only. Operator confirms target and scope before any payload is deployed.
Quick reference cheatsheet for penetration testing commands, techniques, and one-liners organized by phase and tool. Use this skill whenever the user asks for a cheatsheet, quick reference, one-liner, command syntax, "how do I use nmap/sqlmap/hashcat", "give me the command for", pentesting shortcuts, reverse shell one-liners, nmap flags, sqlmap syntax, hashcat modes, hydra syntax, ffuf usage, nuclei commands, or any request for a quick pentest command reference. Also trigger for: "remind me how to", "what's the flag for", "cheatsheet for", "quick reference", or when a user needs a specific command during an active engagement without wanting a full skill execution. This is a REFERENCE skill — it provides commands, not execution.
Post-exploitation activities including privilege escalation, lateral movement, persistence establishment, credential harvesting, and internal network enumeration for penetration testing engagements. Use this skill whenever the user mentions post-exploitation, privesc, privilege escalation, lateral movement, pivoting, credential dumping, hash extraction, internal recon, persistence, maintaining access, domain enumeration, Active Directory attacks, pass-the-hash, Kerberoasting, token impersonation, data exfiltration proof, or any activity that occurs AFTER initial access has been gained. Also trigger for: linpeas, winpeas, bloodhound, mimikatz, impacket, crackmapexec, evil-winrm, kerbrute, responder, meterpreter post modules, local enumeration, SUID binaries, kernel exploits, or "we have a shell, now what". This is phase four — trigger after exploit-dev confirms access, or when the operator already has a session on the target system. CRITICAL: Every action requires operator approval. Lateral movement to new hos
Passive and active reconnaissance, open-source intelligence gathering, subdomain enumeration, DNS analysis, and attack surface mapping for penetration testing engagements. Use this skill whenever the user mentions recon, reconnaissance, OSINT, subdomain enumeration, attack surface mapping, target profiling, DNS enumeration, email harvesting, domain intelligence, footprinting, information gathering, or "what can we find about this target". Also trigger for: theHarvester, subfinder, amass, spiderfoot, whois lookup, Shodan recon, passive recon, active recon, external recon, scope discovery, asset discovery, technology fingerprinting, whatweb, or any request to enumerate or profile a target before vulnerability scanning begins. This is the first phase of any pentest engagement — always trigger it when a new target or engagement scope is introduced.
Generate professional penetration testing and red team engagement reports from structured findings data. Use this skill whenever the user mentions pentest report, red team report, security assessment report, vulnerability report, executive summary for pentest, technical findings report, remediation report, compliance report, security audit deliverable, engagement report, final deliverable, or "write up the findings". Also trigger for: report template, finding write-up, risk matrix, CVSS summary table, attack narrative, attack chain documentation, remediation roadmap, re-test recommendations, or any request to produce a written deliverable from security testing data. This is the final phase of a pentest engagement — trigger after post-exploit completes, or standalone when the operator has findings data and needs a formatted report. Can produce Word (.docx), PDF, Markdown, or HTML report formats.
Runtime scope enforcement and legal authorization validation for penetration testing engagements. Use this skill BEFORE any active security tool execution. Trigger whenever: a new target is introduced, engagement scope is defined, rules of engagement are discussed, authorization needs checking, scope boundaries need validation, an IP or domain needs checking against allowed ranges, "is this in scope", "can I scan this", "check scope", "rules of engagement", "RoE", "scope validation", "authorization check", "legal check", "engagement boundaries", or any time a security tool is about to touch a target. This skill is the mandatory gate — no recon, scanning, exploitation, or post-exploitation should proceed without scope-guard confirming authorization. Also trigger for: CIDR range validation, domain wildcard scope, time window enforcement, excluded host checking, or "add to scope" / "remove from scope".
Threat intelligence gathering, CVE enrichment, indicator of compromise (IOC) analysis, and attack surface intelligence for security engagements. Use this skill whenever the user mentions threat intelligence, threat intel, CVE lookup, CVE enrichment, EPSS score, KEV list, CISA KEV, exploit prediction, IOC analysis, indicator of compromise, threat actor profiling, malware intelligence, MITRE ATT&CK mapping, VirusTotal lookup, Shodan intel, attack surface monitoring, vulnerability intelligence, or "what's known about this CVE". Also trigger for: NVD lookup, ExploitDB search, Shodan CVE query, CVSS analysis, vulnerability prioritization, threat landscape assessment, "is there an exploit for this", "how critical is this CVE", "what's the EPSS score", or any request to enrich security findings with external intelligence. Expert sources: Shodan CVEDB (MCP), NVD/NIST, ExploitDB (searchsploit), CISA KEV, EPSS, MITRE ATT&CK, VirusTotal (MCP available).
Sanitize and validate tool output before feeding it back to AI models to prevent prompt injection attacks from scan results, captured data, and service banners. Use this skill whenever security tool output is being processed by Claude or any LLM, when scan results contain user-controlled content (banners, HTTP responses, DNS TXT records), or when building the AI-driven pentest pipeline. Also trigger for: prompt injection protection, output sanitization, banner poisoning defense, LLM safety for tool output, "clean this output", or when integrating any external tool output into the Claude context window. This is a DEFENSIVE skill — it protects the Kali Agent from being manipulated by malicious content in scan targets.
Vulnerability scanning, CVE analysis, exploit mapping, and finding triage for penetration testing engagements. Use this skill whenever the user mentions vulnerability scanning, vuln scan, CVE lookup, Nuclei scan, Nikto scan, web application testing, SQL injection testing, XSS testing, security assessment, OWASP testing, vulnerability assessment, security audit, finding triage, CVE analysis, CVSS scoring, exploit availability check, or any request to identify vulnerabilities in a target system or application. Also trigger for: sqlmap, wpscan, nikto, nuclei, nessus, openvas, ffuf, directory brute force for vulns, CMS vulnerability scanning, API security testing, SSL/TLS analysis, or "scan this for vulnerabilities". This is the second phase of a pentest — trigger after recon-osint completes, or standalone when the user already knows what to scan.
Web application security testing following OWASP methodology, including injection testing, authentication bypass, XSS, CSRF, SSRF, IDOR, file upload attacks, API security testing, and web application firewalling. Use this skill whenever the user mentions web app testing, OWASP top 10, SQL injection, XSS, cross-site scripting, CSRF, SSRF, IDOR, insecure deserialization, file upload vulnerability, API security, JWT testing, session management testing, authentication bypass, authorization testing, Burp Suite, ZAP, OWASP testing guide, web app pentest, application security assessment, or any web-focused security testing task. Also trigger for: ffuf, gobuster, wfuzz, sqlmap, XSStrike, commix, directory brute force, parameter fuzzing, web fuzzing, cookie testing, header injection, HTTP verb tampering, CORS misconfiguration, clickjacking, content security policy, or "test this web application for vulnerabilities". Expert tools: sqlmap (SQLi), Burp Suite (intercepting proxy), ZAP (open-source proxy), ffuf (web fuzzer
Wireless network security testing including WiFi enumeration, WPA/WPA2/WPA3 cracking, rogue AP detection, Bluetooth reconnaissance, and RF analysis for authorized security engagements. Use this skill whenever the user mentions wireless testing, WiFi security, WiFi cracking, WPA cracking, aircrack-ng, airmon-ng, aireplay-ng, airodump-ng, wifite, reaver, WPS attack, pixie dust, evil twin, rogue access point, deauthentication, handshake capture, PMKID capture, Bluetooth scanning, BLE security, wireless pentest, or any wireless-focused security testing task. CRITICAL: Wireless testing requires physical proximity and appropriate hardware. The AI generates commands — the OPERATOR executes them in person. All wireless testing requires explicit written authorization.