blacklanternsecurity/red-run

DirSkills catalogs 25 skills from this repository, across 4 categories: AI Engineering, Automation, DevOps, Quality.

266 stars37 forksView on GitHub
🪪
1h ago

AD Persistence

AD Persistence documents post-compromise techniques for maintaining access in Active Directory after domain admin access. It covers methods like DCShadow, Golden SAML, SID history, certificate persistence, and security descriptor backdoors.
Automation
26637
🪪
1h ago

ADCS Persistence

ADCS Persistence establishes long-lived access through AD CS certificate abuse and weak certificate mapping. It is used for Golden Certificates, ESC9/10, altSecIdentities, certificate theft, and related persistence techniques.
AI Engineering
26637
🪪
1h ago

ADCS Template Abuse

ADCS Template Abuse exploits misconfigured AD CS certificate templates and CA flags to impersonate domain users with certificates. Use it during authorized assessments to enumerate ESC1, ESC2, ESC3, and ESC6 paths.
AI Engineering
26637
🛡️
1h ago

AV EDR Evasion

AV EDR Evasion covers payload compilation and runtime bypass methods when antivirus or endpoint protection blocks execution. Use it to build alternate DLL, EXE, script, AMSI, or ETW-based payloads for an authorized engagement.
AI Engineering
26637
🔐
1h ago

Acl Abuse

Acl Abuse exploits misconfigured Active Directory ACLs for privilege escalation. It is used to abuse rights like GenericAll, WriteDACL, shadow credentials, SPN manipulation, and password reset paths.
Automation
26637
🗺️
1h ago

Ad Discovery

Ad Discovery enumerates Active Directory domains to map hosts, signing settings, and attack paths during authorized testing. It supports unauthenticated and credentialed reconnaissance and records findings for orchestration.
Automation
26637
🛡️
1h ago

Adcs Access And Relay

Adcs Access And Relay covers ADCS template and CA ACL abuse plus NTLM relay to enrollment endpoints. Use it when enumerating or exploiting ESC4, ESC5, ESC7, ESC8, or ESC11 paths.
AI Engineering
26637
🔐
1h ago

Authentication Coercion And Relay

Authentication Coercion And Relay forces systems to authenticate to attacker-controlled listeners and relays those logons for privilege escalation or lateral movement. Use it when testing NTLM, Kerberos, or name-resolution poisoning paths such as PetitPotam, Responder, ntlmrelayx, or krbrelayx.
AI Engineering
26637
🐳
1h ago

Container Escapes

Container Escapes helps enumerate container and Kubernetes environments, then pursue breakout paths such as exposed Docker sockets, privileged mounts, or cluster access. Use it during authorized penetration tests of containerized hosts and pods.
DevOps
26637
🔐
1h ago

Credential Dumping

Credential Dumping extracts secrets from Active Directory and related stores such as DCSync, NTDS.dit, SAM, LAPS, gMSA, ADSync, DSRM, and EFS-encrypted files. Use it during authorized penetration tests when you need hashes, passwords, or directory recovery credentials.
AI Engineering
26637
🗄️
1h ago

Database Enumeration

Database Enumeration checks common database services for default credentials, unauthenticated access, and command execution paths. Use it after network recon finds MSSQL, MySQL, PostgreSQL, Oracle, MongoDB, or Redis ports.
Quality
26637
🛠️
1h ago

GPO Abuse

GPO Abuse helps test writable Group Policy Objects for code execution, privilege escalation, and lateral movement in Active Directory. It covers GPO enumeration, immediate tasks, logon script poisoning, registry changes, and GPP password extraction.
Automation
26637
🛰️
1h ago

Infrastructure Enumeration

Infrastructure Enumeration checks exposed DNS, SMTP, RPC/MSRPC, LDAP, NFS, SNMP, IPMI, TFTP, and HTTP/HTTPS services for common misconfigurations and information leaks. Use it after network recon identifies open infrastructure ports.
Automation
26637
🛡️
1h ago

Kerberos Delegation Exploitation

Kerberos Delegation Exploitation guides exploitation of Kerberos delegation misconfigurations in Active Directory for privilege escalation and lateral movement. It covers unconstrained delegation, constrained delegation, and RBCD workflows using Kerberos authentication.
AI Engineering
26637
🔑
1h ago

Kerberos Roasting

Kerberos Roasting extracts Kerberoastable TGS tickets and AS-REP hashes for offline password cracking. Use it during authorized Active Directory assessments when you have domain credentials or username lists.
Automation
26637
🎟️
1h ago

Kerberos Ticket Forging

Kerberos Ticket Forging for forging Golden, Silver, Diamond, Sapphire, and pass-the-ticket Kerberos tickets during authorized red team testing. Use it when you have domain or service key material and need Kerberos-based persistence or privilege escalation.
Automation
26637
🛰️
1h ago

Network Reconnaissance

Network Reconnaissance scans authorized targets to discover hosts, open ports, services, and OS fingerprints. Use it to build a port/service map and route deeper enumeration to the right follow-on skills.
Automation
26637
🔑
1h ago

Pass The Hash

Pass The Hash authenticates to Active Directory services with NTLM hashes, AES keys, or Kerberos tickets without cracking passwords. Use it for Pass-the-Hash, Over-Pass-the-Hash, Pass-the-Key, and Pass-the-Ticket during authorized lateral movement.
Automation
26637
🔐
1h ago

Password Spraying

Password Spraying performs lockout-safe credential spraying against authentication services like AD, SSH, web forms, and OWA. Use it when you have authorized usernames and need to test likely passwords without triggering account lockouts.
Automation
26637
🛡️
1h ago

Red Run

Red Run guides authorized penetration testing work within a defined technique scope. It helps track engagement state, evidence, and findings while staying within the documented methodology.
Quality
26637
🛡️
1h ago

Red Run CTF

Red Run CTF orchestrates multi-phase penetration test workflows with agent teams. It routes recon, assessment mapping, and vulnerability chaining tasks to specialist skills during an authorized engagement.
Automation
26637
🛡️
1h ago

Red Run Legacy

Red Run Legacy orchestrates a penetration test by routing reconnaissance and technique work to the right skills and agents under operator approval. Use it manually for legacy subagent-based workflows; it does not auto-trigger.
AI Engineering
26637
📝
1h ago

Retrospective

Retrospective analyzes a completed engagement’s state, timeline, and skill-routing decisions to produce an improvement report. Use it after an engagement to review outcomes, identify missed skills, and capture knowledge gaps.
Quality
26637
🛠️
1h ago

SCCM Exploitation

SCCM Exploitation enumerates Microsoft SCCM/MECM infrastructure and extracts credentials for lateral movement and escalation. Use it when you have authorized access to assess NAA secrets, relays, PXE boot flows, and SCCM deployments.
AI Engineering
26637
🔗
1h ago

Trust Attacks

Trust Attacks enumerates Active Directory trust relationships and uses them for cross-domain and cross-forest privilege escalation. Use it to assess trust settings, SID history, trust tickets, delegation, and PAM trust abuse.
Automation
26637