Skip to content

Marketplace

Everything your AI needs, in one place.

Ready-made agents, skills, personas, prompts, templates and tools. Each one is checked before it goes live, works with any model, and installs in a click. Rate what you use so the best rises to the top.

146.7K
listings
1
installs
0
reviews
40.4K
publishers
49 results
Skill

hunting-for-ntlm-relay-attacks

Detects NTLM relay attacks (MITRE T1557.001) by analyzing Windows Event ID 4624 logon type 3 with NTLMSSP authentication, flagging IP-to-hostname mismatches, Responder/LLMNR poisoning signatures, SMB

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-t1098-account-manipulation

Hunts for MITRE ATT&CK T1098 account manipulation - shadow admin creation, SID history injection, group membership changes, and credential modifications - by analyzing Windows Security Event Log IDs 4

by mukul975skills.sh
Not rated yet
Free
Skill

mapping-attack-paths-with-bloodhound-ce

Collect Active Directory data with SharpHound and Entra ID data with AzureHound, ingest into BloodHound Community Edition, and analyze on-prem, cloud, and hybrid attack paths using built-in queries an

by mukul975skills.sh
Not rated yet
Free
Skill

moving-laterally-with-netexec

Use NetExec (nxc) to validate credentials, enumerate SMB shares/users/policy, password-spray safely across lockout thresholds, execute commands, and dump SAM/LSA/NTDS credentials across SMB, WinRM, LD

by mukul975skills.sh
Not rated yet
Free
Skill

performing-active-directory-bloodhound-analysis

Use BloodHound and SharpHound (or AzureHound) to enumerate Active Directory relationships and graph attack paths from a compromised user to Domain Admin. Use when performing AD red-team reconnaissance

by mukul975skills.sh
Not rated yet
Free
Skill

performing-active-directory-compromise-investigation

Investigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateral movemen

by mukul975skills.sh
Not rated yet
Free
Skill

performing-active-directory-forest-trust-attack

Enumerate and audit Active Directory forest trust relationships using Impacket for SID filtering analysis, trust key extraction, cross-forest SID history abuse detection, and inter-realm Kerberos tick

by mukul975skills.sh
Not rated yet
Free
Skill

performing-active-directory-penetration-test

Conduct a focused Active Directory penetration test using BloodHound, Impacket, Certipy, Rubeus, and NetExec to enumerate domain objects, discover attack paths, exploit Kerberos weaknesses, escalate p

by mukul975skills.sh
Not rated yet
Free
Skill

performing-active-directory-vulnerability-assessment

Assess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations, privilege escalation paths, and attack vectors.

by mukul975skills.sh
Not rated yet
Free
Skill

performing-kerberoasting-attack

Perform Kerberoasting, a post-exploitation technique that enumerates Active Directory service accounts with Service Principal Names (SPNs), requests their Kerberos TGS tickets, and cracks the NTLM-enc

by mukul975skills.sh
Not rated yet
Free
Skill

relaying-ntlm-for-adcs-esc8

Uses Impacket's ntlmrelayx.py with a coercion tool (PetitPotam, Coercer, printerbug) to relay NTLM authentication from a coerced domain controller into the AD CS HTTP web-enrollment endpoint (ESC8), o

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-t1098-account-manipulation

Hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group membership changes, and credential modifications using Windows Security Event Logs.

by autohandaiGitHub
Not rated yet
Free
Skill

detecting-credential-dumping-techniques

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules

by luokai0GitHub
Not rated yet
Free
Skill

detecting-credential-dumping-techniques

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules

by kyssta-exeGitHub
Not rated yet
Free
Skill

detecting-credential-dumping-techniques

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft (e.g. via Mimikatz) using Sysmon Event ID 10 process-access logging, Windows Security logs, and SIEM correlation rules. Use

by gabrielmoreiraGitHub
Not rated yet
Free
Skill

detecting-dcsync-attack-in-active-directory

Detect DCSync attacks (MITRE T1003.006) where adversaries abuse Active Directory replication privileges to extract password hashes, by auditing Event ID 4662 for the DS-Replication-Get-Changes GUIDs a

by rivaldiekaptrrrGitHub
Not rated yet
Free
Skill

detecting-dcsync-attack-in-active-directory

Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes by monitoring for non-domain-controller accounts requesting directory replication via D

by andycungkrinx91GitHub
Not rated yet
Free
Skill

kerberoasting-active-directory

Execute a Kerberoasting attack to extract Service Principal Name (SPN) ticket hashes from Active Directory and crack them offline. This allows an attacker with any valid domain credentials to escalate

by ShulkwiSECGitHub
Not rated yet
Free
Skill

conducting-domain-persistence-with-dcsync

Perform DCSync attacks to replicate Active Directory credentials and establish domain persistence by extracting KRBTGT, Domain Admin, and service account hashes for Golden Ticket creation.

by kaviyarasu2007GitHub
Not rated yet
Free
Skill

conducting-domain-persistence-with-dcsync

Perform DCSync attacks to replicate Active Directory credentials and establish domain persistence by extracting KRBTGT, Domain Admin, and service account hashes for Golden Ticket creation.

by RUSHYOPGitHub
Not rated yet
Free
Skill

conducting-domain-persistence-with-dcsync

Perform DCSync attacks to replicate Active Directory credentials and establish domain persistence by extracting KRBTGT, Domain Admin, and service account hashes for Golden Ticket creation.

by Mahesh-07-404GitHub
Not rated yet
Free
Skill

performing-active-directory-vulnerability-assessment

Assess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations, privilege escalation paths, and attack vectors.

by HenriqueMC17GitHub
Not rated yet
Free
Skill

ad-honeytoken-detect

Deploys deception-based honeytokens in Active Directory including fake privileged accounts with AdminCount=1, fake SPNs for Kerberoasting detection (honeyroasting), decoy GPOs with cpassword traps, an

by DCx7C5GitHub
Not rated yet
Free
Skill

auditing-azure-active-directory-configuration

Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest use

by micsappGitHub
Not rated yet
Free
1

Find

Search or browse by kind. Every card shows who made it, how many people installed it and what they think.

2

Install

One click. You get a manifest the router understands, plus copy-paste snippets for the CLI, Python and YAML.

3

Rate and publish

Leave a star rating after you have used it. Made something useful? Publish it - free listings go live immediately.

Prefer the terminal? osr stack apply registry://starter installs the starter template.