Skip to content

Marketplace

Everything your AI needs, in one place.

Ready-made agents, skills, personas, prompts, templates and tools. Each one is checked before it goes live, works with any model, and installs in a click. Rate what you use so the best rises to the top.

146.7K
listings
1
installs
0
reviews
40.4K
publishers
61 results
Skill

exploiting-constrained-delegation-abuse

Exploits Kerberos Constrained Delegation misconfigurations in Active Directory using Impacket's findDelegation.py and getST.py (or Rubeus/Kekeo on Windows) to abuse S4U2Self and S4U2Proxy and imperson

by mukul975skills.sh
Not rated yet
Free
Skill

exploiting-ms17-010-eternalblue-vulnerability

Detects and exploits MS17-010 (EternalBlue), a critical remote code execution flaw in Microsoft's SMBv1 implementation, using Nmap's ms-17-010 NSE script for detection and Metasploit's ms17_010_eterna

by mukul975skills.sh
Not rated yet
Free
Skill

exploiting-nopac-cve-2021-42278-42287

Exploits the noPac Active Directory privilege-escalation chain (CVE-2021-42278 sAMAccountName spoofing plus CVE-2021-42287 KDC PAC confusion) using Impacket and secretsdump.py to escalate from a stand

by mukul975skills.sh
Not rated yet
Free
Skill

operating-havoc-c2

Deploy a Havoc C2 team server with Yaotl malleable profiles, generate evasive Demon agents using indirect syscalls and sleep obfuscation, and run post-exploitation and pivoting operations. Use during

by mukul975skills.sh
Not rated yet
Free
Skill

operating-sliver-c2

Stand up a Sliver C2 server and mTLS listeners, generate cross-platform implants and beacons, and run post-exploitation, pivoting, and BOF/.NET tooling via the Armory for adversary emulation. Use duri

by mukul975skills.sh
Not rated yet
Free
Skill

performing-active-directory-forest-trust-attack

Enumerate and audit Active Directory forest trust relationships using Impacket for SID filtering analysis, trust key extraction, cross-forest SID history abuse detection, and inter-realm Kerberos tick

by mukul975skills.sh
Not rated yet
Free
Skill

performing-credential-access-with-lazagne

Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red team

by mukul975skills.sh
Not rated yet
Free
Skill

performing-initial-access-with-evilginx3

Perform authorized initial access using EvilGinx3 adversary-in-the-middle phishing framework to capture session tokens and bypass multi-factor authentication during red team engagements.

by mukul975skills.sh
Not rated yet
Free
Skill

performing-kerberoasting-attack

Perform Kerberoasting, a post-exploitation technique that enumerates Active Directory service accounts with Service Principal Names (SPNs), requests their Kerberos TGS tickets, and cracks the NTLM-enc

by mukul975skills.sh
Not rated yet
Free
Skill

performing-lateral-movement-with-wmiexec

Perform lateral movement across Windows networks using WMI-based remote execution techniques including Impacket wmiexec.py, CrackMapExec, and native WMI commands for stealthy post-exploitation during

by mukul975skills.sh
Not rated yet
Free
Skill

performing-open-source-intelligence-gathering

Open Source Intelligence (OSINT) gathering is the first active phase of a red team engagement, where operators collect publicly available information about the target organization to identify attack s

by mukul975skills.sh
Not rated yet
Free
Skill

performing-physical-intrusion-assessment

Conduct authorized physical penetration testing against facilities, server rooms, and restricted areas using tailgating, RFID badge cloning, lock bypassing, rogue network device deployment, and securi

by mukul975skills.sh
Not rated yet
Free
Skill

performing-privilege-escalation-on-linux

Guides manual enumeration and automated tooling to escalate from a low-privilege Linux user to root by exploiting misconfigurations, vulnerable services, kernel exploits, and weak permissions, mapped

by mukul975skills.sh
Not rated yet
Free
Skill

performing-purple-team-exercise

Performs purple team exercises by coordinating red team adversary emulation with blue team detection validation using MITRE ATT&CK-mapped attack scenarios, real-time detection testing, and collaborati

by mukul975skills.sh
Not rated yet
Free
Skill

performing-red-team-with-covenant

Conducts red team operations using the Covenant C2 framework for authorized adversary simulation, covering listener setup, grunt deployment, task execution, and lateral movement tracking. Use when sta

by mukul975skills.sh
Not rated yet
Free
Skill

post-exploiting-microsoft-graph-with-graphrunner

Runs GraphRunner, a PowerShell post-exploitation toolset built on the Microsoft Graph API, to perform tenant recon, establish persistence (OAuth app injection, inbox rules), escalate privilege via gro

by mukul975skills.sh
Not rated yet
Free
Skill

relaying-ntlm-for-adcs-esc8

Uses Impacket's ntlmrelayx.py with a coercion tool (PetitPotam, Coercer, printerbug) to relay NTLM authentication from a coerced domain controller into the AD CS HTTP web-enrollment endpoint (ESC8), o

by mukul975skills.sh
Not rated yet
Free
Skill

pentest-metasploit

Penetration testing framework for exploit development, vulnerability validation, and authorized security assessments using Metasploit Framework. Use when: (1) Validating vulnerabilities in authorized

by aiskillstoreskills.sh
Not rated yet
Free
Skill

social-engineer-toolkit

Run authorized red team social engineering assessments with the Social Engineer Toolkit (SET). Use when a user asks to simulate a phishing campaign for security awareness training, clone a login page

by terminalskillsskills.sh
Not rated yet
Free
Skill

bdistill-behavioral-xray

X-ray any AI model's behavioral patterns — refusal boundaries, hallucination tendencies, reasoning style, formatting defaults. No API key needed.

by wegonbeok45GitHub
Not rated yet
Free
Skill

godmod3

Use G0DM0D3 multi-model racing and prompt engineering inside Hermes Agent.

by crnisamurajGitHub
Not rated yet
Free
Skill

conducting-pass-the-ticket-attack

Pass-the-Ticket (PtT) is a lateral movement technique that uses stolen Kerberos tickets (TGT or TGS) to authenticate to services without knowing the user's password. By extracting Kerberos tickets fro

by momo0410GitHub
Not rated yet
Free
Skill

Security Testing

Techniques and tools for testing application and infrastructure security including penetration testing, fuzzing, and vulnerability assessment

by NeuralBlitzGitHub
Not rated yet
Free
Skill

executing-red-team-engagement-planning

Red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE), threat model selection, and operational timelines before any offensive testing begins.

by Yenn503GitHub
Not rated yet
Free
1

Find

Search or browse by kind. Every card shows who made it, how many people installed it and what they think.

2

Install

One click. You get a manifest the router understands, plus copy-paste snippets for the CLI, Python and YAML.

3

Rate and publish

Leave a star rating after you have used it. Made something useful? Publish it - free listings go live immediately.

Prefer the terminal? osr stack apply registry://starter installs the starter template.