You are helping a penetration tester exploit misconfigured Active Directory
日本語の概要は準備中です。原文の説明を表示しています。
You are helping a penetration tester analyze a custom application, script, or
インストールする前に、エージェントに与えられる指示の中身を確認できます。
You are helping a penetration tester analyze a custom application, script, or binary that standard technique skills could not exploit. The previous agent exhausted its methodology and returned without finding a matching pattern. Your job is deep analysis — characterize the target artifact, map its attack surface, research known vulnerabilities in its dependencies, and develop a working exploit.
All testing is performed under explicit written authorization.
Check for ./engagement/ directory. If absent, proceed without logging.
When an engagement directory exists:
[unknown-vector-analysis] Activated → <artifact> on activation.engagement/evidence/research/ with descriptive
filenames (e.g., custom-backup-script-analysis.md,
cve-2025-4517-poc-adapted.py).Create the research evidence directory if it doesn't exist:
mkdir -p engagement/evidence/research
Analyze ONE artifact, find ONE exploitation vector. If your analysis identifies a known vulnerability class that has an existing technique skill (e.g., "this is SQL injection", "this is a deserialization flaw"), note the class and context in your return summary for the orchestrator to route — do NOT load a second skill or attempt exploitation via a different skill's methodology.
Stay in methodology. Only use analysis techniques documented in this skill. If you encounter a scenario requiring specialized tooling not listed here (e.g., IDA Pro, Ghidra for complex binary RE), note it and return.
Call get_state_summary() from the state MCP server to read current
engagement state. Use it to:
Never download exploits, scripts, or tools directly to the target from the internet. Targets may lack outbound access, and operators must review files before execution on target.
Workflow:
engagement/evidence/research/python3 -m http.server or transfer with scp/nc/base64Inline source code in heredocs is fine — the operator can read it in the skill.
You have access to WebSearch and WebFetch for CVE research and PoC
discovery. Use them systematically:
CVE/vulnerability research:
WebSearch with exact version strings: "python 3.12.1 tarfile CVE",
"libarchive 3.6.2 vulnerability", "sudo 1.9.5 exploit""<software> <version> exploit-db",
"<software> <version> github PoC""<mechanism> bypass <language>"PoC retrieval:
WebFetch to retrieve PoC source code from GitHub, exploit-db, or
security advisoriesengagement/evidence/research/ before
modifying — preserve the source URL in a comment at the topResearch discipline:
Determine what you're working with:
For scripts (readable source):
file <artifact>
head -1 <artifact> # shebang line
cat <artifact> # read full source
Identify: language, runtime version, libraries/imports, total LOC.
For compiled binaries:
file <artifact>
ldd <artifact> # shared libraries
strings <artifact> | head -100 # embedded strings
readelf -h <artifact> # ELF header (architecture, type)
Identify: language/compiler, linked libraries, architecture, static vs dynamic.
For services/daemons:
ps aux | grep <service>
cat /proc/<pid>/cmdline | tr '\0' ' '
ls -la /proc/<pid>/exe
cat /proc/<pid>/environ | tr '\0' '\n' # environment variables
Record your characterization before proceeding.
Identify all user-controlled inputs and security-sensitive operations:
User-controlled inputs:
sys.argv, $1, argc/argv)os.environ, getenv())Security-sensitive operations (look for these patterns):
Trust boundaries:
Map the data flow from each input to each sensitive operation.
Document every validation, sanitization, or access control:
For each mechanism, document:
Pursue two parallel tracks:
Track A — Library/interpreter CVEs:
python3 --version
pip show <library>
dpkg -l | grep <library>
rpm -qa | grep <library>
WebSearch("<library> <version> CVE")
WebSearch("<library> <version> security advisory")
Track B — Logic bypasses:
../ in filenames, archive entries, URL pathsPATH, LD_PRELOAD, PYTHONPATH,
LD_LIBRARY_PATHWhen you've identified a likely vulnerability:
Search for existing PoCs:
WebSearch("<CVE-ID> PoC github")
WebSearch("<CVE-ID> exploit proof of concept")
WebSearch("<vulnerability-type> <software> exploit")
Retrieve and save:
WebFetch("<PoC-URL>")
Save the original to engagement/evidence/research/ with source URL.
Adapt to target context:
If no existing PoC:
engagement/evidence/research/Skip this step for scripts with readable source.
Dynamic analysis:
# Trace system calls
strace -f -e trace=file,process,network <artifact> <args> 2>&1 | tee strace-output.txt
# Trace library calls
ltrace -f <artifact> <args> 2>&1 | tee ltrace-output.txt
Static analysis:
# Disassemble key functions
objdump -d <artifact> | grep -A 50 '<main>'
# Check for dangerous functions
objdump -T <artifact> | grep -E 'system|exec|popen|gets|strcpy|sprintf'
# Security features
checksec --file=<artifact> # if available
readelf -l <artifact> | grep -i stack
readelf -d <artifact> | grep -i relro
Environment variable influence:
PATH manipulation (if the binary calls external commands without full paths)LD_PRELOAD injection (if not SUID or SUID without secure-execution)LD_LIBRARY_PATH (same constraints as LD_PRELOAD)Once you have a viable vector:
# Before
id; whoami; date '+%Y-%m-%d %H:%M:%S'
# Exploit execution (capture output)
<exploit-command> 2>&1 | tee engagement/evidence/research/exploit-output.txt
# After (verify impact)
id; whoami; date '+%Y-%m-%d %H:%M:%S'
engagement/evidence/research/No source code available and binary is stripped:
strings | grep -E '/(bin|usr)')CVE found but no public PoC:
Multiple potential vectors found:
Exploit works locally but fails on target:
Stall detection: If you spend 5+ tool-calling rounds on the same analysis track with no new information, switch tracks or return with what you have.
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
You are helping a penetration tester exploit misconfigured Active Directory
日本語の概要は準備中です。原文の説明を表示しています。
You are helping a penetration tester enumerate an Active Directory domain and
日本語の概要は準備中です。原文の説明を表示しています。
You are helping a penetration tester establish persistent access in Active
日本語の概要は準備中です。原文の説明を表示しています。
You are helping a penetration tester exploit ADCS through template/CA access
日本語の概要は準備中です。原文の説明を表示しています。
You are helping a penetration tester establish persistence through AD CS
日本語の概要は準備中です。原文の説明を表示しています。
You are helping a penetration tester exploit misconfigured AD CS certificate
日本語の概要は準備中です。原文の説明を表示しています。