本文へ移動
cccskills
無料GitHub で公開

metasploit

Drive msfconsole across the workflow - DB-backed recon (db_nmap, auxiliary scanners), version->exploit search/check/run, multi/handler reverse shells (meterpreter-first, plain shell_reverse_tcp backup for Windows/EDR), sessions + local_exploit_suggester + post modules, and autoroute/portfwd/socks pivoting. Points to the metasploit cheatsheet for syntax. Use for "metasploit", "msfconsole", "msfvenom", "meterpreter", "multi/handler", or driving an exploit/reverse-shell through msf.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md4.0 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Metasploit: framework driver

Drive msfconsole for recon, exploit, reverse shells, and post-ex. Syntax lives in [[metasploit]]; this skill is the workflow that strings it together.

Pre-attack wiki query (MANDATORY)

Before firing any exploit module, query the fingerprinted tech/CVE: read [[metasploit]] directly for syntax, then Skill(arsenal) for the matching module/payload/technique. Never fire a module from memory when a targeted lookup would confirm the right one/target index.

Setup / DB

msfconsole -q in a named tmux tab, never a blind background job, the operator needs to see sessions land live. workspace -a <eng> scopes loot to the engagement, db_status confirms the Postgres backend is up before anything else. Cheatsheet: Setup + Database sections.

Recon via msf

db_nmap writes straight to hosts/services; layer auxiliary/scanner/* (smb/http/ssh version + vuln checks) on top for anything plain nmap scripts miss. This complements the ctf-box Phase-1 basics, it does not replace them, run both.

Search / select / verify

search <app> <ver> or search cve:<id>, use, info to read the module's CVE refs and target list, check before run/exploit whenever the module supports it, a non-destructive exploitability test beats a blind fire. Cheatsheet: Search and Selection + Options and Running.

Reverse shells

multi/handler catches. Payload choice: meterpreter first (linux/x64/meterpreter/reverse_tcp / windows/x64/meterpreter/reverse_tcp), fall back to plain shell_reverse_tcp when meterpreter is blocked or unstable, routine on hardened Windows/EDR. Delivery via msfvenom (ELF/EXE/ASPX/PHP, cheatsheet's MSFVenom section has every format). Egress-test the LPORT (80/443/53 before 4444). Background the handler correctly: set ExitOnSession false; run -j so it keeps catching new sessions. On the VM, scripts/vm-handler.sh <eng> <lhost> [payload] automates the LPORT choice: it reads the VM's listeners and picks the first FREE egress-friendly port (80/443/53/8000/8080), so the handler never fails to bind on a taken port nor silently picks a filtered high port; it launches in the engagement's msf tmux window and prints the LPORT to build the payload with.

Sessions / post-ex

sessions -i to interact, run post/multi/recon/local_exploit_suggester is the privesc reflex on every fresh session, then targeted post/* modules, getsystem, and post/multi/manage/shell_to_meterpreter to upgrade a plain shell. Cheatsheet: Sessions and Jobs

  • Post-Exploitation Modules.

Pivoting

autoroute/portfwd/socks through a session to reach internal-only ports before hand-rolling SSH -L. Full syntax and proxychains setup: [[pivoting]].

Verify target (false-root)

Before trusting any shell or privesc claim: getuid + sysinfo/hostname must match the actual target. A uid=0 that doesn't match the target is the false-root trap, the session died back to the attacker box. Same guardrail Skill(delegate) enforces on manual exploit runs.

Interlock + anti-drift

The fiddly msfvenom-compile -> handler-catch -> escalation-run sequence is a prime Skill(delegate) hand-off: fully specified, mechanical, cheap-model-shaped. DRIVE msf for every load-bearing exploit/shell request so the operator watches sessions land; don't abandon msf for raw scripts once a foothold lands.

Client-data boundary

Sessions, loot, and creds stay in the msf DB workspace + targets/<eng>/; never paste a real host/cred/hashdump into wiki/ or session/*.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

arsenal

無料

Wiki-first "what do I use" lookup - pick the automated TOOL (wiki/tools/), then the PAYLOAD/technique (wiki/payloads/ + wiki/cheatsheets/), for a surface/service/vuln-class BEFORE hand-rolling or working from memory. Use for "tool for <service>", "automated tools for web/<service>", "what should I run on <surface>", "which tool for <X>", "payloads for <X>", "payload arsenal", "cheatsheet for <X>", "how do I exploit <tech/class>", "exploit/attack chain for <X>", "arsenal", any SSRF/XSS/SQLi/SSTI/LFI/JWT/XXE/IDOR/NoSQL/deserialization/CSRF/CORS/CRLF/GraphQL/smuggling/web-cache/OAuth/SAML/MFA/crypto/LDAP/XPath/WebAuthn/file-upload/IMDS/prompt-injection/Modbus ask, plus "privesc arsenal", "CVE arsenal", "default creds", "nuclei templates", "sqlmap/hydra/nmap/bloodhound", "password attacks".

日本語の概要は準備中です。原文の説明を表示しています。

Encod3d-Sec/TORCH3302026年9月1日 更新

Autonomous bug-bounty campaign driver. Runs a full programme end to end with no operator approvals - the deterministic driver (scripts/campaign.py) owns pass state, generates the killchain board from recon, and prints the exact next action (including which Skill and tool to run) every turn. Use when starting or resuming a bug-bounty engagement, "run the bb workflow", "hunt this program", "9-pass campaign", or when handed a *.scope wildcard to test for TIER1 findings. Single agent, refuter-verified, wiki-first, tool-first.

日本語の概要は準備中です。原文の説明を表示しています。

Encod3d-Sec/TORCH3302026年9月1日 更新

Health check for the bb/pt/ctf workflow driver subsystem - verifies everything is in place so every machine runs the same. Checks vault-content consistency (scripts present, JSON valid, routing wired, all 69 tool pages carry phase:, the tool index resolves, the hook edits are in place) AND per-machine wiring (the three workflow skills symlinked, hooks registered, imports work), then runs a live init->board->next smoke test. Use when setting up the workflow on a new machine, after a vault sync, when the driver misbehaves, or on "bb-health", "campaign health", "is the workflow set up", "check hooks and scripts", "why is the board not working".

日本語の概要は準備中です。原文の説明を表示しています。

Encod3d-Sec/TORCH3302026年9月1日 更新

Bring up a REAL, visible, interactive chromium on the Kali VM that the operator logs into (Smart-ID / Mobile-ID / any manual auth or MFA/CAPTCHA), while the agent drives and observes it live through the chrome-devtools MCP (navigate, DOM snapshot, network capture, screenshots, console, evaluate). Use whenever a target needs a MANUAL login the agent cannot complete headlessly, when you need to capture an authenticated session / the real API calls a page makes, or to confirm/screenshot a DOM-XSS. Triggers - "open a browser", "log in manually", "smart-id / mobile-id / national id login", "mfa / 2fa login", "solve the captcha", "drive the browser", "capture the authenticated session / network".

日本語の概要は準備中です。原文の説明を表示しています。

Encod3d-Sec/TORCH3302026年9月1日 更新

OFFLINE FALLBACK for the claude-md-management plugin - prefer that plugin when it is installed. Audit and improve CLAUDE.md files - scan for CLAUDE.md files, evaluate quality against templates, output a report, then make targeted updates. Invoke explicitly (/claude-md-improver) when the plugin is unavailable.

日本語の概要は準備中です。原文の説明を表示しています。

Encod3d-Sec/TORCH3302026年9月1日 更新

coverage

無料

Show per-asset vuln-class coverage gaps for the active engagement so nothing in scope is skipped. Use when asked "coverage", "what haven't we tested", "test gaps", "are we thorough", or before calling an engagement done.

日本語の概要は準備中です。原文の説明を表示しています。

Encod3d-Sec/TORCH3302026年9月1日 更新

Encod3d-Sec のスキルをすべて見る

このスキルの問題を報告する