本文へ移動
cccskills
無料GitHub で公開

shell

Shell and session operations after an attack module already established command execution, a raw shell, webshell channel, container/runner shell, or remote session. This module does not own exploitation and should not pull SSH/WinRM/RDP authentication or vulnerability-to-shell chains out of Web/AD/Cloud/K8s/CI-CD/Service/Phishing. Use it to bootstrap a usable callback from existing command execution, stabilize Linux PTY, upgrade Windows sessions with ConPTY where applicable, manage listeners, recover fragile sessions, and exchange files for continued operations.

インストール方法を見る

含まれるファイル(7)

  • SKILL.md4.3 KB
  • references/file-transfer.md853 B
  • references/linux-pty.md609 B
  • references/listeners-recovery.md748 B
  • references/session-bootstrap.md1.0 KB
  • references/SOURCES.md400 B
  • references/windows-conpty.md912 B

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

/shell — Shell & Session Operations

新定位: 不负责“把漏洞变成 shell”。Attack 模块已经负责把自己选择的链做到 foothold。/shell 只处理已有 execution/shell/session 的质量与可操作性。


开局与收尾

开局第一件事:Read ./notes.md。没有则 python ~/.claude/skills/bin/notes.py init。只按已拿下/凭据继续。 走到哪条链,才 Read 一份 references/<file>.md。禁止开局全读、禁止凭记忆写 payload。 监听 / sudo / 输密码 / Permission denied:立刻停,说明等操作者做什么,等回报。不要假装已成功。 收尾:

  1. 追加 ./notes.md
  2. python ~/.claude/skills/bin/modules.py tail <本模块名> Read 备用:~/.claude/skills/shared/modules.yaml 禁止 ./modules.yaml 和 python ../bin/...
  3. 优先 default_next;never_default 不得当作默认(操作者点名除外)
  4. 名册外的名字不许建议
  5. 停。等操作者选 /模块 或 /clear /edr-bypass 半条链未完:打通后回本模块,不要 /clear。

0. 输入条件

至少满足一个:

single-command execution
raw reverse shell
bind shell
webshell command channel
container/runner shell
poor cmd/PowerShell channel
existing interactive remote session

如果你只有一个 Web/AD/Service/Cloud/K8s/CI-CD 漏洞候选,还没有执行能力,回原 Attack 模块继续,不要用 /shell 代替 exploit chain。


1. Session bootstrap

当原 Attack 模块已经证明 single-command execution,但当前 operator 明确选择 /shell 来改善会话时,可以从现有 execution primitive 建立 callback。

这不改变攻击链所有权:最终 foothold 仍属于原模块。

见 references/session-bootstrap.md。


2. Linux PTY

目标:

raw /bin/sh
→ PTY
→ Ctrl-C / job control
→ correct TERM/rows/cols
→ stable interactive shell

见 references/linux-pty.md。


3. Windows ConPTY / Session Upgrade

目标:把 poor cmd/PowerShell/stdin-stdout channel 变成可正常交互的 Windows session。优先使用系统自带 Pseudo Console 能力;ConPtyShell 是常见实现之一,但不是唯一答案。

见 references/windows-conpty.md。


4. Listener & Recovery

处理:

listener discipline
socket reconnect
TTY state corruption
Ctrl-C breakage
stale session
resume after network interruption

见 references/listeners-recovery.md。


5. File Exchange

用于foothold 日常工具/文件交换:

HTTP
SMB
SCP/SFTP when already available
base64/chunking
native PowerShell/curl/certutil alternatives where appropriate

不负责“大规模数据外带”,那属于 /post。

见 references/file-transfer.md。


6. 明确不属于 /shell

SQLi→xp_cmdshell→shell            → /web-attack
MSSQL direct exploit→shell        → /service-attack
PTH/PsExec/WinRM lateral shell    → /ad-attack
Cloud IAM→SSM/VM RunCommand shell → /cloud-attack
K8s exec/container/node shell     → /k8s
Runner workflow→runner shell      → /cicd
ClickFix/client execution→shell   → /phishing
AV/EDR blocks payload             → /edr-bypass
network pivot                     → /tunnel

7. 成功条件

Linux:
[+] PTY usable
[+] Ctrl-C/job control works
[+] TERM + rows/cols correct

Windows:
[+] stable cmd/PowerShell/ConPTY
[+] stdin/stdout/stderr usable
[+] long-running commands do not kill session

Generic:
[+] reliable file exchange
[+] session survives normal operator interaction

完成后

写入 ./notes.md。候选只按「开局与收尾」跑 python ~/.claude/skills/bin/modules.py tail。

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

ad-attack

無料

Active Directory exploitation after domain credentials exist: Kerberos (AS-REP/Kerberoast including cracking the ticket then using the account), delegation, NTLM coercion/relay, lateral movement, ACL abuse, ADCS ESC1-ESC17 and CVE paths, dMSA/BadSuccessor, Kerberos reflection, identity confusion, management-plane, domain trust, and domain persistence. Own the current AD chain through crack-and-use to DA, equivalent domain control, or the targeted host SYSTEM. Do not stop after requesting TGS. Host C2 belongs to /post. Operator chooses next modules.

日本語の概要は準備中です。原文の説明を表示しています。

pale-knight/redteam-skill492026年8月23日 更新

ad-recon

無料

Active Directory reconnaissance with or without credentials: user/group/computer enumeration, ACL/delegation, ADCS, modern Windows LAPS, BloodHound, Server 2025/dMSA/Ghost SPN candidates, and trust mapping. Recon only — do not exploit Kerberoast-to-DA, DCSync, or change passwords. Operator may select /ad-attack after cards are ready.

日本語の概要は準備中です。原文の説明を表示しています。

pale-knight/redteam-skill492026年8月23日 更新

cicd

無料

CI/CD pipeline and software-supply-chain exploitation: Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps, Gitea/Forgejo, self-hosted runners/agents, poisoned pipeline execution, artifact/cache abuse, dependency confusion, third-party Action trust, GitOps/registry poisoning, workload identity/OIDC, and emerging agentic CI/CD. Use this skill when the operator has access to a CI/CD system, source repository, build/deploy configuration, runner/agent, artifact/package/registry path, or software delivery trust chain.

日本語の概要は準備中です。原文の説明を表示しています。

pale-knight/redteam-skill492026年8月23日 更新

Cloud control-plane exploitation for AWS, Azure/Entra, GCP, and Alibaba Cloud: IAM/RAM privilege escalation, impersonation, cross-account trust, serverless/compute control, and cloud-native persistence. Host OS persistence/C2 after root/SYSTEM belongs to /post. K8s RBAC belongs to /k8s. Operator chooses next modules; new identities default to /cloud-recon first.

日本語の概要は準備中です。原文の説明を表示しています。

pale-knight/redteam-skill492026年8月23日 更新

Cloud control-plane reconnaissance for AWS, Azure/Entra, GCP, and Alibaba Cloud: identity, IAM/RAM, trust, resources, metadata, and managed-Kubernetes cloud-side boundary. Recon only — no policy changes, no privilege escalation. Operator may select /cloud-attack or /k8s.

日本語の概要は準備中です。原文の説明を表示しています。

pale-knight/redteam-skill492026年8月23日 更新

creds

無料

Credential operations: secret discovery, classification, extraction, conversion, offline cracking of hashes the operator already has as a credential job, policy-aware spraying, NetNTLM capture, generic SMB relay, and Windows/Linux harvest. Do not hijack an in-progress /ad-attack Kerberoast/AS-REP chain (that module cracks and uses the ticket itself). Do not DCSync, read LAPS LDAP, or escalate cloud IAM. Usable credentials are recorded; the operator chooses the next module.

日本語の概要は準備中です。原文の説明を表示しています。

pale-knight/redteam-skill492026年8月23日 更新

pale-knight のスキルをすべて見る

このスキルの問題を報告する