Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
9308 commits
Select commit Hold shift + click to select a range
e269788
feat: support claude agent SDK-style structured outputs in the OpenCo…
Feb 12, 2026
f6e7aef
chore: generate
Feb 12, 2026
8f9742d
fix(win32): use ffi to get around bun raw input/ctrl+c issues (#13052)
Feb 12, 2026
03de51b
release: v1.1.60
Feb 12, 2026
d86f24b
zen: return cost
Feb 12, 2026
624dd94
tweak: tool outputs to be more llm friendly (#13269)
Feb 12, 2026
1413d77
desktop: sqlite migration progress bar (#13294)
Feb 12, 2026
0eaeb45
Testing SignPath Integration (#13308)
Feb 12, 2026
fa97475
ci: move test-sigining policy
Feb 12, 2026
5f42188
chore: style loading screen
Feb 12, 2026
ecb2742
wip(ui): diff virtualization (#12693)
Feb 12, 2026
9f9f0fb
chore: update nix node_modules hashes
Feb 12, 2026
d723147
feat: update to not post comment on workflows when no duplicates foun…
Feb 12, 2026
d82d22b
wip: zen
Feb 12, 2026
a115565
core: allow model configurations without npm/api provider details
Feb 12, 2026
892bb75
release: v1.1.61
Feb 12, 2026
85df106
chore: generate
Feb 12, 2026
ae811ad
wip: zen
Feb 12, 2026
56ad2db
core: expose tool arguments in shell hook for plugin visibility
Feb 12, 2026
ff4414b
chore: refactor packages/app files (#13236)
Feb 12, 2026
ed472d8
fix(app): more defensive session context metrics
Feb 12, 2026
a82ca86
fix(app): more defensive code component
Feb 12, 2026
658bf6f
zen: minimax m2.5
Feb 12, 2026
59a323e
wip: zen
Feb 12, 2026
ecab692
fix(docs): correct `format` attribute in `StructuredOutputs` (#13340)
Feb 12, 2026
2db618d
fix: downgrade bun to 1.3.5 (#13347)
Feb 12, 2026
847e06f
chore: update nix node_modules hashes
Feb 12, 2026
ba54cee
feat(tool): return image attachments from webfetch (#13331)
Feb 12, 2026
789705e
ignore: document test fixtures for agents
Feb 12, 2026
da95213
chore(app): refactor for better solidjs hygiene (#13344)
Feb 12, 2026
0771e3a
fix(app): preserve undo history for plain-text paste (#13351)
Feb 12, 2026
ff0abac
fix(app): project icons unloading
Feb 12, 2026
aaee5fb
release: v1.1.62
Feb 12, 2026
e6e9c15
improve codex model list
Feb 12, 2026
ac018e3
release: v1.1.63
Feb 12, 2026
d1ee4c8
test: add more test cases for project.test.ts (#13355)
Feb 12, 2026
958320f
fix(app): remote http server connections
Feb 12, 2026
50f208d
fix(app): suggestion active state broken
Feb 12, 2026
3696d1d
chore: cleanup
Feb 12, 2026
81c623f
chore: cleanup
Feb 12, 2026
e9b9a62
chore: cleanup
Feb 12, 2026
7ccf223
chore: cleanup
Feb 12, 2026
70303d0
chore: cleanup
Feb 12, 2026
ff3b174
fix(app): normalize oauth error messages
Feb 12, 2026
4e0f509
feat(app): option to turn off sound effects
Feb 12, 2026
548608b
fix(app): terminal pty isolation
Feb 12, 2026
11dd281
docs: update STACKIT provider documentation with typo fix (#13357)
Feb 12, 2026
20dcff1
chore: generate
Feb 12, 2026
c0814da
do not open console on error (#13374)
Feb 12, 2026
a8f2884
feat: windows selection behavior, manual ctrl+c (#13315)
Feb 12, 2026
4018c86
fix: baseline CPU detection (#13371)
Feb 12, 2026
445e0d7
chore: update nix node_modules hashes
Feb 12, 2026
93eee0d
fix: look for recent model in fallback in cli (#12582)
Feb 12, 2026
d475fd6
chore: generate
Feb 12, 2026
f66624f
chore: cleanup flag code (#13389)
Feb 12, 2026
29671c1
fix: token substitution in OPENCODE_CONFIG_CONTENT (#13384)
Feb 12, 2026
76db218
release: v1.1.64
Feb 12, 2026
991496a
fix: resolve ACP hanging indefinitely in thinking state on Windows (#…
Feb 13, 2026
adb0c4d
desktop: only show loading window if sqlite migration is necessary
Feb 13, 2026
0303c29
fix(app): failed to create store
Feb 13, 2026
8da5fd0
fix(app): worktree delete
Feb 13, 2026
b525c03
chore: cleanup
Feb 13, 2026
7f95cc6
fix(app): prompt input quirks
Feb 13, 2026
c9719df
fix(app): notification should navigate to session
Feb 13, 2026
dec304a
fix(app): emoji as avatar
Feb 13, 2026
e0f1c3c
cleanup desktop loading page
Feb 13, 2026
fb7b2f6
feat(app): toggle all provider models
Feb 13, 2026
dd296f7
fix(app): reconnect event stream on disconnect
Feb 13, 2026
b06afd6
ci: remove signpath policy
Feb 13, 2026
1608565
feat(hook): add tool.definition hook for plugins to modify tool descr…
Feb 13, 2026
98aeb60
fix: ensure @-ing a dir uses the read tool instead of dead list tool …
Feb 13, 2026
1fb6c0b
Revert "fix: token substitution in OPENCODE_CONFIG_CONTENT" (#13429)
Feb 13, 2026
34ebe81
release: v1.1.65
Feb 13, 2026
0d90a22
feat: update some ai sdk packages and uuse adaptive reasoning for opu…
Feb 13, 2026
693127d
feat(cli): add --dir option to run command (#12443)
Feb 13, 2026
b8ee882
chore: update nix node_modules hashes
Feb 13, 2026
ebb907d
fix(desktop): performance optimization for showing large diff & files…
Feb 13, 2026
9f20e0d
fix(web): sync docs locale cookie on alias redirects (#13109)
Feb 13, 2026
ebe5a2b
fix(app): remount SDK/sync tree when server URL changes (#13437)
Feb 13, 2026
b1764b2
docs: Fix zh-cn translation mistake in tools.mdx (#13407)
Feb 13, 2026
f991a6c
chore: generate
Feb 13, 2026
e242fe1
fix(web): use prompt_async endpoint to avoid timeout over VPN/tunnel …
Feb 13, 2026
1c71604
fix(app): terminal resize
Feb 13, 2026
4f51c09
chore: cleanup
Feb 13, 2026
b8848cf
docs(ko): polish Korean phrasing in acp, agents, config, and custom-t…
Feb 13, 2026
88e2eb5
docs: add pacman installation option for Arch Linux alongside AUR (#1…
Feb 13, 2026
bc1fd06
fix(test): move timeout config to CLI flag (#13494)
Feb 13, 2026
72c09e1
fix: standardize zh-CN docs character set and terminology (#13500)
Feb 13, 2026
d30e917
fix(ui): support cmd-click links in inline code (#12552)
Feb 13, 2026
d018903
fix: prevent opencode run crash on malformed tool inputs (#13051)
Feb 14, 2026
6d95f0d
sqlite again (#10597)
Feb 14, 2026
afb04ed
chore: generate
Feb 14, 2026
7d46872
desktop: remote OPENCODE_SQLITE env (#13545)
Feb 14, 2026
d0dcffe
chore: update nix node_modules hashes
Feb 14, 2026
0b9e929
desktop: fix rust
Feb 14, 2026
ffc000d
release: v1.2.0
Feb 14, 2026
1e25df2
zen: minimax m2.5 & glm5
Feb 14, 2026
179c407
fix: tweak websearch tool description date info to avoid cache busts …
Feb 14, 2026
b020758
tui: show all project sessions from any working directory
Feb 14, 2026
cd775a2
release: v1.2.1
Feb 14, 2026
ed439b2
ci: test-signing signpath policy
Feb 14, 2026
df3203d
ci: move signpath policy
Feb 14, 2026
ef205c3
bump vertex ai packages (#13625)
Feb 14, 2026
759ec10
fix vercel gateway variants (#13541)
Feb 14, 2026
306fc77
chore: update nix node_modules hashes
Feb 14, 2026
68bb8ce
core: filter sessions at database level to improve session list loadi…
Feb 14, 2026
8631d6c
core: add comprehensive test coverage for Session.list() filters
Feb 14, 2026
3b6b3e6
release: v1.2.2
Feb 14, 2026
933a491
fix: ensure vercel variants pass amazon models under bedrock key (#13…
Feb 14, 2026
575f2cf
chore: bump nixpkgs to get bun 1.3.9 (#13302)
Feb 14, 2026
67c985c
fix: add WAL checkpoint on database open (#13633)
Feb 14, 2026
839c5cd
fix: ensure anthropic models on OR also have variant support (#13498)
Feb 14, 2026
7911cb6
chore: update nix node_modules hashes
Feb 14, 2026
dda7669
chore: add dual-license structure (MIT + PolyForm Noncommercial)
Feb 14, 2026
897fd70
chore: phase 0 - remove web/docs packages and add rebrand script
Feb 14, 2026
602ea22
refactor: complete OpenCode → CyberStrike rebrand
Feb 14, 2026
e51db2a
refactor: rename CLI binary from opencode to cyberstrike
Feb 14, 2026
1392fcd
refactor: fix remaining opencode references (camelCase, PascalCase, b…
Feb 14, 2026
8e15907
fix: resolve typecheck errors after rebrand
Feb 14, 2026
58fb029
Merge pull request #1 from CyberStrikeus/rebrand/opencode-to-cyberstrike
Feb 14, 2026
12a5cab
feat: add security agents and knowledge base (Phase 1)
Feb 15, 2026
14a1a4a
Merge pull request #2 from CyberStrikeus/security/phase-1-agents
Feb 15, 2026
c1ffb60
docs: update contributor docs for security platform
Feb 15, 2026
461b579
Merge pull request #3 from CyberStrikeus/chore/contributor-docs
Feb 15, 2026
74fdf3b
feat: add HackR browser, memory system, lazy tool registry (Phase 2)
Feb 16, 2026
4426871
Merge pull request #4 from CyberStrikeus/security/phase-2-browser-memory
Feb 16, 2026
b76e68f
feat: replace ASCII logo with CyberStrike figlet art
Feb 16, 2026
eb7a915
Merge pull request #5 from CyberStrikeus/security/phase-2-browser-memory
Feb 16, 2026
b4399f0
feat: random gradient palette for ASCII logo on each startup
Feb 16, 2026
9f7b98a
Merge pull request #6 from CyberStrikeus/security/phase-2-browser-memory
Feb 16, 2026
c8e23fe
feat: add Claude Code CLI/API providers, cloud security agent, domain…
Feb 16, 2026
d282aa5
Merge branch 'feat/claude-cli-integration' into dev
Feb 16, 2026
2ea5a3e
feat: port chunked compaction and pre-compaction memory flush from Op…
Feb 20, 2026
559e3cc
fix: increase Claude CLI timeout to 15min and fix timer leak
Feb 20, 2026
5c30bff
fix: rebrand leftover — terminal title OC→CS, sidebar OpenCode→CyberS…
Feb 20, 2026
8359145
feat: enable browser tool for default build and general agents
Feb 20, 2026
9c34c0a
feat: add tool calling support to claude-cli provider
Feb 20, 2026
bbe86a7
fix: use correct AI SDK stream event types for tool calls
Feb 20, 2026
1782b42
fix: add session-id continuity for multi-turn tool calling
Feb 20, 2026
522bf55
fix: prevent infinite loop in claude-cli multi-step tool calling
Feb 20, 2026
ff9078f
fix: enforce browser tool usage over bash in claude-cli provider
Feb 20, 2026
e26b6f9
revert: remove broken tool-calling experiment from claude-cli provider
Feb 20, 2026
12034b3
feat: add MCP browser server for Claude CLI tool support
Feb 28, 2026
5e197cf
feat: update packages with latest codebase
Feb 28, 2026
3524190
fix: add placeholder for empty endpoint migration
Mar 1, 2026
ca89b7c
fix: use valid no-op SQL for empty endpoint migration
Mar 1, 2026
e86e566
feat: simplify ASCII logo and use theme colors
Mar 1, 2026
7ec506e
fix: migration folder timestamps and loader validation
Mar 6, 2026
2243680
fix: default server port to 4096
Mar 6, 2026
6958b7f
chore: update .gitignore for temporary debug artifacts
Mar 6, 2026
c7cccb0
feat: add vulnerability reporting and request normalization models
Mar 6, 2026
9e33136
feat: add web security testing infrastructure (credentials, roles, ob…
Mar 6, 2026
41a2fd6
feat: add report_vulnerability tool with severity and impact tracking
Mar 6, 2026
232af19
feat: add web proxy agent tools for endpoint analysis and credential …
Mar 6, 2026
18a320d
feat: add vulnerability testing and proxy analysis agent prompts
Mar 6, 2026
6a1b5bf
feat: extend agent definitions with proxy agents and vulnerability te…
Mar 6, 2026
d454c44
feat: add vulnerability, request, and web context API endpoints
Mar 6, 2026
30d3404
feat: add request context prepending for vulnerability agents
Mar 6, 2026
93777e7
chore: register new web and vulnerability tools in tool registry
Mar 6, 2026
e088406
chore: update config schema for report_vulnerability permission
Mar 6, 2026
f81cd77
feat: add vulnerability and web context views to TUI session sidebar
Mar 6, 2026
eadd12f
feat: add sync context handlers for vulnerability and web security data
Mar 6, 2026
7e9e2a3
feat: integrate vulnerability reporting into CLI commands
Mar 6, 2026
79d3def
chore: regenerate SDK types and update storage schema exports
Mar 6, 2026
f6e8aba
feat: v1.0.8-beta.1 — agent architecture refactor + vulnerability tes…
Mar 15, 2026
81db9b1
fix: critical bug fixes for v1.0.8-beta.1 release
Mar 15, 2026
7c234d0
feat: local LLM provider support + CLI management + UI improvements
Mar 15, 2026
c07378f
feat: Bolt client integration + browser tool cleanup
Mar 16, 2026
3712a7a
fix: bolt sidebar display + lazy registry + sdk.fetch
Mar 16, 2026
7d84c8a
fix: refresh lazy registry on ToolListChanged notification
Mar 16, 2026
055a2ae
fix: defer Bus.subscribe to init() to avoid Instance context error
Mar 16, 2026
56ea40b
feat: bolt delete + auth error detection
Mar 16, 2026
f724075
fix: change bolt delete keybind from 'd' to 'ctrl+d'
Mar 16, 2026
5e72cdf
ui: hide LSP section from sidebar
Mar 16, 2026
ea1ee9f
fix: update @opentui/core 0.1.79 → 0.1.87
Mar 16, 2026
82cdeee
fix: work around opentui border rendering bug in prompt input
Mar 16, 2026
6f3a5b2
feat: v1.1.0 — MCP/Bolt management improvements
Mar 17, 2026
18e1cfc
docs: rewrite README as offensive security platform — 23 languages + …
Mar 17, 2026
2847ebd
docs: enhance README with community-focused narrative and feature sho…
Mar 17, 2026
ec3117f
docs: redesign social preview SVGs with enhanced visual design
Mar 17, 2026
01de8b1
fix: remove SVG filters for GitHub compatibility
Mar 17, 2026
162ea38
docs: use actual CyberStrike logo in social preview SVGs
Mar 17, 2026
951e964
chore: overhaul issue templates + fix Discord invite link
Mar 17, 2026
5145b8a
chore: improve PR template with security impact section
Mar 17, 2026
2b671dc
docs: update CONTRIBUTING.md — MCP ecosystem, fix dead refs, add comm…
Mar 17, 2026
9e84c58
docs: rewrite SECURITY.md — fix domain, add Bolt/MCP sections, disclo…
Mar 17, 2026
d4ef2a2
docs: add CHANGELOG.md covering v0.1.0 → v1.1.0
Mar 17, 2026
695c6af
chore: move CLAUDE.md to .claude/ and gitignore it
Mar 17, 2026
5c2a08a
Merge remote-tracking branch 'origin/main' into dev
Mar 17, 2026
6730c3f
Merge pull request #12 from CyberStrikeus/dev
Mar 17, 2026
926c707
chore: add FUNDING.yml — GitHub Sponsors + Buy Me a Coffee
Mar 17, 2026
aa14702
Merge pull request #13 from CyberStrikeus/dev
Mar 17, 2026
9757455
fix: use badchars for GitHub Sponsors (CyberStrikeus org not enrolled)
Mar 17, 2026
6d8eba0
Merge pull request #14 from CyberStrikeus/dev
Mar 17, 2026
7b11de7
docs: add MCP Security Suite backlink table to all READMEs + remove B…
Mar 17, 2026
a16590d
Merge pull request #15 from CyberStrikeus/dev
Mar 17, 2026
99ac70e
docs: add section navigation bar to all 23 READMEs
Mar 17, 2026
5e467a5
Merge pull request #16 from CyberStrikeus/dev
Mar 17, 2026
0766da9
docs: add Bolt section and nav link to all 23 READMEs
Mar 17, 2026
34482d8
Merge pull request #17 from CyberStrikeus/dev
Mar 17, 2026
f62874d
feat: redesign SVG banners, reorder README headers, add NPM keywords
Mar 17, 2026
8873ee7
Merge pull request #18 from CyberStrikeus/dev
Mar 17, 2026
e7b6cb0
ci: replace Blacksmith runners with GitHub free runners
Mar 17, 2026
c43723a
ci: make cyberstrike install non-fatal for first publish
Mar 17, 2026
42b0442
feat: migrate all NPM packages to @cyberstrike-io/ scope
Mar 17, 2026
066fc52
Merge pull request #19 from CyberStrikeus/dev
Mar 17, 2026
cb53b42
fix: handle missing cyberstrike binary in changelog generation
Mar 17, 2026
0aeff05
ci: allow publish to proceed when desktop builds fail
Mar 17, 2026
b40f522
ci: fix publish job — fallback git config and NPM auth token
Mar 17, 2026
2384078
fix: remove duplicate migration folders with invalid names
Mar 17, 2026
d2ef0fe
fix: use authenticated GitHub API requests in changelog
Mar 17, 2026
8132fe0
chore: add .cyberstrike/ and __MACOSX/ to gitignore
Mar 17, 2026
b75dfaf
fix: update tests for opencode → cyberstrike agent rename
Mar 17, 2026
e3665df
fix: decouple publish from Tauri desktop builds
Mar 17, 2026
ac30808
fix: add fallback git config when GitHub App credentials missing
Mar 17, 2026
650ec0f
fix: tool registry test should not require cowsay to be installed
Mar 17, 2026
e464336
fix: gracefully skip custom tools with missing dependencies
Mar 17, 2026
bc557c9
feat: remove Tauri desktop app (opencode legacy)
Mar 17, 2026
e4026ed
ci: remove Playwright e2e from test workflow
Mar 17, 2026
21f9d8d
fix: lowercase Docker image tag for ghcr.io
Mar 17, 2026
3687f5e
chore: remove 13 unused workflows inherited from opencode
Mar 17, 2026
e01112d
fix: rename opencode → cyberstrike in Dockerfile + remove unused work…
Mar 17, 2026
fb884a6
chore: remove Docker from build pipeline
Mar 17, 2026
1ebb38c
refactor: rename npm scope @cyberstrikeus → @cyberstrike-io
Mar 17, 2026
e77a353
release: v1.1.1
Mar 17, 2026
23af004
chore: remove AUR and Homebrew from publish script
Mar 17, 2026
8efdab9
chore: generate
Mar 17, 2026
7596f28
chore: publish only on manual trigger, not on every push
Mar 17, 2026
c286df8
fix: rename opencode → cyberstrike in bin launcher script
Mar 17, 2026
f086b4c
release: v1.1.2
Mar 17, 2026
95db941
fix: add billing header for OAT token auth on Sonnet/Opus models
Mar 18, 2026
726ce8e
feat: add offensive security agent prompts and harden publish script
Mar 18, 2026
6313e57
release: v1.1.3
Mar 18, 2026
a184936
fix: correct npm install commands and domain references on website
Mar 18, 2026
85ad427
fix: add --beta flag to install script, fix scoped package names in u…
Mar 18, 2026
5bc0873
fix: auto-fallback to available port when default port is busy
Mar 18, 2026
26b36a2
fix: update @opentui/core and @opentui/solid to 0.1.88
Mar 18, 2026
527fd08
release: vpatch
Mar 18, 2026
1f95685
release: v1.1.4
Mar 18, 2026
943be3a
fix: add schema reconciler to repair partially applied migrations
Mar 18, 2026
369e471
chore: generate
Mar 18, 2026
d773494
chore: consolidate license to AGPL-3.0-only, fix Twitter and domain refs
Mar 18, 2026
53ea9cc
fix: replace all cyberstrike.us references with cyberstrike.io
Mar 18, 2026
b227b8c
Merge pull request #20 from CyberStrikeus/dev
Mar 18, 2026
d6f76c5
Update copyright year and holder in LICENSE file
Mar 18, 2026
5c1ca57
Update copyright year and holder in LICENSE file
Mar 18, 2026
8fa901a
docs: rewrite README with intelligence layer, SEO optimization, and B…
Mar 18, 2026
377d530
chore: generate
Mar 18, 2026
a8dd983
Merge pull request #21 from CyberStrikeus/dev
Mar 18, 2026
489b068
fix(security): prevent SSRF via unvalidated GitHub Enterprise URL in …
Mar 19, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
16 changes: 16 additions & 0 deletions .claude/settings.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
{
"permissions": {
"allow": [
"Bash(*)",
"Read(*)",
"Write(*)",
"Edit(*)",
"Glob(*)",
"Grep(*)",
"WebFetch(*)",
"WebSearch(*)",
"NotebookEdit(*)",
"Task(*)"
]
}
}
3 changes: 3 additions & 0 deletions .cyberstrike/.gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
plans/
bun.lock
package.json
10 changes: 10 additions & 0 deletions .cyberstrike/cyberstrike.jsonc
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
{
"$schema": "https://cyberstrike.io/config.json",
"provider": {
"cyberstrike": {
"options": {}
}
},
"mcp": {
}
}
4 changes: 4 additions & 0 deletions .cyberstrike/env.d.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
declare module "*.txt" {
const content: string
export default content
}
180 changes: 180 additions & 0 deletions .cyberstrike/skill/ad-security/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,180 @@
---
name: ad-security
description: Active Directory security testing and attack techniques
tags: [ad, windows, kerberos, ldap, internal-network]
version: "1.0"
---

# Active Directory Security Testing

## Credential Access Techniques

| ID | Technique | Tool | Description |
|----|-----------|------|-------------|
| CA-01 | Kerberoasting | GetUserSPNs.py, Rubeus | Request TGS for service accounts |
| CA-02 | AS-REP Roasting | GetNPUsers.py, Rubeus | Attack accounts without preauth |
| CA-03 | DCSync | secretsdump.py, Mimikatz | Replicate DC credentials |
| CA-04 | LSASS Dump | Mimikatz, ProcDump | Extract credentials from memory |
| CA-05 | SAM/SYSTEM Dump | secretsdump.py | Extract local credentials |
| CA-06 | NTDS.dit Extraction | secretsdump.py | Offline DC credential dump |
| CA-07 | Cached Credentials | Mimikatz | Extract cached domain creds |
| CA-08 | DPAPI Secrets | Mimikatz, SharpDPAPI | Decrypt protected data |
| CA-09 | Credential Vault | Mimikatz | Windows credential manager |
| CA-10 | Browser Credentials | SharpChromium | Chrome/Edge saved passwords |
| CA-11 | LLMNR/NBT-NS Poisoning | Responder | Capture NTLMv2 hashes |
| CA-12 | NTLM Relay | ntlmrelayx.py | Relay captured authentication |
| CA-13 | Password Spraying | Spray, Kerbrute | Test common passwords |
| CA-14 | GPP Passwords | Get-GPPPassword | Decrypt Group Policy preferences |

## Privilege Escalation Techniques

| ID | Technique | Tool | Description |
|----|-----------|------|-------------|
| PE-01 | ACL Abuse | BloodHound, PowerView | WriteDACL, GenericAll abuse |
| PE-02 | GPO Abuse | SharpGPOAbuse | Modify group policy |
| PE-03 | AD CS ESC1 | Certipy | Template allows user SAN |
| PE-04 | AD CS ESC2 | Certipy | Any purpose EKU |
| PE-05 | AD CS ESC3 | Certipy | Enrollment agent abuse |
| PE-06 | AD CS ESC4 | Certipy | Template ACL abuse |
| PE-07 | AD CS ESC5 | Certipy | PKI object access control |
| PE-08 | AD CS ESC6 | Certipy | EDITF_ATTRIBUTESUBJECTALTNAME2 |
| PE-09 | AD CS ESC7 | Certipy | CA ACL abuse |
| PE-10 | AD CS ESC8 | Certipy | NTLM relay to HTTP enrollment |
| PE-11 | Constrained Delegation | Rubeus, getST.py | S4U2Self/S4U2Proxy abuse |
| PE-12 | Resource-Based Constrained Delegation | Rubeus | msDS-AllowedToActOnBehalfOfOtherIdentity |

## Lateral Movement Techniques

| ID | Technique | Tool | Description |
|----|-----------|------|-------------|
| LM-01 | Pass-the-Hash | Mimikatz, pth-winexe | Authenticate with NTLM hash |
| LM-02 | Pass-the-Ticket | Rubeus, Mimikatz | Inject Kerberos tickets |
| LM-03 | Overpass-the-Hash | Rubeus | Request TGT with NTLM hash |
| LM-04 | PSExec | Impacket, Sysinternals | Remote execution via SMB |
| LM-05 | WMI Execution | wmiexec.py | Execute commands via WMI |
| LM-06 | DCOM Execution | dcomexec.py | Distributed COM abuse |
| LM-07 | WinRM | evil-winrm | PowerShell remoting |
| LM-08 | RDP Hijacking | tscon.exe | Take over disconnected sessions |
| LM-09 | SMB Relay | ntlmrelayx.py | Relay auth to other hosts |
| LM-10 | SSH (Linux) | ssh | Lateral to Linux systems |

## Persistence Techniques

| ID | Technique | Tool | Description |
|----|-----------|------|-------------|
| PS-01 | Golden Ticket | Mimikatz, ticketer.py | Forge TGT with KRBTGT hash |
| PS-02 | Silver Ticket | Mimikatz, ticketer.py | Forge TGS for specific service |
| PS-03 | Diamond Ticket | Rubeus | Modify legitimate TGT |
| PS-04 | Skeleton Key | Mimikatz | Master password on DC |
| PS-05 | AdminSDHolder | PowerView | Persistent admin rights |
| PS-06 | DCShadow | Mimikatz | Rogue domain controller |
| PS-07 | SID History | Mimikatz | Add privileged SID to history |
| PS-08 | Machine Account | Powermad | Add computer to domain |

## Enumeration Commands

### BloodHound Collection
```bash
# SharpHound (Windows)
SharpHound.exe -c All --zipfilename bloodhound.zip

# BloodHound.py (Linux)
bloodhound-python -d domain.local -u user -p pass -ns 10.0.0.1 -c all

# NetExec BloodHound
nxc ldap 10.0.0.1 -u user -p pass --bloodhound --collection All
```

### LDAP Enumeration
```bash
# Get domain info
ldapsearch -x -H ldap://10.0.0.1 -D "user@domain.local" -w 'pass' -b "DC=domain,DC=local"

# Find users with SPN (Kerberoastable)
ldapsearch -x -H ldap://10.0.0.1 -D "user@domain.local" -w 'pass' \
-b "DC=domain,DC=local" "(&(objectClass=user)(servicePrincipalName=*))" sAMAccountName

# Find users without preauth (AS-REP Roastable)
ldapsearch -x -H ldap://10.0.0.1 -D "user@domain.local" -w 'pass' \
-b "DC=domain,DC=local" "(&(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=4194304))"
```

### NetExec Commands
```bash
# Enumerate users
nxc smb 10.0.0.1 -u user -p pass --users

# Enumerate groups
nxc smb 10.0.0.1 -u user -p pass --groups

# Find shares
nxc smb 10.0.0.1 -u user -p pass --shares

# Check for admin access
nxc smb 10.0.0.0/24 -u user -p pass

# Password spray
nxc smb 10.0.0.1 -u users.txt -p 'Spring2024!' --no-bruteforce
```

## Attack Paths

### Path 1: Domain User to Domain Admin
```
User Credential
├─► Kerberoast SPN accounts
│ └─► Crack service account password
│ └─► Service account is Domain Admin
├─► BloodHound Path Finding
│ └─► ACL chain to DA group
│ └─► WriteDACL → GenericAll → Add to DA
└─► AD CS Misconfiguration
└─► ESC1: Request cert as DA
└─► Authenticate as DA
```

### Path 2: Compromised Workstation to DC
```
Local Admin on Workstation
├─► LSASS dump → cached domain creds
│ └─► Domain user credential
│ └─► Continue as Path 1
├─► Find admin sessions
│ └─► Lateral move to server
│ └─► Dump DA credentials
└─► Unconstrained Delegation
└─► Coerce DC authentication
└─► Capture TGT → DCSync
```

## Important Impacket Tools

| Tool | Purpose |
|------|---------|
| GetUserSPNs.py | Kerberoasting |
| GetNPUsers.py | AS-REP Roasting |
| secretsdump.py | Dump secrets (DCSync, SAM, LSA) |
| smbexec.py | SMB-based execution |
| wmiexec.py | WMI-based execution |
| psexec.py | PSExec-style execution |
| ntlmrelayx.py | NTLM relay attacks |
| getST.py | Request service tickets |
| ticketer.py | Create Golden/Silver tickets |
| lookupsid.py | SID enumeration |
| samrdump.py | SAM Remote interface dump |

## Detection Evasion Considerations

| Action | Detection | Evasion |
|--------|-----------|---------|
| Kerberoasting | 4769 events (RC4) | Use AES encryption |
| DCSync | 4662 events | Time-based, limit frequency |
| Pass-the-Hash | 4624 Type 3 with NTLM | Overpass-the-Hash (Kerberos) |
| BloodHound | LDAP queries | Reduce collection scope |
| Mimikatz | AV signatures | BOF, custom tools |
42 changes: 42 additions & 0 deletions .cyberstrike/skill/bun-file-io/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
---
name: bun-file-io
description: Use this when you are working on file operations like reading, writing, scanning, or deleting files. It summarizes the preferred file APIs and patterns used in this repo. It also notes when to use filesystem helpers for directories.
---

## Use this when

- Editing file I/O or scans in `packages/cyberstrike`
- Handling directory operations or external tools

## Bun file APIs (from Bun docs)

- `Bun.file(path)` is lazy; call `text`, `json`, `stream`, `arrayBuffer`, `bytes`, `exists` to read.
- Metadata: `file.size`, `file.type`, `file.name`.
- `Bun.write(dest, input)` writes strings, buffers, Blobs, Responses, or files.
- `Bun.file(...).delete()` deletes a file.
- `file.writer()` returns a FileSink for incremental writes.
- `Bun.Glob` + `Array.fromAsync(glob.scan({ cwd, absolute, onlyFiles, dot }))` for scans.
- Use `Bun.which` to find a binary, then `Bun.spawn` to run it.
- `Bun.readableStreamToText/Bytes/JSON` for stream output.

## When to use node:fs

- Use `node:fs/promises` for directories (`mkdir`, `readdir`, recursive operations).

## Repo patterns

- Prefer Bun APIs over Node `fs` for file access.
- Check `Bun.file(...).exists()` before reading.
- For binary/large files use `arrayBuffer()` and MIME checks via `file.type`.
- Use `Bun.Glob` + `Array.fromAsync` for scans.
- Decode tool stderr with `Bun.readableStreamToText`.
- For large writes, use `Bun.write(Bun.file(path), text)`.

NOTE: Bun.file(...).exists() will return `false` if the value is a directory.
Use Filesystem.exists(...) instead if path can be file or directory

## Quick checklist

- Use Bun APIs first.
- Use `path.join`/`path.resolve` for paths.
- Prefer promise `.catch(...)` over `try/catch` when possible.
Loading