mukul975/Threatswarm
27 scope-enforced AI agents that run the full pentest kill-chain (recon → exploit → post-ex → DFIR → report) as a one-command Claude Code plugin. Backed by 754 MITRE-mapped skills.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
# review before running: this installs third-party code
$ npx degit mukul975/Threatswarm/.claude ./rig-threatswarm # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit mukul975/Threatswarm/.claude/skills/ad-attacks .claude/skills/ad-attacks $ npx degit mukul975/Threatswarm/.claude/skills/exploit-db .claude/skills/exploit-db $ npx degit mukul975/Threatswarm/.claude/skills/mitre-attack .claude/skills/mitre-attack $ npx degit mukul975/Threatswarm/.claude/skills/report-templates .claude/skills/report-templates $ npx degit mukul975/Threatswarm/.claude/skills/wordlists .claude/skills/wordlists
$ curl -fsSL --create-dirs -o .claude/agents/active-directory.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/active-directory.md $ curl -fsSL --create-dirs -o .claude/agents/api-attacker.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/api-attacker.md $ curl -fsSL --create-dirs -o .claude/agents/blue-team.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/blue-team.md $ curl -fsSL --create-dirs -o .claude/agents/c2-operator.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/c2-operator.md $ curl -fsSL --create-dirs -o .claude/agents/cloud-attacker.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/cloud-attacker.md $ curl -fsSL --create-dirs -o .claude/agents/compliance-scanner.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/compliance-scanner.md $ curl -fsSL --create-dirs -o .claude/agents/container-attacker.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/container-attacker.md $ curl -fsSL --create-dirs -o .claude/agents/crypto-attacker.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/crypto-attacker.md $ curl -fsSL --create-dirs -o .claude/agents/dfir.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/dfir.md $ curl -fsSL --create-dirs -o .claude/agents/evasion.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/evasion.md $ curl -fsSL --create-dirs -o .claude/agents/exploit.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/exploit.md $ curl -fsSL --create-dirs -o .claude/agents/iot-attacker.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/iot-attacker.md $ curl -fsSL --create-dirs -o .claude/agents/log-analyst.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/log-analyst.md $ curl -fsSL --create-dirs -o .claude/agents/malware-analyst.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/malware-analyst.md $ curl -fsSL --create-dirs -o .claude/agents/mobile-attacker.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/mobile-attacker.md $ curl -fsSL --create-dirs -o .claude/agents/network-ops.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/network-ops.md $ curl -fsSL --create-dirs -o .claude/agents/osint.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/osint.md $ curl -fsSL --create-dirs -o .claude/agents/password-attacks.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/password-attacks.md $ curl -fsSL --create-dirs -o .claude/agents/post-ex.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/post-ex.md $ curl -fsSL --create-dirs -o .claude/agents/recon.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/recon.md $ curl -fsSL --create-dirs -o .claude/agents/report-writer.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/report-writer.md $ curl -fsSL --create-dirs -o .claude/agents/reverse-engineer.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/reverse-engineer.md $ curl -fsSL --create-dirs -o .claude/agents/social-engineer.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/social-engineer.md $ curl -fsSL --create-dirs -o .claude/agents/threat-hunter.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/threat-hunter.md $ curl -fsSL --create-dirs -o .claude/agents/vuln-researcher.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/vuln-researcher.md $ curl -fsSL --create-dirs -o .claude/agents/web-attacker.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/web-attacker.md $ curl -fsSL --create-dirs -o .claude/agents/wireless-attacker.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/wireless-attacker.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(rm -rf *)",
"Bash(shred *)",
"Bash(wipe *)",
"Bash(dd if=/dev/zero *)",
"Read(.env)",
"Read(.env.*)",
"Read(secrets/**)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "python3 .claude/hooks/scope_check.py"
}
]
}
]
}
} Skills (5)
Subagents (27)
| active-directory model: opus | Active Directory and Windows domain attack specialist. Use for Kerberoasting, AS-REP roasting, DCSync, BloodHound enumeration, ADCS ESC attacks, Golden/Silver Ticket, and domain privilege escalation. |
| api-attacker model: sonnet | API security testing specialist for REST, GraphQL, gRPC, and WebSocket APIs. Handles BOLA/IDOR, mass assignment, authentication bypass, rate limit evasion, JWT attacks, GraphQL introspection abuse, AP |
| blue-team model: sonnet | Defensive security and hardening specialist. Creates detection rules, hardens Linux/Windows systems, writes Sigma rules, configures auditd, fail2ban, Sysmon, and provides CIS benchmark remediation gui |
| c2-operator model: opus | Command and control infrastructure specialist for authorized red team operations. Handles Sliver C2 framework, Havoc C2, Metasploit multi-handler, msfvenom payload generation, implant configuration, H |
| cloud-attacker model: sonnet | Cloud penetration testing specialist for AWS, Azure, and GCP. Handles IAM enumeration, privilege escalation, S3 bucket abuse, metadata SSRF, Pacu framework, container escape to cloud, and cloud-native |
| compliance-scanner model: sonnet | Compliance and security standards assessment specialist. Handles CIS benchmarks, PCI-DSS controls, NIST CSF, SOC2, GDPR technical controls, OpenSCAP assessments, Docker CIS bench, Kubernetes CIS bench |
| container-attacker model: sonnet | Container and Kubernetes security specialist. Handles Docker escape techniques, Kubernetes RBAC abuse, service account token theft, kubelet API exploitation, etcd access, namespace breakout, and cloud |
| crypto-attacker model: opus | Cryptography and TLS security specialist. Handles TLS configuration auditing, JWT algorithm confusion, padding oracle attacks, hash cracking mode selection, RSA weak key analysis, ECB mode detection, |
| dfir model: opus | Digital forensics and incident response specialist. Handles triage, memory acquisition with AVML/LiME, Volatility analysis, log timeline reconstruction, IOC extraction, persistence hunting, and incide |
| evasion model: opus | Antivirus and EDR evasion specialist for authorized red team engagements. Handles AMSI bypass, payload obfuscation, living-off-the-land techniques, sandbox detection, process injection concepts, and d |
| exploit model: opus | Exploitation specialist for gaining initial access. Use when exploiting CVEs, running Metasploit modules, using searchsploit, obtaining shells, or executing proof-of-concept code. Triggers on: exploit |
| iot-attacker model: sonnet | IoT and embedded systems security specialist. Handles firmware extraction and analysis, hardcoded credential discovery, UART/JTAG access, MQTT/CoAP protocol testing, RouterSploit exploitation, web int |
| log-analyst model: sonnet | Security log analysis specialist. Parses and correlates auth.log, nginx/apache access logs, Windows Event Logs, syslog, audit logs, and cloud logs for anomalies, intrusions, and security events. Gener |
| malware-analyst model: opus | Malware analysis specialist for static and dynamic analysis. Handles PE/ELF/APK binary triage, behavioral analysis, IOC extraction, YARA rule writing, C2 protocol reverse engineering, deobfuscation, s |
| mobile-attacker model: sonnet | Mobile application security specialist for Android and iOS. Handles APK decompilation, static/dynamic analysis, Frida instrumentation, SSL pinning bypass, ADB shell exploitation, MobSF scanning, traff |
| network-ops model: sonnet | Network penetration testing specialist for ARP attacks, MitM, packet capture, SNMP enumeration, SMB relay, Responder credential capture, and network-level attacks. Triggers on: ARP, MitM, sniff, inter |
| osint model: sonnet | Open source intelligence specialist for passive reconnaissance. Handles domain intelligence, certificate transparency, Shodan enumeration, email harvesting, GitHub dorking, employee profiling, ASN/IP |
| password-attacks model: sonnet | Password cracking and credential attack specialist. Use when working with password hashes, hash cracking, wordlist attacks, credential analysis, or password auditing. Triggers on: password, hash, crac |
| post-ex model: opus | Post-exploitation specialist for privilege escalation, lateral movement, persistence, and credential harvesting. Use after obtaining initial shell access. Triggers on: privesc, lateral, pivot, persist |
| recon model: sonnet | Reconnaissance and enumeration specialist. Use when scanning, enumerating ports, fingerprinting services, discovering subdomains, running nuclei vulnerability scans, directory brute-forcing, or buildi |
| report-writer model: opus | Penetration test report writing specialist. Consolidates evidence from all evidence/ directories into professional reports with CVSS scoring, executive summaries, technical findings, remediation roadm |
| reverse-engineer model: opus | Binary reverse engineering and exploit development specialist. Handles static analysis with Ghidra/Radare2, dynamic analysis with GDB/strace, shellcode crafting, ROP chain construction, format string |
| social-engineer model: sonnet | Social engineering and phishing simulation specialist. Handles GoPhish campaign setup, spear-phishing email crafting, evilginx2 adversary-in-the-middle phishing, pretexting scripts, vishing scenarios, |
| threat-hunter model: sonnet | Proactive threat hunting specialist using ATT&CK-based hypotheses. Hunts for lateral movement, persistence, credential dumping, C2 beaconing, data exfiltration, and living-off-the-land techniques acro |
| vuln-researcher model: opus | Vulnerability research and CVE analysis specialist. Handles NVD API queries, searchsploit cross-reference, PoC reliability assessment, CVSS scoring, version fingerprinting, exploit chain research, and |
| web-attacker model: sonnet | Web application penetration testing — SQL injection, XSS, SSRF, LFI, IDOR, JWT attacks, GraphQL, API parameter discovery, and OWASP Top 10 exploitation |
| wireless-attacker model: sonnet | Wireless network penetration testing specialist. Handles WPA2/WPA3 capture and cracking, PMKID attacks, Evil Twin / rogue AP attacks, WPS PIN attacks, EAP/PEAP credential capture, Bluetooth assessment |
Hooks (3)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | python3 .claude/hooks/scope_check.py |
| PostToolUse | Bash | bash .claude/hooks/cmd_log.sh |
| Stop | * | python3 .claude/hooks/findings_sync.py |
Slash commands (6)
/attack/engage/hunt/ir/pwned/report
Permissions
deny (7)
Bash(rm -rf *)
Bash(shred *)
Bash(wipe *)
Bash(dd if=/dev/zero *)
Read(.env)
Read(.env.*)
Read(secrets/**)
ask (0)
—
allow (103)
Bash(nmap *)
Bash(nuclei *)
Bash(amass *)
Bash(subfinder *)
Bash(httpx *)
Bash(feroxbuster *)
Bash(ffuf *)
Bash(sqlmap *)
Bash(hashcat *)
Bash(john *)
Bash(hydra *)
Bash(msfconsole *)
Bash(msfvenom *)
Bash(impacket-GetUserSPNs *)
Bash(impacket-GetNPUsers *)
Bash(impacket-secretsdump *)
Bash(impacket-psexec *)
Bash(impacket-wmiexec *)
Bash(impacket-smbexec *)
Bash(impacket-ntlmrelayx *)
Bash(impacket-ticketer *)
Bash(crackmapexec *)
Bash(bloodhound-python *)
Bash(responder *)
Bash(bettercap *)
Bash(arpspoof *)
Bash(tcpdump *)
Bash(tshark *)
Bash(wireshark *)
Bash(airodump-ng *)
Bash(aireplay-ng *)
Bash(airmon-ng *)
Bash(hcxdumptool *)
Bash(hostapd-wpe *)
Bash(reaver *)
Bash(ghidra *)
Bash(analyzeHeadless *)
Bash(radare2 *)
Bash(r2 *)
Bash(binwalk *)
Bash(strings *)
Bash(objdump *)
Bash(readelf *)
Bash(strace *)
Bash(ltrace *)
Bash(gdb *)
Bash(checksec *)
Bash(frida *)
Bash(frida-ps *)
Bash(adb *)
Bash(apktool *)
Bash(jadx *)
Bash(sliver-client *)
Bash(certipy *)
Bash(enum4linux-ng *)
Bash(ldapdomaindump *)
Bash(onesixtyone *)
Bash(snmpwalk *)
Bash(fierce *)
Bash(dnsx *)
Similar rigs
0xSteph/pentest-ai-agents
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.
Orchestrator 3.1k tok ·
shin-sforzando/dotfiles
My dotfiles managed by chezmoi
YOLO Cowboy 1.5k tok ·
liangdabiao/claude-data-analysis
Create a data analysis AI agent with Claude Code. Make data analysis as simple as having a chat! 别忘了!claude code也是agent框架,类似langgraph,crewAI,autogen等等agent框架。我改造claude code搞一个数据分析智能体AI。 让数据分析变得像聊天一样简单!
Orchestrator 1.2k tok ·
javi-salazar/claudeops-guardrails-demo
Defense-in-depth guardrails starter for Claude Code as an SRE copilot (CLAUDE.md + settings.json + PreToolUse hook). Reference scaffold from the ClaudeOps talk.
Orchestrator 1.4k tok ·