~ / rigs / mukul975 / Threatswarm

mukul975/Threatswarm

27 scope-enforced AI agents that run the full pentest kill-chain (recon → exploit → post-ex → DFIR → report) as a one-command Claude Code plugin. Backed by 754 MITRE-mapped skills.

↗ GitHub ★ 84 mit updated 5mo ago project Claude Code Claude plugin
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~6.3k tokens
Heavy · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit mukul975/Threatswarm/.claude ./rig-threatswarm  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit mukul975/Threatswarm/.claude/skills/ad-attacks .claude/skills/ad-attacks
$ npx degit mukul975/Threatswarm/.claude/skills/exploit-db .claude/skills/exploit-db
$ npx degit mukul975/Threatswarm/.claude/skills/mitre-attack .claude/skills/mitre-attack
$ npx degit mukul975/Threatswarm/.claude/skills/report-templates .claude/skills/report-templates
$ npx degit mukul975/Threatswarm/.claude/skills/wordlists .claude/skills/wordlists
$ curl -fsSL --create-dirs -o .claude/agents/active-directory.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/active-directory.md
$ curl -fsSL --create-dirs -o .claude/agents/api-attacker.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/api-attacker.md
$ curl -fsSL --create-dirs -o .claude/agents/blue-team.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/blue-team.md
$ curl -fsSL --create-dirs -o .claude/agents/c2-operator.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/c2-operator.md
$ curl -fsSL --create-dirs -o .claude/agents/cloud-attacker.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/cloud-attacker.md
$ curl -fsSL --create-dirs -o .claude/agents/compliance-scanner.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/compliance-scanner.md
$ curl -fsSL --create-dirs -o .claude/agents/container-attacker.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/container-attacker.md
$ curl -fsSL --create-dirs -o .claude/agents/crypto-attacker.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/crypto-attacker.md
$ curl -fsSL --create-dirs -o .claude/agents/dfir.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/dfir.md
$ curl -fsSL --create-dirs -o .claude/agents/evasion.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/evasion.md
$ curl -fsSL --create-dirs -o .claude/agents/exploit.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/exploit.md
$ curl -fsSL --create-dirs -o .claude/agents/iot-attacker.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/iot-attacker.md
$ curl -fsSL --create-dirs -o .claude/agents/log-analyst.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/log-analyst.md
$ curl -fsSL --create-dirs -o .claude/agents/malware-analyst.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/malware-analyst.md
$ curl -fsSL --create-dirs -o .claude/agents/mobile-attacker.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/mobile-attacker.md
$ curl -fsSL --create-dirs -o .claude/agents/network-ops.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/network-ops.md
$ curl -fsSL --create-dirs -o .claude/agents/osint.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/osint.md
$ curl -fsSL --create-dirs -o .claude/agents/password-attacks.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/password-attacks.md
$ curl -fsSL --create-dirs -o .claude/agents/post-ex.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/post-ex.md
$ curl -fsSL --create-dirs -o .claude/agents/recon.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/recon.md
$ curl -fsSL --create-dirs -o .claude/agents/report-writer.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/report-writer.md
$ curl -fsSL --create-dirs -o .claude/agents/reverse-engineer.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/reverse-engineer.md
$ curl -fsSL --create-dirs -o .claude/agents/social-engineer.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/social-engineer.md
$ curl -fsSL --create-dirs -o .claude/agents/threat-hunter.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/threat-hunter.md
$ curl -fsSL --create-dirs -o .claude/agents/vuln-researcher.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/vuln-researcher.md
$ curl -fsSL --create-dirs -o .claude/agents/web-attacker.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/web-attacker.md
$ curl -fsSL --create-dirs -o .claude/agents/wireless-attacker.md https://raw.githubusercontent.com/mukul975/Threatswarm/main/.claude/agents/wireless-attacker.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(rm -rf *)",
      "Bash(shred *)",
      "Bash(wipe *)",
      "Bash(dd if=/dev/zero *)",
      "Read(.env)",
      "Read(.env.*)",
      "Read(secrets/**)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "python3 .claude/hooks/scope_check.py"
          }
        ]
      }
    ]
  }
}

Skills (5)

Subagents (27)

active-directory
model: opus
Active Directory and Windows domain attack specialist. Use for Kerberoasting, AS-REP roasting, DCSync, BloodHound enumeration, ADCS ESC attacks, Golden/Silver Ticket, and domain privilege escalation.
api-attacker
model: sonnet
API security testing specialist for REST, GraphQL, gRPC, and WebSocket APIs. Handles BOLA/IDOR, mass assignment, authentication bypass, rate limit evasion, JWT attacks, GraphQL introspection abuse, AP
blue-team
model: sonnet
Defensive security and hardening specialist. Creates detection rules, hardens Linux/Windows systems, writes Sigma rules, configures auditd, fail2ban, Sysmon, and provides CIS benchmark remediation gui
c2-operator
model: opus
Command and control infrastructure specialist for authorized red team operations. Handles Sliver C2 framework, Havoc C2, Metasploit multi-handler, msfvenom payload generation, implant configuration, H
cloud-attacker
model: sonnet
Cloud penetration testing specialist for AWS, Azure, and GCP. Handles IAM enumeration, privilege escalation, S3 bucket abuse, metadata SSRF, Pacu framework, container escape to cloud, and cloud-native
compliance-scanner
model: sonnet
Compliance and security standards assessment specialist. Handles CIS benchmarks, PCI-DSS controls, NIST CSF, SOC2, GDPR technical controls, OpenSCAP assessments, Docker CIS bench, Kubernetes CIS bench
container-attacker
model: sonnet
Container and Kubernetes security specialist. Handles Docker escape techniques, Kubernetes RBAC abuse, service account token theft, kubelet API exploitation, etcd access, namespace breakout, and cloud
crypto-attacker
model: opus
Cryptography and TLS security specialist. Handles TLS configuration auditing, JWT algorithm confusion, padding oracle attacks, hash cracking mode selection, RSA weak key analysis, ECB mode detection,
dfir
model: opus
Digital forensics and incident response specialist. Handles triage, memory acquisition with AVML/LiME, Volatility analysis, log timeline reconstruction, IOC extraction, persistence hunting, and incide
evasion
model: opus
Antivirus and EDR evasion specialist for authorized red team engagements. Handles AMSI bypass, payload obfuscation, living-off-the-land techniques, sandbox detection, process injection concepts, and d
exploit
model: opus
Exploitation specialist for gaining initial access. Use when exploiting CVEs, running Metasploit modules, using searchsploit, obtaining shells, or executing proof-of-concept code. Triggers on: exploit
iot-attacker
model: sonnet
IoT and embedded systems security specialist. Handles firmware extraction and analysis, hardcoded credential discovery, UART/JTAG access, MQTT/CoAP protocol testing, RouterSploit exploitation, web int
log-analyst
model: sonnet
Security log analysis specialist. Parses and correlates auth.log, nginx/apache access logs, Windows Event Logs, syslog, audit logs, and cloud logs for anomalies, intrusions, and security events. Gener
malware-analyst
model: opus
Malware analysis specialist for static and dynamic analysis. Handles PE/ELF/APK binary triage, behavioral analysis, IOC extraction, YARA rule writing, C2 protocol reverse engineering, deobfuscation, s
mobile-attacker
model: sonnet
Mobile application security specialist for Android and iOS. Handles APK decompilation, static/dynamic analysis, Frida instrumentation, SSL pinning bypass, ADB shell exploitation, MobSF scanning, traff
network-ops
model: sonnet
Network penetration testing specialist for ARP attacks, MitM, packet capture, SNMP enumeration, SMB relay, Responder credential capture, and network-level attacks. Triggers on: ARP, MitM, sniff, inter
osint
model: sonnet
Open source intelligence specialist for passive reconnaissance. Handles domain intelligence, certificate transparency, Shodan enumeration, email harvesting, GitHub dorking, employee profiling, ASN/IP
password-attacks
model: sonnet
Password cracking and credential attack specialist. Use when working with password hashes, hash cracking, wordlist attacks, credential analysis, or password auditing. Triggers on: password, hash, crac
post-ex
model: opus
Post-exploitation specialist for privilege escalation, lateral movement, persistence, and credential harvesting. Use after obtaining initial shell access. Triggers on: privesc, lateral, pivot, persist
recon
model: sonnet
Reconnaissance and enumeration specialist. Use when scanning, enumerating ports, fingerprinting services, discovering subdomains, running nuclei vulnerability scans, directory brute-forcing, or buildi
report-writer
model: opus
Penetration test report writing specialist. Consolidates evidence from all evidence/ directories into professional reports with CVSS scoring, executive summaries, technical findings, remediation roadm
reverse-engineer
model: opus
Binary reverse engineering and exploit development specialist. Handles static analysis with Ghidra/Radare2, dynamic analysis with GDB/strace, shellcode crafting, ROP chain construction, format string
social-engineer
model: sonnet
Social engineering and phishing simulation specialist. Handles GoPhish campaign setup, spear-phishing email crafting, evilginx2 adversary-in-the-middle phishing, pretexting scripts, vishing scenarios,
threat-hunter
model: sonnet
Proactive threat hunting specialist using ATT&CK-based hypotheses. Hunts for lateral movement, persistence, credential dumping, C2 beaconing, data exfiltration, and living-off-the-land techniques acro
vuln-researcher
model: opus
Vulnerability research and CVE analysis specialist. Handles NVD API queries, searchsploit cross-reference, PoC reliability assessment, CVSS scoring, version fingerprinting, exploit chain research, and
web-attacker
model: sonnet
Web application penetration testing — SQL injection, XSS, SSRF, LFI, IDOR, JWT attacks, GraphQL, API parameter discovery, and OWASP Top 10 exploitation
wireless-attacker
model: sonnet
Wireless network penetration testing specialist. Handles WPA2/WPA3 capture and cracking, PMKID attacks, Evil Twin / rogue AP attacks, WPS PIN attacks, EAP/PEAP credential capture, Bluetooth assessment

Hooks (3)

eventmatcherruns
PreToolUseBashpython3 .claude/hooks/scope_check.py
PostToolUseBashbash .claude/hooks/cmd_log.sh
Stop*python3 .claude/hooks/findings_sync.py

Slash commands (6)

/attack/engage/hunt/ir/pwned/report

Permissions

deny (7)
Bash(rm -rf *)
Bash(shred *)
Bash(wipe *)
Bash(dd if=/dev/zero *)
Read(.env)
Read(.env.*)
Read(secrets/**)
ask (0)
—
allow (103)
Bash(nmap *)
Bash(nuclei *)
Bash(amass *)
Bash(subfinder *)
Bash(httpx *)
Bash(feroxbuster *)
Bash(ffuf *)
Bash(sqlmap *)
Bash(hashcat *)
Bash(john *)
Bash(hydra *)
Bash(msfconsole *)
Bash(msfvenom *)
Bash(impacket-GetUserSPNs *)
Bash(impacket-GetNPUsers *)
Bash(impacket-secretsdump *)
Bash(impacket-psexec *)
Bash(impacket-wmiexec *)
Bash(impacket-smbexec *)
Bash(impacket-ntlmrelayx *)
Bash(impacket-ticketer *)
Bash(crackmapexec *)
Bash(bloodhound-python *)
Bash(responder *)
Bash(bettercap *)
Bash(arpspoof *)
Bash(tcpdump *)
Bash(tshark *)
Bash(wireshark *)
Bash(airodump-ng *)
Bash(aireplay-ng *)
Bash(airmon-ng *)
Bash(hcxdumptool *)
Bash(hostapd-wpe *)
Bash(reaver *)
Bash(ghidra *)
Bash(analyzeHeadless *)
Bash(radare2 *)
Bash(r2 *)
Bash(binwalk *)
Bash(strings *)
Bash(objdump *)
Bash(readelf *)
Bash(strace *)
Bash(ltrace *)
Bash(gdb *)
Bash(checksec *)
Bash(frida *)
Bash(frida-ps *)
Bash(adb *)
Bash(apktool *)
Bash(jadx *)
Bash(sliver-client *)
Bash(certipy *)
Bash(enum4linux-ng *)
Bash(ldapdomaindump *)
Bash(onesixtyone *)
Bash(snmpwalk *)
Bash(fierce *)
Bash(dnsx *)

Similar rigs

copied ✓