feat(agents): deep Active Directory suite — 25 host/infra skills + 7 AD chains

Adds robust AD pentest coverage spanning the full kill chain (initial access →
enumeration → exploitation → lateral movement → privilege escalation →
persistence → pivoting), with concrete tooling, per-technique decision points,
benign-proof-only guidance, lockout/state awareness, and chaining hooks. All
GENERIC — no lab-specific hosts/IPs/creds/flags; works in any AD environment.

New infra/ skills: ad_recon_enum, ad_bloodhound_paths, ad_llmnr_poisoning,
ad_ntlm_relay, ad_password_spray, ad_kerberos_delegation, ad_adcs_esc,
ad_pth_ptt, ad_coerce_auth, ad_critical_cve (Zerologon/noPac), ad_smb_share_hunt,
ad_laps_gmsa_read, ad_gpo_abuse, ad_dpapi_looting, ad_trust_abuse,
ad_persistence_review, ad_mssql_abuse. Enriched: ad_kerberoasting, ad_asreproasting,
ad_dcsync, ad_acl_privesc, ad_default_creds, windows_priv_esc.

New chains/: chain_ad_web_to_forest_root, chain_ad_rbcd_s4u_to_adcs,
chain_ad_coerce_relay_adcs, chain_ad_kerberoast_to_domain,
chain_ad_mssql_linked_pivot, chain_ad_trust_cross_forest, chain_ad_local_to_domain.

attack_graph: map CWE-294/295/1392/269 to OWASP/MITRE/stage + CVSS bands so AD
findings grade and place in the kill chain correctly. 473 agents, 421 tests.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 4.8 committed 2026-10-03 01:08:57 -03:00
1 parent 8051464a84
commit 7741290193
32 files changed
+1479 -86

No files matched your search

+7 -5
View File
@@ -11,7 +11,7 @@
<img src="https://img.shields.io/badge/Version-4.2.1-blue?style=flat-square">
<img src="https://img.shields.io/badge/Harness-Rust%20%7C%20tokio-e6b673?style=flat-square">
<img src="https://img.shields.io/badge/License-MIT-green?style=flat-square">
<img src="https://img.shields.io/badge/MD%20Agents-458-red?style=flat-square">
<img src="https://img.shields.io/badge/MD%20Agents-473-red?style=flat-square">
<img src="https://img.shields.io/badge/Models-19%20providers-success?style=flat-square">
<img src="https://img.shields.io/badge/Modes-Black%20%7C%20White%20%7C%20Grey%20%7C%20Host%20%7C%20AI%20%7C%20Mobile%20%7C%20Container-9cf?style=flat-square">
<img src="https://img.shields.io/badge/Auth-API%20key%20%7C%20Subscription-orange?style=flat-square">
@@ -32,7 +32,7 @@ LLMs** — via **API key** or local **subscription** (Claude Code / Codex / Gemi
Grok) — recons the target, **intelligently selects only the agents that match the
discovered surface**, runs them in parallel, **chains** findings into deeper
impact, and **validates every claim by cross-model voting + tool-receipt
grounding** before reporting. It ships **435 markdown agents** and a **Mission
grounding** before reporting. It ships **473 markdown agents** and a **Mission
Control TUI**.
### Engagement modes
@@ -60,6 +60,8 @@ Control TUI**.
> every object identifier it sees (ids, UUIDs, tokens, emails) into a reference
> pool and substitutes them across identities and endpoints, the core of
> reliable BOLA / IDOR / mass-assignment discovery.
>
> Also a deep **Active Directory** suite: 25+ host/infra skills and 7 multi-stage AD chains covering the full kill chain — initial access, enumeration (BloodHound), Kerberoasting/AS-REP, NTLM relay + coercion (PetitPotam/PrinterBug), delegation abuse (unconstrained/constrained/RBCD + S4U), AD CS (ESC1-ESC13), MSSQL linked-server pivoting, DCSync, cross-forest trust abuse (SID history/trust keys), and persistence (detect-and-report). Lockout- and state-aware, benign-proof-only.
> **New in v4.2.0** — **binary / APK / IPA testing**: a new `mobile` mode analyses
> a local artifact with 12 reverse-engineering skills (static binary triage,
@@ -85,7 +87,7 @@ Control TUI**.
> (`--compliance pci-dss,hipaa,soc2`); an **internal-network / AD attack graph**;
> a **reasoning-budget governor** (`--budget`); and **TypeSafe System One**
> (`--typesafe on|off|auto`) as a calibrated confirmation + adjudication layer.
> 27 deterministic per-CWE validators, 446 agents.
> 27 deterministic per-CWE validators, 473 agents.
- 🧠 **POMDP belief + anti-hallucination gate** — findings aren't booleans; a
property-graph belief carries probabilities, and `may_assert` refuses to claim
@@ -238,7 +240,7 @@ Zero npm dependencies (Node built-ins only).
out-of-scope) → Leads (the 435-agent board below) → Model & Run (provider/model picker,
API-key vs. subscription toggle, votes/chain-depth/recon) → Review. Every engagement is named
up front, so runs are identifiable in history instead of by raw target string.
- **Lead board** — all 435 agents auto-categorized (Business Logic, Broken Access Control,
- **Lead board** — all 473 agents auto-categorized (Business Logic, Broken Access Control,
Injection, LLM Application, Auth & Session, SSRF & Network, Cloud & Infra, …). Toggle a single
lead, a whole category (indeterminate when partially selected), or use **Select all / Clear
all** — respects the active search filter. Leave everything off to let the harness's own
@@ -980,7 +982,7 @@ Every run writes a self-contained folder `runs/ns-<ts>-<target>/`:
A reinforcement-learning reward store (`data/rl_state_rs.json`) biases agent
selection on future runs.
## Agent library — `agents_md/` (446)
## Agent library — `agents_md/` (473)
| Category | Count | Purpose |
|----------|-------|---------|