Black Lantern Security
Official@blacklanternsecurity · Charleston, SC
Security Organization
Agent Skills by Black Lantern Security
Showing 77 vetted skills indexed across 1 GitHub repositories.
<skill-name>
Execute defined offensive security techniques against specified targets.
retrospective
Analyze penetration testing engagement logs to identify skill gaps and improvements.
orchestrator
Orchestrate multi-phase penetration tests with operator approval and status updates.
unknown-vector-analysis
Analyze custom applications, scripts, and binaries for unknown exploitation vectors.
password-spraying
Test username-password combinations against SMB, Kerberos, LDAP, SSH, and web forms.
credential-dumping
Automate credential extraction from Active Directory via DCSync, NTDS.dit, and SAM.
adcs-template-abuse
Exploit misconfigured AD CS templates to impersonate domain users via SAN manipulation.
kerberos-ticket-forging
Forge Golden, Silver, Diamond, and Sapphire Kerberos tickets using key materials.
pass-the-hash
Authenticate to Active Directory services using stolen NTLM hashes, AES keys, or Kerberos tickets.
adcs-persistence
Automate AD CS persistence via Golden Certificate forging and certificate theft.
kerberos-delegation
Exploit Kerberos delegation misconfigurations in Active Directory for privilege escalation.
sccm-exploitation
Automate SCCM/MECM enumeration and credential harvesting for lateral movement.
trust-attacks
Enumerate and exploit Active Directory trust relationships for cross-domain privilege escalation.
gpo-abuse
Exploit Active Directory Group Policy Objects for code execution and privilege escalation.
adcs-access-and-relay
Exploit ADCS via ACL abuse and NTLM relay to enrollment endpoints.
auth-coercion-relay
Automates PetitPotam, PrinterBug and DFSCoerce authentication coercion attacks with NTLM/Kerberos relay to SMB, LDAP, AD CS targets.
ad-persistence
Establish persistent Active Directory access using DCShadow, Skeleton Key, and Golden SAML.
acl-abuse
Exploit misconfigured Active Directory ACLs for privilege escalation.
ad-discovery
Enumerate Active Directory domains and map attack surfaces for penetration testing.
kerberos-roasting
Extract and crack Kerberos service tickets and AS-REP hashes for offline password recovery.
av-edr-evasion
Compile custom C and Go payloads to bypass antivirus and EDR detection.
ssrf
Guide SSRF exploitation across HTTP, HTTPS, file, gopher, and dict protocols.
web-discovery
Discover web application injection points and test for common vulnerability classes.
sql-injection-stacked
Exploit stacked query and second-order SQL injection across MSSQL, PostgreSQL, MySQL, and Oracle.
Frequently Asked Questions About Black Lantern Security
FAQPage SchemaWhat specific security tasks are enabled by these methodologies?▼
These methodologies enable comprehensive penetration testing, including Active Directory domain enumeration, credential harvesting, web application injection testing, and post-exploitation privilege escalation. They facilitate the identification of misconfigurations in Kerberos, AD CS, and web frameworks to validate organizational security posture.
Which technical personas benefit from these security techniques?▼
These techniques are designed for penetration testers, red team operators, and security researchers. They provide actionable frameworks for professionals tasked with identifying vulnerabilities in Windows environments, Linux systems, and complex web application architectures.
What are the prerequisites for implementing these security assessments?▼
Implementation requires authorized access to the target environment and a foundational understanding of network protocols, Windows internals, and web request structures. Operators must ensure all activities are conducted within the scope of a formal penetration testing engagement or security audit.