blacklanternsecurityblacklanternsecurityOfficialยท77 Agent Skills Included

red-run

Autonomous penetration testing, CTF solving, and exploit chaining

Orchestrates full penetration tests and CTF challenges across recon, exploitation, privilege escalation, and lateral movement. Coordinates persistent domain teammates that run 67+ technique skills covering web, Active Directory, and credential attacks. Tracks engagement state in SQLite, routes skills via semantic search, and eliminates manual scan-and-pivot workflows.
npx skills add blacklanternsecurity/red-run --all -g -y
Available:

Instructs the agent on how to orchestrate engagements as a team lead, route findings to technique skills via the skill-router, delegate execution to persistent domain teammates, and enforce state management and operational safety rules.

All Skills in This Repository (77)

Pure Emerald Level Indicators
๐Ÿ“ฆ In Repo
blacklanternsecurityblacklanternsecurity

<skill-name>

Execute defined offensive security techniques against specified targets.

Official
Advanced
๐Ÿ“ฆ In Repo
blacklanternsecurityblacklanternsecurity

retrospective

Analyze penetration testing engagement logs to identify skill gaps and improvements.

Official
Advanced
๐Ÿ“ฆ In Repo
blacklanternsecurityblacklanternsecurity

orchestrator

Orchestrate multi-phase penetration tests with operator approval and status updates.

Official
Advanced
๐Ÿ“ฆ In Repo
blacklanternsecurityblacklanternsecurity

unknown-vector-analysis

Analyze custom applications, scripts, and binaries for unknown exploitation vectors.

Official
Advanced
๐Ÿ“ฆ In Repo
blacklanternsecurityblacklanternsecurity

password-spraying

Test username-password combinations against SMB, Kerberos, LDAP, SSH, and web forms.

Official
Advanced
๐Ÿ“ฆ In Repo
blacklanternsecurityblacklanternsecurity

credential-dumping

Automate credential extraction from Active Directory via DCSync, NTDS.dit, and SAM.

Official
Advanced
๐Ÿ“ฆ In Repo
blacklanternsecurityblacklanternsecurity

adcs-template-abuse

Exploit misconfigured AD CS templates to impersonate domain users via SAN manipulation.

Official
Advanced
๐Ÿ“ฆ In Repo
blacklanternsecurityblacklanternsecurity

kerberos-ticket-forging

Forge Golden, Silver, Diamond, and Sapphire Kerberos tickets using key materials.

Official
Advanced
๐Ÿ“ฆ In Repo
blacklanternsecurityblacklanternsecurity

pass-the-hash

Authenticate to Active Directory services using stolen NTLM hashes, AES keys, or Kerberos tickets.

Official
Advanced
๐Ÿ“ฆ In Repo
blacklanternsecurityblacklanternsecurity

adcs-persistence

Automate AD CS persistence via Golden Certificate forging and certificate theft.

Official
Advanced
๐Ÿ“ฆ In Repo
blacklanternsecurityblacklanternsecurity

kerberos-delegation

Exploit Kerberos delegation misconfigurations in Active Directory for privilege escalation.

Official
Advanced
๐Ÿ“ฆ In Repo
blacklanternsecurityblacklanternsecurity

sccm-exploitation

Automate SCCM/MECM enumeration and credential harvesting for lateral movement.

Official
Advanced

Frequently Asked Questions

FAQPage Schema
How to install red-run?โ–ผ

Run `npx skills add blacklanternsecurity/red-run --all -g -y` in your terminal to install all skills in this suite globally.

What does red-run do?โ–ผ

It runs autonomous penetration tests and CTF challenges by coordinating agent teammates that perform recon, exploitation, privilege escalation, and lateral movement. A lead orchestrator routes findings to 67+ technique skills and tracks all progress in a persistent state database.

How do I start an engagement with red-run?โ–ผ

After installing, run ./run.sh and send a target IP to activate the /red-run-ctf orchestrator. It presents routing decisions for your approval before assigning any task to a teammate.

Does red-run work with Claude Code agent teams?โ–ผ

Yes. It is built on Claude Code agent teams, spawning persistent domain teammates in separate tmux panes that you can watch, interrupt, and redirect in real time.

Is red-run safe to use on production systems?โ–ผ

No. It is designed for CTF and lab environments with explicit written authorization, runs with no stealth considerations, and must never be used against systems you do not own or have permission to test.

Related Repositories in Software Engineering

View All in Software Engineeringโ†’