By s3cr1z
BloodHound Enterprise integration via the v2 REST API. HMAC-signed requests (long-lived integration) or JWT bearer (interactive); full coverage of attack-path findings, asset groups + tier-zero curation, AD/Azure/OpenGraph entity walks, raw + saved Cypher, data ingestion (SharpHound/AzureHound uploads), posture trending, and audit logs. Complementary to the existing bloodhound capability — that one talks Bolt to a local CE Neo4j; this one talks REST to a hosted BHE deployment.
Based on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Specialist agent for attack-path triage. Takes a domain (or "all domains") and produces a ranked, evidence-backed list of findings worth remediating. Use when the caller wants attack-path work specifically — not a general audit, not a Cypher investigation, not data ingestion.
Top-level BloodHound Enterprise analyst. Accepts open-ended questions about an Active Directory or Azure environment ("audit our Tier Zero", "what attack paths are active in this domain", "produce a posture report") and routes to the appropriate skill. Use this agent as the entrypoint when the task isn't already narrow enough to call a specialist directly.
Specialist for Tier Zero hygiene — audits asset-group-tag membership, certifies deliberate inclusions, surfaces drift, and catches shadow changes via the audit log. Use when Tier Zero is the explicit subject of the request, when the caller suspects a tier was modified incorrectly, or as a periodic hygiene cycle.
Open-ended graph investigation via raw OpenCypher queries. Use when the prebuilt tools don't capture the question — bespoke "find every X that can reach Y via Z" queries, ad-hoc relationship walks, novel attack-path patterns, or one-off exports for analysis. Read-only by default; writes require explicit opt-in.
Push SharpHound / AzureHound collection data into a BloodHound Enterprise deployment, monitor the ingest pipeline, and confirm the graph is updated. Use when the caller has fresh collection output to load, when the deployment's posture data is stale, or when the caller asks "ingest these files", "upload SharpHound output", "push collection data".
Compare BHE posture between two points in time — what got better, what got worse, and which specific findings drove the change. Use when the caller asks "how have we improved", "what changed since last week", "produce a trend report", or at the close of a remediation cycle.
Audit the Tier Zero asset group — list members, validate that every inclusion is intentional, identify drift since the last audit, and certify or revoke certifications as needed. Use when the caller asks "audit Tier Zero", "review the tier list", "who's in Tier Zero and why", or after Tier Zero membership changes are reported in the audit log.
Investigate a single AD or Azure principal — who controls it, what it controls, where it has admin rights, and what's reachable via its credentials. Use when the caller asks "tell me about this user", "what does X have access to", "who can compromise Y", or when triaging a finding tied to a specific principal.
Uses power tools
Uses Bash, Write, or Edit tools
This is the source repo for the capabilities Dreadnode publishes to app.dreadnode.io. A capability is a directory — a manifest plus any combination of agents, tools, skills, and MCP servers — that a Dreadnode runtime picks up and loads:
ai-red-teaming/
capability.yaml # manifest
agents/ # markdown prompts
tools/ # python @tool functions
skills/ # SKILL.md packs
dn capability install dreadnode/ai-red-teaming (swap in any name from capabilities/)dn capability install ./capabilities/ai-red-teaming symlinks the directory into your runtime, so edits go live on reloaddn, press Ctrl+P, filter for dreadnode/dn is the Dreadnode CLI — see getting-started to install and authenticate. Full install reference for capabilities lives at docs.dreadnode.io/capabilities/installing.
Every directory under capabilities/ is a shipped, working example. Read one alongside the docs:
Every skill in this repo is scanned with cisco-ai-defense/skill-scanner for prompt injection, data exfiltration, tool-chaining abuse, and supply chain risk. CI fails on HIGH+ findings and uploads SARIF reports to GitHub Code Scanning. The repo policy in scan-policy.yaml tunes the scanner for security-focused content.
just security-scan # scan all capabilities
just security-scan web-security # scan one capability
just security-scan behavioral="true" # deep dataflow analysis
This repo is published for reference, not as a contribution target — we don't generally accept external PRs that add new capabilities. See CONTRIBUTING.md for what's useful to send and how to build your own capabilities instead.
Each capability declares its license in its capability.yaml.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimnpx claudepluginhub s3cr1z/capabilities --plugin bloodhound-enterpriseMemory forensics and DFIR triage via Volatility3. Curated tools for process enumeration, network artifacts, code injection, credential extraction, registry analysis, and YARA over memory images, plus playbooks for triage, injection / credential / persistence hunts, and YARA-based IoC sweeping.
BloodHound CE integration for Active Directory attack path analysis. Graph-based queries against Neo4j for domain enumeration, tier zero identification, Kerberos attack surfaces, delegation abuse, PKI/ADCS vulnerabilities, and Azure/Entra attack paths.
Read-only GhostWriter integration. Query clients, projects, findings, objectives, targets, scope, deconflictions, evidence, observations, reports, infrastructure (servers and domains), activity logs, white cards, and notes without modifying any GhostWriter state.
.NET reverse engineering for decompiling and analyzing assemblies (.dll, .exe). Provides binary scanning, namespace exploration, type decompilation, reference search, and call flow tracing via ILSpy.
Web application penetration testing with 30+ attack technique playbooks covering request smuggling, cache poisoning, SSRF, SSTI, DOM vulnerabilities, authentication bypasses, parser differentials, and client-side attacks. Includes HTTP client tooling, Caido proxy integration via MCP, credential management, DNS rebinding, phone verification, and vulnerability verification.
Complete creative writing suite with 10 specialized agents covering the full writing process: research gathering, character development, story architecture, world-building, dialogue coaching, editing/review, outlining, content strategy, believability auditing, and prose style/voice analysis. Includes genre-specific guides, templates, and quality checklists.
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
A growing collection of Claude-compatible academic workflow bundles. Covers scientific figures, manuscript writing and polishing, reviewer assessment, citation retrieval, data availability, paper reading, literature search, response letters, paper-to-PPTX conversion, and evidence-grounded Chinese invention patent drafting. Rules are organized as reusable skill folders with explicit workflows and quality checks.
Upstash Context7 MCP server for up-to-date documentation lookup. Pull version-specific documentation and code examples directly from source repositories into your LLM context.
Intelligent draw.io diagramming plugin with AI-powered diagram generation, multi-platform embedding (GitHub, Confluence, Azure DevOps, Notion, Teams, Harness), conditional formatting, live data binding, and MCP server integration for programmatic diagram creation and management.
Comprehensive startup business analysis with market sizing (TAM/SAM/SOM), financial modeling, team planning, and strategic research