SkillAtlasSkill 详情

mid-engagement-ir-detection

A self-contained Claude skill bundle for bug hunting and external red-team work · 82 skills · 15...

审核状态:已审核Quality 72Security 70

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年8月4日

claude-bughunter banner

claude-bughunter

A self-contained Claude skill bundle for bug hunting and external red-team work · 82 skills · 15 slash commands · 681 disclosed-report patterns across 24 core vulnerability classes · enterprise identity + infrastructure attack matrices · engagement-folder scaffolding · Burp MCP integration · battle-tested across authorized red-team and bug-hunting engagements, plus public training platforms (DVWA, OWASP Juice Shop, Hacker101, testphp.vulnweb.com).

Built by Sachin Sharma — Bug Hunting & GenAI Security Research.

SPONSORED BY
Atlas Cloud


What is this?

claude-bughunter is a drop-in skill bundle for the Claude Code skills system. Install once and Claude Code stops being a chatbot and starts behaving like a senior bug-hunting researcher or red-team operator: it knows the techniques, the chain templates, the VRT mappings, the platform CVE chains, and the hygiene — and it stays in scope.

Four layers stack:

  • Think — bb-methodology + redteam-mindset: the 5-phase non-linear workflow, critical-thinking framework, and red-team operator discipline.
  • Hunt webapps — 48 hunt-* skills curated from 681 disclosed HackerOne reports: per-class detection patterns, payloads, bypass tables, and chain templates.
  • Hit the perimeter — enterprise platform chains (M365/Entra, Okta, vCenter, SSL-VPN appliances, SharePoint, cloud IAM): current 2024–2026 CVE chains + post-credential escalation.
  • Ship it — triage-validation + reporting + evidence-hygiene: the 7-Question Gate, VRT-aware severity, OOS rebuttals, PII redaction, and red-team deliverables.

All triggered automatically by topic — describe what you're testing in plain English and the relevant skill loads. No invocation by name.


Quickstart

Option A — install as a Claude Code plugin (recommended). From inside Claude Code:

/plugin marketplace add elementalsouls/Claude-BugHunter
/plugin install claude-bughunter@elementalsouls

All 82 skills + 15 commands load namespaced under claude-bughunter: and update when you bump the plugin version — no files copied into ~/.claude/.

Option B — copy install (no plugin system / pin to a clone):

git clone https://github.com/elementalsouls/Claude-BugHunter.git
cd Claude-BugHunter
# macOS / Linux
bash scripts/install.sh

# Windows (PowerShell)
pwsh ./scripts/install.ps1

Both copy the skills + commands into ~/.claude/ (macOS/Linux) or %USERPROFILE%\.claude\ (Windows) and wire the hunt engagement scaffolder.

What each install path gives you:

Path82 skills + 15 slash commandscbh CLIhunt scaffolder
A — plugin✅ namespaced under claude-bughunter:➕ separate pipx install❌ clone-only
B — copy install✅ copied into ~/.claude/✅ from the clone✅ from the clone

The plugin is the fastest path to the skills + slash commands. The terminal-native cbh runner installs standalone — pipx install git+https://github.com/elementalsouls/Claude-BugHunter — so plugin users can add it without a full clone (see cbh CLI). The hunt engagement scaffolder ships with the clone (Option B).

That's it. Open Claude Code and describe what you're testing in plain English — the right skill loads automatically, no invocation by name:

> Testing acme.com — an in-scope HackerOne target. Run recon and rank the surface.

  ⟳ loading skills: web2-recon, offensive-osint, bb-methodology …
    → subdomain enum (subfinder + crt.sh) … 47 hosts
    → live hosts (httpx) … 12 · tech fingerprint … 6 distinct stacks
    → ranked surface: api.acme.com (GraphQL, introspection ON)  ← start here
                      auth.acme.com (OAuth, SSO)               ← hunt-oauth

  Next: want me to probe the GraphQL introspection + OAuth redirect_uri?

→ Full Installation guide · Usage guide · searchable skill catalog.

The block above is an illustrative transcript. To record a real demo of your own session: asciinema rec demo.cast → upload to asciinema.org and drop the badge here.


Runs on four harnesses

One install, four agent harnesses — Claude Code, OpenCode, Codex CLI, Hermes Agent

The skills are plain Agent Skills — the same SKILL.md format that Claude Code · OpenCode · OpenAI Codex CLI · Hermes Agent all load. One command installs them everywhere:

# macOS / Linux
bash scripts/install.sh --all --burp-mcp

# Windows (PowerShell)
pwsh ./scripts/install.ps1 -All -BurpMcp

--all (-All) copies the skills to every harness's path (~/.claude/skills, ~/.agents/skills, ~/.hermes/skills); --burp-mcp (-BurpMcp) wires the Burp MCP server into each. The full knowledge layer ports to all four — the slash commands and /hunt engine stay Claude-Code-only by design.

→ Multi-harness guide


Star History

Star history chart for Claude-BugHunter

Chart is self-hosted — regenerate with python3 scripts/gen_star_history.py (needs gh auth login). Refreshes automatically each Monday via .github/workflows/star-history.yml.


Scope — what this bundle is for, and what it isn't

This bundle covers the external attack surface — anything reachable from the internet without first compromising an internal endpoint.

In scope

  • Bug bounty hunting — web apps, APIs, SaaS, GraphQL, OAuth, JWT, file upload, IDOR, SSRF, RCE chains
  • Web application pentesting — full hunt-* coverage of OWASP-mapped bug classes + discipline rules
  • External red-team engagements — initial-access against internet-facing enterprise estate: M365 / Entra ID, Okta-as-IdP, SharePoint on-prem (ToolShell + legacy SOAP), VMware vCenter / Workspace ONE, SSL VPN appliances (Cisco / Fortinet / Citrix / Palo Alto / Pulse / SonicWall / F5), Android APK red-team, supply-chain recon
  • Cloud misconfig + post-credential escalation — public S3, IMDS chains, STS AssumeRole, cross-account confused-deputy
  • Recon + OSINT — subdomain enum, identity-fabric mapping, certificate transparency, JS analysis, secret scanning
  • Reporting — H1, Bugcrowd (VRT-aware), Intigriti, Immunefi, plus client-facing red-team deliverable format

Out of scope (deliberate — not gaps, design decisions)

  • Internal Active Directory attacks — BloodHound, Kerberoasting, ASREProast, DCSync, Pass-the-Hash, AD CS abuse, ntlmrelayx, Responder, PetitPotam, etc. Different operational risk profile; needs different tooling and judgment. Future bundle, not this one.
  • C2 frameworks — Cobalt Strike, Sliver, Mythic, Havoc, BRC4 tradecraft. Out of scope for external-only engagement model.
  • Post-exploit / persistence / lateral — Mimikatz/comsvcs LSASS dumping, golden/silver tickets, named-pipe impersonation, persistence (registry, scheduled tasks, WMI events, COM hijacking), token theft. These start after the perimeter has already broken — different bundle territory.
  • Evasion — AMSI bypass, ETW patching, AV/EDR bypass. Tied to C2 tradecraft above.
  • iOS pentesting / hardware / RF / ICS — out of scope by design.
  • Binary exploitation / kernel pwn / browser internals — different skill universe.

If you're running an internal red team that includes domain-takeover chains via Kerberos or lateral movement, this bundle won't help you in those phases — and we'd rather say that up front than have you find out mid-engagement. The external surface handoff to internal-RT tooling (Impacket, NetExec, CrackMapExec, Rubeus, Certify, BloodHound) is intentionally outside our scope. Coverage for internal AD and post-exploit may come in a future update.


What's inside

82 skills, auto-loaded by topic — no invocation by name. Coverage across the external attack surface:

Category#Examples
Web application hunting13XSS, SQLi, SSRF, IDOR, LFI, SSTI, XXE, CSRF, CORS, open-redirect
Authentication & identity7auth-bypass, session, OAuth, SAML, MFA-bypass, ATO
API & infrastructure15GraphQL, gRPC, WebSocket, API-misconfig, host-header, RCE
Advanced & concurrency6race-condition, HTTP smuggling, deserialization, cache-poison
Framework-specific4Next.js, Node.js, Laravel, Spring Boot
Enterprise identity & cloud ★3M365/Entra, Okta, cloud-IAM-deep
Infrastructure & appliance ★4VMware vCenter, enterprise VPN, SharePoint, ASP.NET/NTLM
Red-team tradecraft ★4redteam-mindset, APK pipeline, supply-chain recon, mid-engagement IR
Recon & OSINT4web2-recon, offensive-osint, subdomain
Workflow, reporting & specialized11methodology, triage-validation, evidence-hygiene, VRT-aware reporting

Full searchable catalog → docs/skills.md. Also ships 15 slash commands (/hunt, /recon, /report, …) and a deterministic engagement engine (engine/) that maps a target's attack surface and routes each finding to the skill that handles it.


How it works

A 6-phase, non-linear workflow — recon → map & rank → hunt → validate → report — with scope enforced in code and a 7-Question Gate before anything is submitted. Two ways to drive it:

  • Plain English — describe what you're testing and the relevant skill loads automatically.
  • /hunt scaffold + cbh CLI — engagement-folder structure, state, and orchestration.

→ Usage guide & worked example · 6-phase architecture & skill-to-phase map · cbh CLI


Authorization

These skills are intended for assets you own or have written authorization to assess (bug-bounty in-scope assets, pentest engagement letters, CTF challenges, your own infrastructure).

The skills include validation gates that auto-trigger when you point Claude at unverified third-party targets — triage-validation's 7-Question Gate explicitly asks whether the asset is in scope (Q3) and on the program's accepted-impact list (Q2). The bugcrowd-reporting skill includes researcher-side hygiene (Bugcrowdninja alias, account-state restoration, friendly-tester posture) that signals legitimate authorized testing to the target's fraud team.

The bundle explicitly excludes: weaponizing 0-days against unauthorized targets, post-exploitation tooling, malware development, mass-targeting infrastructure. See SECURITY.md for the full posture.

Heads-up — Anthropic runtime cyber safeguards. Anthropic's models apply real-time safeguards that block "vulnerability exploitation or offensive security tooling development" by default — so even authorized, in-scope work can hit a refusal that isn't this bundle's doing. If you do authorized offensive security (pentest / bug bounty / red team), enroll in Anthropic's free, application-based Cyber Verification Program (CVP) to get safeguards adjusted for legitimate dual-use work. (Mass data exfiltration and ransomware development stay prohibited and are not adjustable.) Details: Anthropic — real-time cyber safeguards.

Why your model switched mid-session

Separate from refusals, and easy to miss. On Opus 5, a narrow set of higher-risk cyber requests — Anthropic names exploit generation, binary-based vulnerability scanning and penetration testing — fall back to Opus 4.8 rather than being refused. You get a notice and the response is labelled with the model that answered, but in a long agentic run that is easy to scroll past, so it can look like Opus 5 quietly got worse. See why Claude switched models.

What to do depends on what you are actually doing:

SituationWhat helps
Auditing your own code — reviewing a repo you own for defectsSay so. "Defensive review of my own repo", "check this against the OWASP Top 10", "secure refactor to remediate" describe the work accurately and read as remediation. This is not a workaround; the work genuinely is defensive.
Authorized offensive work — live engagement, PoC for a bounty submissionThis is what the bundle is for, and the supported route is CVP. Do not reword an offensive engagement to look defensive to get past a classifier — enroll instead.
You just want the switching offSettings → Capabilities disables automatic model switching.

/hunt states the engagement frame (authorized, scope-bounded, remediable finding) on its first turn for exactly this reason — engagement context belongs in the session explicitly, not implied.


Documentation

DocContents
README.mdThis file — overview, quickstart, scope, skill summary
INSTALL.mdFull setup with Burp MCP integration and optional skill regenerator
USAGE.mdWorkflow walkthrough · decision tree · worked engagement example
docs/architecture.md6-phase architecture · skill-to-phase mapping · engagement composition
docs/cbh-cli.mdcbh CLI — native runner orchestrating recon + classify + triage + report
docs/cve-coverage.mdCISA KEV coverage snapshot — refreshed weekly via the workflow template at docs/automation/cve-refresh.yml.template
docs/credits.mdFull attribution: 43 original skills + 8 vendored from upstream
CONTRIBUTING.mdPR guidelines · skill quality standards · scope
SECURITY.mdAuthorized-use posture · responsible disclosure · what's excluded
LICENSEMIT

Why this exists

Most bug-hunting Claude setups are either too generic (one big "security" prompt) or too fragmented (you bookmark 30 disclosed reports and re-read them every engagement). Neither scales past the second target.

This bundle was built and validated through authorized engagements that exposed different capability gaps:

Bug-bounty engagement — surfaced four gaps a starter 3-skill stack could not close:

  1. No hypothesis discipline — drafts written before validation → wasted hours, hurt validity ratio
  2. No per-program reporting tactics — VRT defaults auto-downgraded P3-worthy findings to P4
  3. No engagement coordination — findings, evidence, and submission IDs scattered across folders
  4. No evidence hygiene — screenshots leaked cookies and victim PII

External red-team engagement — exposed five additional gaps that bug-bounty defaults made worse:

  1. Conservative defaults retracted real findings — WAPT mindset stopped tests early on defended targets where red-team continuation would have surfaced bypass chains → redteam-mindset
  2. No mid-engagement situational awareness — client SOC patched confirmed SQLi within 30 min; external attacker locked 14 accounts during a live test session — both invisible without explicit detection methodology → mid-engagement-ir-detection
  3. No enterprise-platform attack chains — M365 + Entra ID, on-prem SharePoint, Cisco SSL VPN, vCenter, and 7 Android APKs all needed current 2024-2026 CVE knowledge and platform-specific tradecraft → m365-entra-attack, okta-attack, hunt-sharepoint, hunt-aspnet, hunt-ntlm-info, vmware-vcenter-attack, enterprise-vpn-attack, apk-redteam-pipeline
  4. No client-facing deliverable format — bug-bounty report templates don't fit enterprise red-team where output is a 50KB+ MD + DOCX with embedded screenshots → redteam-report-template
  5. No post-credential escalation model — when recon yielded credentials (AWS keys, JWTs, GCP JSON), it was unclear what they granted or how to escalate → cloud-iam-deep

The per-class hunt-* skills address gap-zero ("what should I look for in webapps") — the original 24 codifying patterns from 681 disclosed HackerOne reports, with 20+ framework/surface skills added by the community v3 expansion — Claude knows the actual chain templates real triagers paid for, not abstract OWASP Top 10. The enterprise-platform and red-team-tradecraft layers address what bug-bounty alone cannot: external red-team engagements against monitored enterprise targets.


Roadmap

  • HackerOne MCP integration (currently only Burp MCP wired in)
  • Per-engagement memory layer — pattern recall across targets
  • Industry-specific hunt skills — hunt-fintech-graphql, hunt-healthcare-fhir, hunt-gov-compliance
  • Program-rules-parser skill — auto-generate structured scope.md from program text
  • Refresh hunt-* skills with newer disclosed reports (re-run public-skills-builder)
  • Additional enterprise-platform skills — citrix-netscaler-deep, f5-bigip-attack, ad-cs-attack (AD Certificate Services)
  • Refresh enterprise-VPN CVE matrix quarterly to track 2026 advisories
  • Update architecture SVG to include the 7-skill enterprise-platform layer

Sponsors

Atlas Cloud

Atlas Cloud is a full-modal AI inference platform that gives developers a single AI API to access video generation, image generation, and LLM APIs. Instead of managing multiple vendor integrations, you connect once and get unified access to 300+ curated models across all modalities.

Check out Atlas Cloud's new coding plan promotion for more budget-friendly API access: https://www.atlascloud.ai/console/coding-plan


About

Operational tradecraft accumulated across bug-bounty engagements and authorized pentests, codified into Claude skills. Platform-agnostic — slot into any engagement workflow you already use, or none.

Author: ElementalSoul · GenAI Security Research

Sister project: Claude-OSINT — paired skills for the recon phase that this bundle picks up after. Its two recon skills (offensive-osint, osint-methodology) are canonically maintained here and re-exported there, so the two are byte-identical. Installing both is safe: each bundle's installer (install.sh on macOS/Linux, install.ps1 on Windows) records a manifest, the script skips re-copying an identical skill, and --uninstall keeps any skill the other bundle still owns — uninstalling one never breaks the other.

Vendored foundation: shuvonsec/claude-bug-bounty — methodology, validation, reporting, payload library (8 of 82 skills + 15 slash commands)

Generator tool used (not vendored): shuvonsec/public-skills-builder — used to scaffold per-class skills from H1 disclosed reports

Inspirations:

Tool inventory:

License: MIT — use freely, attribution appreciated.


"Give Claude the right skill and it stops being a chatbot. It becomes an operator."

测试与质量

中风险

  • 来源需自行核对维护者身份。
  • 包含脚本或命令调用,安装前请复核。
  • 可能需要外部 token、网络权限或第三方服务。
  • 未检测到高风险命令。
  • 扫描发现:3 条。

Codex — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/elementalsouls/Claude-BugHunter.git
  3. 将 "skills/mid-engagement-ir-detection" 文件夹复制到 Codex 的 skills 目录中。
  4. 重启 Codex 让新的 skill 生效。

Codex — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Codex 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Codex 让新的 skill 生效。

Claude Code — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/elementalsouls/Claude-BugHunter.git
  3. 将 "skills/mid-engagement-ir-detection" 文件夹复制到 Claude Code 的 skills 目录中。
  4. 重启 Claude Code 让新的 skill 生效。

Claude Code — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Claude Code 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Claude Code 让新的 skill 生效。

Cursor — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/elementalsouls/Claude-BugHunter.git
  3. 将 "skills/mid-engagement-ir-detection" 文件夹复制到 Cursor 的 skills 目录中。
  4. 重启 Cursor 让新的 skill 生效。

Cursor — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Cursor 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Cursor 让新的 skill 生效。

GitHub Copilot — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/elementalsouls/Claude-BugHunter.git
  3. 将 "skills/mid-engagement-ir-detection" 文件夹复制到 GitHub Copilot 的 skills 目录中。
  4. 重启 GitHub Copilot 让新的 skill 生效。

GitHub Copilot — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 GitHub Copilot 让新的 skill 生效。

Windsurf — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/elementalsouls/Claude-BugHunter.git
  3. 将 "skills/mid-engagement-ir-detection" 文件夹复制到 Windsurf 的 skills 目录中。
  4. 重启 Windsurf 让新的 skill 生效。

Windsurf — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Windsurf 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Windsurf 让新的 skill 生效。
查看 SKILL.md 原文
name: mid-engagement-ir-detection
description: Methodology for detecting client SOC patches, attacker activity, and security-state changes that occur DURING a red-team engagement — and converting those observations into deliverable findings. Built from authorized red-team work where the client patched a confirmed SQLi within 30 minutes of detection AND an external attacker locked multiple new accounts during a single test session. Use when (a) running ANY active engagement against a monitored target, (b) a previously-confirmed finding stops reproducing, (c) baseline timing shifts unexpectedly, or (d) you notice response patterns changing during testing.
sources: authorized-engagement
report_count: 1

When to use this skill

Trigger when:

  • Running active testing against a target with active SOC monitoring
  • A confirmed-vulnerable finding stops reproducing on recheck
  • Baseline timing shifts unexpectedly (3× slower, sudden errors, new headers)
  • Response sizes change between test windows
  • New WAF cookies or headers appear that weren't there at session start
  • Lockout / error rates change between test windows (especially LOCKED count for credential attacks)
  • Engagement is "assume breach" or "white box" — client knows you're testing

DO NOT use for:

  • Bug bounty (client doesn't know you're there; no real-time IR)
  • Pure recon (no state-change happening)
  • One-off vulnerability scanning (no temporal dimension)

The core insight

In a real red-team engagement against a competent SOC, the security state of the target is not static. It changes during your test in response to your traffic. These state changes are:

  1. Themselves valuable findings (positive operational observations about IR responsiveness)
  2. Confirmation evidence (mid-engagement patch = the original vulnerability was real)
  3. Classification signals (WAF rule deployment vs code fix — different remediation depth)

Anti-pattern: treating reproduction failure as evidence the original signal was a false positive. Original PoC artifacts captured before the change are still the vulnerability finding.


The discipline — capture before, diff after

Before any active test:

# Capture pre-test fingerprint of the target
fingerprint = {
    "ts_pre": time.time(),
    "ip_seen": "<operator-src-ip>",
    "baseline_response_time_ms": <measure>,
    "baseline_response_size_bytes": <measure>,
    "response_headers": <capture set>,
    "waf_cookies": <list>,
    "lockout_count_in_state": <count from o365_attempts.json>,
}

Persist to engagement_log/fingerprint_pre.json.

During the test:

Log every test result with full context (timestamp, IP, payload, response code, response size, response time, headers if relevant) to JSONL append-only.

After the test session OR on first failed-recheck:

fingerprint_post = same structure
delta = {
    "baseline_time_change_ms": post.time - pre.time,
    "baseline_size_change_bytes": post.size - pre.size,
    "new_headers_appeared": post.headers - pre.headers,
    "new_waf_cookies": post.cookies - pre.cookies,
    "new_lockouts": post.locked_count - pre.locked_count,
}

If any delta is significant — investigate, don't retract.


The three primary IR observations

Observation 1 — Mid-engagement WAF rule deployment

Symptoms:

  • Original payloads return identical response → no signal at all on recheck
  • Body size identical to baseline (login page reflection)
  • Timing reverts to baseline regardless of payload
  • New cookie or header in responses (e.g., cf-bm, __cf_bm, awselb)
  • Specific keyword in URL/body now triggers different response code (403, 406, 429)

Confirmation: retry with WAF-evasion variants:

  • URL-encode the payload differently (%27 vs %5cu0027)
  • Change request method (POST → PUT, GET → POST)
  • Different content-type (form-urlencoded → multipart)
  • Slower pace (5s → 60s between requests)
  • Mixed-case keywords (SLEEP → SlEeP)

If WAF-evasion variants restore the signal, the mitigation is at the WAF layer (bypassable).

If even WAF-evasion variants stay blocked, the mitigation is likely in code.

Finding template:

Subject: Mid-engagement mitigation deployed for <vulnerability X>
Observation: At engagement timestamp T0, vulnerability <X> on <endpoint> was
confirmed via <PoC>. At T0+<minutes>, recheck via the original payload no longer
reproduces the timing/error/size differential. <WAF-evasion variant> [does/does
not] restore the signal.

Description: This pattern is consistent with the client SOC observing engagement
traffic and deploying a mitigation in real time. Mitigation depth assessment:
[at-WAF, bypassable] vs [in-code, durable].

Impact (positive): Client SOC has both detection-grade visibility into application
traffic AND the authority to deploy mitigations within ~<minutes> of detection.

Impact (caveat): The original vulnerability did exist and was exploitable for at
least the engagement window before mitigation. If the mitigation is at the WAF
layer only, the underlying code-level flaw remains exploitable via alternative
payloads.

Recommendation:
1. Verify the mitigation is in code (parameterized queries, input sanitization),
   not just at the WAF layer.
2. Audit the codebase for the same root cause across sister applications.
3. (Positive) Document the IR responsiveness as a capability metric.

Observation 2 — Active concurrent attacker

Symptoms:

  • Many AADSTS50053 (LOCKED) responses despite your 1-attempt-per-user discipline
  • Lockouts cluster alphabetically or by some other sort key
  • New lockouts appear DURING your engagement (diff before/after)
  • LOCKED rate exceeds expected baseline (in our engagement: 11% of all attempts → red flag)

Math check:

  • Your discipline: 1 attempt per user lifetime
  • Smart Lockout default: lockout after 10 failed attempts; lockout duration starts at 60 seconds and grows with each subsequent lockout (not a flat 10-minute window)
  • Therefore: IF tool logs confirm exactly 1 attempt/user (no burst retries, no parallel-goroutine duplicate sends, no tool misconfiguration), you cannot mathematically cause Smart Lockout — verify journal.jsonl shows 1 attempt/user before asserting this
  • Therefore: every NEW AADSTS50053 accumulating during the window (per before/after diff) was caused by someone else; pre-existing locks may stem from the legitimate user's own failures or a prior test run, so attribute only the newly-accumulating locks to an external party

Confirmation:

  • Sort locked accounts alphabetically; if they cluster, attacker is using sorted username list
  • Compare pre-session lockout count vs post-session — new locks during your session = attacker is active right now
  • Probe a known-active "system" account (noreply@, info@, oc@) — if it's locked, attacker is hitting service mailboxes too (typically MFA-exempt → high-value to attackers)

Finding template:

Subject: Active external password-spray campaign detected during engagement

Observation: During M365 ROPC validation against the <tenant> Entra tenant, <N>
unique principals returned AADSTS50053 (Smart Lockout) when probed with a single
password attempt at safe pace. Our tool journal (journal.jsonl) confirms exactly
1 attempt per user with no duplicate sends, so under the Smart Lockout default
(lockout after 10 failed attempts) we cannot have caused these lockouts. The
attribution below applies to the <K> NEW locks that accumulated during our
engagement window between <timestamp_start> and <timestamp_end> (per before/after
diff); pre-existing locks are not attributed to this campaign.

Description: The pattern (alphabetical clustering, real-time accumulation,
including system mailboxes) is consistent with an external attacker performing
a username-list-driven password spray attack against the tenant.

Impact: An external adversary is actively attempting to compromise corporate
M365 accounts. The attacker has knowledge of the user-email schema and a
password-guess wordlist. <List of locked accounts is now in attacker's hands>
(Smart Lockout differentiates valid from invalid usernames).

Recommendation (CRITICAL — within 24h):
1. Open a P1 incident with the SOC. Pull Entra sign-in logs for the <N> locked
   accounts over the last 30-60 days. Identify source IPs and time windows.
2. Apply Conditional Access rule blocking sign-ins from outside <expected geo>
   for non-admin accounts.
3. Enable Identity Protection's User Risk policy with auto-reset on high risk.
4. Force tenant-wide password reset for all <N> previously-locked accounts.
5. Audit service accounts for MFA exemptions; ensure all human-interactive
   accounts have phishing-resistant MFA.

Evidence: engagement_log/poc/m365/locked_accounts.txt (<N> entries with timestamps)

Observation 3 — Detection-induced rate limiting / IP blocks

Symptoms:

  • Specific IP starts returning 403 / 429 / 451 after a window of normal responses
  • Specific IP starts seeing dramatically slower responses (3x+ baseline)
  • TLS handshake fails or RST mid-connection
  • DNS suddenly returns NXDOMAIN for hosts that resolved before
  • Some hosts work from one IP but not another

Confirmation:

  • Rotate to a different IP and retry — if works, you got rate-limited/blocked
  • Compare TTL on DNS responses — sudden short TTL = active mitigation deployed
  • Check Server:, Via:, CF-Cache-Status: headers for CDN-introduced limits

Finding template (operational note, usually low/info severity):

Subject: Engagement traffic detected — IP <X> rate-limited at <timestamp>

Observation: After ~<N> requests in <window> from IP <X>, target <hostname>
began returning <code> for all subsequent requests. Rotation to IP <Y>
restored normal responses.

Description: Active anti-automation control at the perimeter (CDN/WAF/origin).

Impact (positive): Volumetric anti-automation is functional.

Impact (caveat): Rotation defeats this control trivially (cloud VMs cost <$5).
A patient adversary or spray-from-residential-proxies attacker is not affected.

State diff — the key technique

Maintain three pieces of state:

1. engagement_log/baseline.json — captured at session start

{
  "ts": "2026-05-08T13:00:00",
  "source_ip": "<operator-src-ip>",
  "targets": {
    "https://target.example.com/login": {
      "baseline_response_time_ms": 584,
      "baseline_response_size_bytes": 11966,
      "headers_seen": ["Server: Apache", "X-Powered-By: PHP/8.0.26"],
      "set_cookie_names": ["PHPSESSID"]
    }
  },
  "m365": {
    "lockout_count": 247,
    "valid_creds_count": 0
  }
}

2. engagement_log/journal.jsonl — append-only test log

Every test logs:

{"ts":"...","ip":"...","tool":"...","target":"...","payload":"...","resp_code":...,"resp_size":...,"resp_ms":...,"verdict":"...","notes":"..."}

3. engagement_log/state_changes.jsonl — observed deltas

When a state change is detected, append:

{"ts_observed":"2026-05-08T14:30:00","change_type":"baseline_time_shift","target":"https://<employee-app-host>/<app>/login.php","baseline_pre_ms":24412,"baseline_post_ms":90403,"interpretation":"likely WAF rule deployed","actions_taken":["tested WAF-evasion variants — no signal restoration","documented as IR-mitigation finding"]}

This third file is your finding evidence. Every entry is a candidate finding.


Tooling — automated state-change detection

# Bash watcher — runs every 5 min during engagement, alerts on shifts

cd "$ENGAGEMENT_DIR"

# Re-measure baseline timing on key targets
for target in "$@"; do
  ms=$(curl -sk -o /dev/null -w "%{time_total}" "$target" --max-time 30)
  ms_int=$(echo "$ms * 1000" | bc | cut -d. -f1)
  echo "$(date -u +%FT%TZ) $target $ms_int" >> baseline_history.log
done

# Diff against pre-session baseline
python3 - << 'PY'
import json, time
baseline = json.load(open("engagement_log/baseline.json"))
for line in open("baseline_history.log"):
    parts = line.strip().split()
    ts, target, ms = parts[0], parts[1], int(parts[2])
    if target in baseline["targets"]:
        pre = baseline["targets"][target]["baseline_response_time_ms"]
        if abs(ms - pre) > pre * 0.5:  # >50% shift
            print(f"ALERT {ts} {target} time {pre} -> {ms}")
PY

For lockout-count tracking on M365:

# Run every 30 min during M365 spray
LOCK_COUNT=$(grep -c '"AADSTS50053"' engagement_log/o365_results.jsonl)
echo "$(date -u +%FT%TZ) lockout_count $LOCK_COUNT" >> lockout_history.log
# Diff first vs last to surface delta

The "single signal recanted" rule

If a confirmed-vulnerable finding stops reproducing:

  1. DO NOT delete the original PoC. Original timestamps + payloads + response captures are forever.
  2. Capture the new state in detail. What's the recheck response? What's different?
  3. Try at least 3 alternative vectors before declaring "indeterminate".
  4. If none restore the signal, document as "vulnerability confirmed at T0, mitigation observed at T0+, mitigation depth: [WAF | code]".
  5. Both states go in the report. The original finding + the IR observation.

This is the discipline that distinguishes professional red team from "hobbyist scanning". Your client wants the timeline of vulnerability + mitigation, not just the static state.


Why this is a finding (selling it to the client)

When you tell a client "I confirmed SQLi at 14:24, you deployed a mitigation by 14:55, here's the original PoC and here's why you should still verify the fix is in code":

  • Confirmed the vulnerability existed (auditor-grade evidence)
  • Confirmed the mitigation was deployed (positive ops finding for the SOC)
  • Identified the depth question (WAF vs code — different remediation cost)
  • Demonstrated red-team value (you proved both the bug AND the IR responsiveness)

This is a more valuable deliverable than "I confirmed SQLi" alone, because it captures the engagement's full operational picture.


Anti-patterns to avoid

  • "Recheck failed → false positive." No. Recheck failed because the target changed. Investigate the change.
  • "It's no longer vulnerable, drop the finding." No. It WAS vulnerable. The finding stays. Add a "current state: mitigated" annotation.
  • "They patched it, mission accomplished." No. WAF rule != code fix. Verify the depth.
  • "Don't tell the client we observed their patch." Yes, do. It's a positive finding about their IR.
  • "Don't include the locked accounts list — they'll think we caused it." No. Math + journaling discipline proves you didn't. Include the list with the math.

Bridge to neighboring skills

  • redteam-mindset — broader discipline framework; this skill is a specific application
  • m365-entra-attack — specific case for M365 / Smart Lockout differential
  • evidence-hygiene — how to capture and redact PoC evidence properly
  • report-writing — finding template for IR observations
  • bb-methodology — note that this skill is INAPPROPRIATE for bug bounty (no real-time IR there)

One-line summary

Your engagement leaves a footprint. The footprint changes the target. Capture both states. Both are findings.


Related Skills & Chains

  • redteam-mindset — This skill is a specific application of the broader red-team discipline. Engagement flow: redteam-mindset loaded at engagement start → baseline-capture habit built in → when response patterns shift mid-test, mid-engagement-ir-detection activates to capture the SOC-patch state as a NEW finding (defensive-action observed = client capability metric, not "the bug got fixed so we lose the finding").
  • evidence-hygiene — Mid-engagement IR detection produces TWO states (pre-patch and post-patch); both need disciplined evidence capture or the second finding can't be defended. Engagement flow: baseline screenshots + timestamped request/response dumps at session start → response shift detected → second capture set with explicit timestamp delta → both packaged together.
  • m365-entra-attack — The single richest source of mid-engagement IR signal in modern engagements. Engagement flow: M365 spray triggers AADSTS50053 lockout → baseline lockout policy captured → if lockout window changes mid-test (e.g., from 60min to 24hr) → mid-engagement-ir-detection captures the policy change as a finding ("CA policy hardened mid-engagement; defensive response measured").
  • enterprise-vpn-attack + vmware-vcenter-attack — Critical-infrastructure CVE exploitation is the highest-noise activity; expect SOC to patch within hours. Engagement flow: confirmed VPN/vCenter CVE → baseline capture BEFORE exploitation attempt → if appliance updates mid-test, capture as defensive-action finding → report both the original CVE AND the IR-response.
  • redteam-report-template — IR-observation findings get their own Subject in the deliverable, framed differently from technical-vuln findings. Engagement flow: mid-engagement-ir-detection captures behavior-change event → triage-validation 7-Question Gate (specifically: "is the behavior-change attributable to my activity?") → redteam-report-template packages as a "client capability observation" with explicit timeline and detection-latency metric.

发现问题?提交给管理员复核

评分:

评论 (0)

暂无评论,成为第一个评论者吧!