hypnguyen1209/offensive-claude

crypto-analysis

Use when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum migration review

First seen May 24, 2026

Installation

$ npx skills add hypnguyen1209/offensive-claude --skill crypto-analysis

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from hypnguyen1209/offensive-claude · top by installs.

npx skills add hypnguyen1209/offensive-claude

Browse all from hypnguyen1209/offensive-claude

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 357
License LICENSE
Default branch main
Open issues 0
Status Active

Skill metadata

Parsed from SKILL.md frontmatter.

More metadata
type
offensive
phase
analysis
tools
testssl.sh, openssl, hashcat, john, RsaCtfTool, sagemath, jwt_tool, ecdsa-lattice
mitre
["T1600","T1600.001","T1557","T1110.002","T1552.004","T1606.001","T1040"]

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 8,756 B
  • docs SUMMARY.md 213 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 16 installs

SKILL.md

Cryptographic Analysis

When to Activate

  • Auditing TLS/SSL/SSH configurations and X.509 PKI (cipher suites, downgrade, protocol flaws)
  • Reviewing crypto implementations in source code or captured traffic
  • Attacking weak RSA/ECC keys (CTF and real-world weak-key hygiene)
  • Recovering ECDSA/DSA private keys from reused or biased nonces (lattice/HNP)
  • Exploiting symmetric/AEAD misuse: padding oracles, GCM nonce reuse, key-commitment
  • Forging JWT/JOSE tokens (algorithm confusion, none, jwk/jku/kid injection)
  • Cracking password hashes and grading KDF strength
  • Assessing post-quantum readiness ("harvest now, decrypt later" exposure)

Technique Map

Technique ATT&CK CWE Reference Script
TLS cipher/protocol downgrade audit T1600.001 CWE-326 references/tls-pki-audit.md scripts/tls_audit.py
Terrapin SSH prefix truncation (CVE-2023-48795) T1557 CWE-222 references/tls-pki-audit.md scripts/tls_audit.py
Marvin/Bleichenbacher RSA timing oracle T1600 CWE-208 references/tls-pki-audit.md scripts/tls_audit.py
X.509 / CT-log shadow-asset discovery T1589 CWE-295 references/tls-pki-audit.md scripts/tls_audit.py
RSA weak-key factoring (Fermat/Wiener/common-modulus) T1600 CWE-326 references/rsa-attacks.md scripts/rsa_attack.py
Coppersmith partial-key & ROCA (CVE-2017-15361) T1600 CWE-310 references/rsa-attacks.md scripts/rsa_attack.py
Hastad broadcast / batch-GCD T1600 CWE-326 references/rsa-attacks.md scripts/rsa_attack.py
ECDSA nonce reuse key recovery T1552.004 CWE-323 references/ecc-nonce-attacks.md scripts/ecdsa_lattice.py
Biased-nonce lattice/HNP (Minerva, PuTTY CVE-2024-31497) T1552.004 CWE-1241 references/ecc-nonce-attacks.md scripts/ecdsa_lattice.py
Psychic signature (0,0) (CVE-2022-21449) T1606.001 CWE-347 references/ecc-nonce-attacks.md scripts/ecdsa_lattice.py
CBC padding oracle (byte-by-byte decrypt) T1040 CWE-209 references/symmetric-aead.md scripts/padding_oracle.py
AES-GCM nonce reuse "forbidden attack" T1040 CWE-323 references/symmetric-aead.md scripts/gcmnoncereuse.py
AEAD key-commitment / invisible salamanders / partitioning oracle T1606 CWE-347 references/symmetric-aead.md scripts/gcmnoncereuse.py
JWT algorithm confusion RS256→HS256 (CVE-2024-54150) T1606.001 CWE-347 references/jwt-jose.md scripts/jwt_forge.py
JWT alg=none / jwk / jku / kid injection T1606.001 CWE-347 references/jwt-jose.md scripts/jwt_forge.py
Hash identification & GPU cracking T1110.002 CWE-916 references/hash-pq.md scripts/hash_triage.py
Weak KDF / fast-hash password storage T1110.002 CWE-916 references/hash-pq.md scripts/hash_triage.py
Post-quantum / HNDL exposure review T1600 CWE-327 references/hash-pq.md scripts/tls_audit.py

Quick Start

# 0. TLS/PKI posture in one shot (downgrade, ROBOT, SWEET32, Terrapin, cert/CT)
python3 scripts/tls_audit.py target.com:443 --ssh target.com:22 --ct --json out.json
testssl.sh --full --robot --sweet32 https://target.com   # cross-check with the canonical tool

# 1. RSA weak-key triage on a captured public key
python3 scripts/rsa_attack.py --pubkey server.pem --ct ciphertext.b64 --auto
#   tries Fermat (p~=q), Wiener (small d), batch-GCD/common-modulus, ROCA fingerprint

# 2. ECDSA key recovery from a signature corpus (reuse or bias)
python3 scripts/ecdsa_lattice.py recover sigs.json --curve secp256r1 --known-msb 4
#   reuse: needs 2 sigs w/ same r; bias: ~256-1200 sigs depending on leak

# 3. Symmetric/AEAD misuse
python3 scripts/padding_oracle.py --url https://t/dec --ct $CT --block 16   # CBC oracle
python3 scripts/gcm_nonce_reuse.py forbidden ct1.bin ct2.bin --nonce $N     # recover H + forge

# 4. JWT forgery chain
python3 scripts/jwt_forge.py confusion --pubkey jwt_pub.pem --claims '{"role":"admin"}'
python3 scripts/jwt_forge.py none      --claims '{"sub":"admin"}'

# 5. Hash triage + crack plan
python3 scripts/hash_triage.py hashes.txt            # identify + emit hashcat -m / john format
hashcat -m 22000 capture.hc22000 wl.txt -r rules/best64.rule

OPSEC & Detection (summary)

Technique Telemetry / IOC Detection (Sigma/EDR) OPSEC note
TLS scanning / testssl Burst of handshakes, many cipher renegotiations, malformed ClientHellos NIDS: high TLS alert rate from one src; Zeek ssl.log anomalous cipher offers Rate-limit, spread across source IPs; passive cert/CT recon leaves no target-side trace
Marvin/ROBOT oracle probing ~10^4–10^6 RSA decrypts, repeated malformed pre-master/CMS WAF/IDS: spike of TLS decrypt errors, identical-size payloads Extremely loud; only against authorized hosts; use minimal query budgets
Terrapin MitM Injected SSHMSGIGNORE, sequence-number gap at NEWKEYS SSH server logs kex mismatch; netflow showing on-path device Requires active MitM; detectable by strict-kex peers; abort if kex-strict present
ECDSA nonce harvesting Bulk signature collection (Git, TLS, SSH, blockchain) Mostly offline — no target telemetry once sigs captured Collection is passive; recovery is offline; rotate-key advice in report
CBC padding oracle Thousands of decrypt requests, alternating valid/invalid padding Web logs: ~256×blocks requests to one endpoint; Sigma on 4xx burst Very noisy (256×blocks×msgs); throttle, randomize timing
GCM nonce reuse / partitioning Repeated (nonce,key) pairs; multi-key ciphertext blobs App crypto audit; flag reused IVs in logs Forbidden-attack math is offline once two ciphertexts captured
JWT forgery Anomalous alg, external jku/x5u fetch, all-zero ES signature Sigma: JWT with alg:none/HS after RS expected; egress to attacker JWKS URL Each forged token is a single request; minimal noise
Hash cracking None on target (offline) N/A unless online spray (then T1110) Offline; protect loot at rest; never spray live without scope

Deep Dives

  • references/tls-pki-audit.md — TLS/SSL/SSH posture: cipher/protocol downgrade, Terrapin (CVE-2023-48795), Marvin/Bleichenbacher (CVE-2022-4304, CVE-2024-2236), SWEET32/DROWN/Logjam/POODLE, X.509 and Certificate-Transparency analysis.
  • references/rsa-attacks.md — Weak-key factoring: Fermat, Wiener, common modulus, Hastad broadcast, Coppersmith partial-key, batch-GCD, ROCA (CVE-2017-15361); RsaCtfTool / cado-nfs / SageMath workflow.
  • references/ecc-nonce-attacks.md — ECDSA/DSA nonce reuse, biased-nonce lattice/HNP recovery (Minerva, PuTTY CVE-2024-31497), invalid-curve attacks, psychic signatures (CVE-2022-21449).
  • references/symmetric-aead.md — Block-cipher mode misuse: ECB detection, CBC padding oracle, CTR/GCM nonce reuse (forbidden attack), AEAD key-commitment / invisible salamanders / partitioning oracles.
  • references/jwt-jose.md — JWT/JOSE token forgery: algorithm confusion (CVE-2024-54150), alg=none, jwk/jku/x5u/kid injection, weak-secret cracking, library-level CVE landscape.
  • references/hash-pq.md — Hash identification, modern GPU cracking economics (RTX 40/50-series), KDF strength grading, and post-quantum migration / "harvest now, decrypt later" assessment (ML-KEM/ML-DSA, hybrid TLS, crypto-agility).