Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,071Paid calls: 1,552Letters: 14Defects: 1,323counted 3 min ago
teppi

Server definition

Hash
sha256:2640cd4e93b6d2f51f9d5af6b4fe092d3bef8134a9f963e417d087ace65e409c
What it is
What a remote MCP server returned when asked what it offers: 7 tools

The blob, as servednamed by its sha256

{ "instructions": "Offline offensive methodology engine for authorized penetration testing, CTF, and security research. Every technique is paired with detection and mitigation context — equally useful for defenders. All tools are read-only and deterministic. No external API calls at runtime. AUTHORIZED USE ONLY: all output is scoped to systems the tester owns or has explicit written authorization to test.", "tools": [ { "description": "Analyze an HTTP response from authorized probing for information leakage, fingerprinting signals, and related exposure. Structured findings cover version disclosures, stack traces, debug headers, internal paths, authentication patterns, CORS configuration, detection signals, remediation, and associated methodology vectors.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "properties": { "context": { "description": "Freeform context about the authorized test target — e.g., \"login endpoint\", \"GraphQL API\", \"file upload handler\". Narrows the pattern matching to relevant categories. Max 2,000 characters.", "maxLength": 2000, "type": "string" }, "response_body": { "description": "Raw HTML, JSON, XML, or error response body text. Maximum 10,000 characters.", "maxLength": 10000, "type": "string" }, "response_headers": { "description": "Raw HTTP response headers, optionally including the status line. Maximum 20,000 characters.", "maxLength": 20000, "type": "string" }, "status_code": { "description": "HTTP status code (100–599). Helps classify the response type.", "maximum": 599, "minimum": 100, "type": "integer" } }, "type": "object" }, "name": "pentest_analyze_response", "outputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "anyOf": [ { "not": { "required": [ "error" ] }, "required": [ "authorized_use_reminder", "findings", "fingerprints", "summary", "nextToolSuggestions" ] }, { "required": [ "error" ] } ], "properties": { "authorized_use_reminder": { "description": "Reminder that response analysis is for authorized testing only. Rendered first.", "type": "string" }, "error": { "additionalProperties": {}, "description": "Present when the call failed. Absent on success.", "properties": { "code": { "description": "JSON-RPC error code for this failure.", "maximum": 9007199254740991, "minimum": -9007199254740991, "type": "integer" }, "data": { "additionalProperties": {}, "properties": { "reason": { "description": "Machine-readable failure mode. Declared by this tool: `no_input`: Neither response_headers nor response_body was provided. Other values are possible when a failure originates below the handler.", "examples": [ "no_input" ], "type": "string" }, "recovery": { "additionalProperties": {}, "description": "Actionable next step for the caller.", "properties": { "hint": { "type": "string" } }, "required": [ "hint" ], "type": "object" }, "retryable": { "description": "Whether retrying may succeed.", "type": "boolean" } }, "type": "object" }, "message": { "description": "Human-readable description of what went wrong.", "type": "string" } }, "required": [ "code", "message" ], "type": "object" }, "findings": { "description": "Structured findings ordered by severity descending (high first).", "items": { "additionalProperties": false, "description": "A single leakage or fingerprinting finding.", "properties": { "category": { "description": "Finding category. version_disclosure = server/app version exposed; stack_trace = exception stacktrace leaked; internal_path = filesystem/internal route visible; debug_header = diagnostic header present; technology_fingerprint = framework/language signal; auth_pattern = JWT/cookie/auth mechanism visible; cors_misconfiguration = permissive CORS policy; security_header_missing = CSP/X-Frame-Options absent; interesting_field = non-obvious field worth noting; error_message = application/database error text.", "enum": [ "version_disclosure", "stack_trace", "internal_path", "debug_header", "technology_fingerprint", "auth_pattern", "cors_misconfiguration", "security_header_missing", "interesting_field", "error_message" ], "type": "string" }, "detection": { "description": "Observable signals associated with exploitation of this finding.", "type": "string" }, "finding": { "description": "What was detected and where — header name, body excerpt, or field path with surrounding context.", "type": "string" }, "remediation": { "description": "Recommended fix for the target application.", "type": "string" }, "severity": { "description": "Relative impact in an authorized testing context. info = fingerprinting only; low = indirect exposure; medium = useful for chaining; high = directly exploitable.", "enum": [ "info", "low", "medium", "high" ], "type": "string" }, "significance": { "description": "Why this finding matters for an authorized penetration test.", "type": "string" }, "suggested_vector": { "description": "Pentest_guide vector name for follow-up when this finding maps to an attack vector. Absent when no direct vector mapping exists.", "type": "string" } }, "required": [ "category", "severity", "finding", "significance", "detection", "remediation" ], "type": "object" }, "type": "array" }, "fingerprints": { "additionalProperties": false, "description": "Detected server, framework, language, database, cloud, and other technology signals.", "properties": { "cloud_provider": { "description": "Detected cloud provider or CDN.", "type": "string" }, "database": { "description": "Detected database technology if disclosed.", "type": "string" }, "framework": { "description": "Detected framework or runtime (e.g., \"Express 4.x\", \"Spring Boot\").", "type": "string" }, "language": { "description": "Detected backend language (e.g., \"PHP\", \"Python\", \"Java\").", "type": "string" }, "other": { "description": "Other technology signals detected.", "items": { "description": "A technology signal.", "type": "string" }, "type": "array" }, "server_software": { "description": "Detected server software and version (e.g., \"Apache/2.4.54\", \"nginx/1.25\").", "type": "string" } }, "required": [ "other" ], "type": "object" }, "nextToolSuggestions": { "description": "Suggested tools derived from detected fingerprints and findings.", "items": { "additionalProperties": false, "description": "A suggested tool with arguments derived from the analysis.", "properties": { "args": { "additionalProperties": {}, "description": "Arguments derived from detected fingerprints and findings.", "propertyNames": { "type": "string" }, "type": "object" }, "reason": { "description": "Relationship between the analysis findings and the suggested tool.", "type": "string" }, "toolName": { "description": "Suggested tool name (e.g., \"pentest_guide\").", "type": "string" } }, "required": [ "toolName", "reason", "args" ], "type": "object" }, "type": "array" }, "summary": { "description": "One-paragraph summary of findings and associated follow-up actions.", "type": "string" } }, "type": "object" } }, { "description": "Transform a payload string through an ordered encoding chain for authorized filter research. Results include the final value, intermediate values, optional decode path and rationale, and detection guidance. All transforms are local; no live probing occurs.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "properties": { "chain": { "description": "Ordered list of encodings to apply (1–6 steps). Applied left to right. E.g., [\"unicode\", \"url\"] applies Unicode escape first, then URL-encodes the result.", "items": { "description": "An encoding step.", "enum": [ "url", "double_url", "html_entity", "unicode", "hex", "base64", "js_escape", "null_byte", "mixed_case", "comment_break" ], "type": "string" }, "maxItems": 6, "minItems": 1, "type": "array" }, "explain": { "default": true, "description": "Whether to include the decode path and bypass rationale.", "type": "boolean" }, "payload": { "description": "Input payload string to encode. Max 10,000 characters.", "maxLength": 10000, "minLength": 1, "type": "string" } }, "required": [ "payload", "chain" ], "type": "object" }, "name": "pentest_encode", "outputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "anyOf": [ { "not": { "required": [ "error" ] }, "required": [ "authorized_use_reminder", "original", "encoded", "intermediate_steps", "detection_note" ] }, { "required": [ "error" ] } ], "properties": { "authorized_use_reminder": { "description": "Reminder that encoding transforms are for authorized bypass research only.", "type": "string" }, "bypass_rationale": { "description": "Why this encoding combination might bypass common filter patterns. Included when explain is true.", "type": "string" }, "decode_path": { "description": "Step-by-step explanation of how a decoder (WAF, server, browser) would reverse the encoding chain. Included when explain is true.", "type": "string" }, "detection_note": { "description": "Detection methods for encoded variants, including normalization and behavior signals.", "type": "string" }, "encoded": { "description": "Final encoded payload after all chain steps applied.", "type": "string" }, "error": { "additionalProperties": {}, "description": "Present when the call failed. Absent on success.", "properties": { "code": { "description": "JSON-RPC error code for this failure.", "maximum": 9007199254740991, "minimum": -9007199254740991, "type": "integer" }, "data": { "additionalProperties": {}, "properties": { "reason": { "description": "Machine-readable failure mode. Declared by this tool: `encoding_error`: An encoding step produced invalid output (e.g., base64 on invalid input). Other values are possible when a failure originates below the handler.", "examples": [ "encoding_error" ], "type": "string" }, "recovery": { "additionalProperties": {}, "description": "Actionable next step for the caller.", "properties": { "hint": { "type": "string" } }, "required": [ "hint" ], "type": "object" }, "retryable": { "description": "Whether retrying may succeed.", "type": "boolean" } }, "type": "object" }, "message": { "description": "Human-readable description of what went wrong.", "type": "string" } }, "required": [ "code", "message" ], "type": "object" }, "intermediate_steps": { "description": "Intermediate values at each encoding step, for tracing the chain.", "items": { "additionalProperties": false, "description": "One encoding step in the chain with its output.", "properties": { "encoding": { "description": "Encoding name applied at this step.", "type": "string" }, "result": { "description": "Payload value after this encoding step.", "type": "string" } }, "required": [ "encoding", "result" ], "type": "object" }, "type": "array" }, "original": { "description": "The input payload.", "type": "string" } }, "type": "object" } }, { "description": "Generate context-specific payload templates for authorized systems. Each template includes its vulnerability category, context rationale, WAF/IDS detection signature, mitigation, optional WAF research note, and optional encoded variant.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "properties": { "category": { "description": "Vulnerability category for payload generation.", "enum": [ "xss", "sqli", "ssrf", "xxe", "path_traversal", "ssti", "command_injection", "open_redirect", "csrf", "deserialization", "jwt", "ldap_injection", "nosql_injection", "http_header" ], "type": "string" }, "count": { "default": 5, "description": "Number of payload variants to return (1–20, default 5). More variants cover different bypass approaches for the same context.", "maximum": 20, "minimum": 1, "type": "integer" }, "encoding": { "description": "Optional encoding chain applied left to right to each returned template.", "items": { "description": "An encoding step to apply.", "enum": [ "none", "url", "double_url", "html_entity", "unicode", "hex", "base64", "js_escape" ], "type": "string" }, "type": "array" }, "injection_context": { "description": "Precise injection context. Critical for XSS: an HTML attribute payload differs from a JS string payload. Provide the most specific context for the best results.", "enum": [ "html_attribute", "html_body", "js_string", "js_template", "js_script_block", "url_parameter", "url_path", "sql_where", "sql_integer", "xml_element", "xml_attribute", "http_header", "json_value", "cookie_value", "file_name", "generic" ], "type": "string" }, "waf_profile": { "default": "none", "description": "WAF or filter in front of the authorized test target. When a specific WAF is named, bypass variants referencing known public research are included.", "enum": [ "cloudflare", "aws_waf", "modsecurity_crs", "imperva", "akamai", "f5_bigip_asm", "nginx_modsecurity", "fortinet_fortiwaf", "none", "unknown" ], "type": "string" } }, "required": [ "category", "injection_context" ], "type": "object" }, "name": "pentest_generate_payloads", "outputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "anyOf": [ { "not": { "required": [ "error" ] }, "required": [ "category", "injection_context", "authorized_use_reminder", "payloads" ] }, { "required": [ "error" ] } ], "properties": { "authorized_use_reminder": { "description": "Reminder that these templates are for authorized testing only.", "type": "string" }, "category": { "description": "Requested payload category.", "type": "string" }, "error": { "additionalProperties": {}, "description": "Present when the call failed. Absent on success.", "properties": { "code": { "description": "JSON-RPC error code for this failure.", "maximum": 9007199254740991, "minimum": -9007199254740991, "type": "integer" }, "data": { "additionalProperties": {}, "properties": { "reason": { "description": "Machine-readable failure mode.", "type": "string" }, "recovery": { "additionalProperties": {}, "description": "Actionable next step for the caller.", "properties": { "hint": { "type": "string" } }, "required": [ "hint" ], "type": "object" }, "retryable": { "description": "Whether retrying may succeed.", "type": "boolean" } }, "type": "object" }, "message": { "description": "Human-readable description of what went wrong.", "type": "string" } }, "required": [ "code", "message" ], "type": "object" }, "injection_context": { "description": "Requested injection context.", "type": "string" }, "payloads": { "description": "Payload templates ordered by coverage breadth, each annotated with offense and defense context.", "items": { "additionalProperties": false, "description": "A payload template annotated with offense context (what it tests, how it works) and defense context (detection signature, mitigation).", "properties": { "description": { "description": "What this payload tests and why it works in the specified injection context.", "type": "string" }, "detection_signature": { "description": "Signature a WAF or IDS might match, such as keywords or patterns.", "type": "string" }, "encoded_variant": { "description": "Encoded form of the template per the requested encoding chain. Absent when no encoding was requested.", "type": "string" }, "mitigation": { "description": "Input validation or encoding control that prevents this payload class.", "type": "string" }, "template": { "description": "The payload template string. Adapt to the specific authorized target — replace placeholder values as annotated.", "type": "string" }, "waf_bypass_note": { "description": "WAF-specific bypass technique and public research reference. Present only when waf_profile is not \"none\".", "type": "string" } }, "required": [ "template", "description", "detection_signature", "mitigation" ], "type": "object" }, "type": "array" } }, "type": "object" } }, { "description": "Return an authorized-testing methodology for a selected vector and optional target context. The playbook covers reconnaissance, enumeration, exploitation, and post-exploitation phases with objectives, techniques, detection signals, mitigations, common pitfalls, references, and context-derived tool suggestions across 15 vectors.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "properties": { "phase": { "default": "all", "description": "Methodology phase selector. \"all\" returns the complete playbook; a named phase returns only that phase.", "enum": [ "all", "recon", "enumeration", "exploitation", "post_exploitation" ], "type": "string" }, "target_context": { "description": "Optional target profile for authorized engagement. Providing this narrows the playbook to what is most relevant for the specific environment.", "properties": { "recon_notes": { "description": "Freeform recon findings to incorporate. E.g., \"endpoint /api/users/{id} reflects user input in JSON response\". Narrows which phases are most relevant.", "type": "string" }, "stack": { "description": "Technology stack (e.g., \"Node.js + Express + PostgreSQL\", \"PHP 7.4 + Apache\", \"Spring Boot\"). Narrows methodology to stack-specific techniques.", "type": "string" }, "waf": { "description": "WAF or filter in use (e.g., \"Cloudflare\", \"AWS WAF\", \"ModSecurity CRS\", \"custom regex\"). Triggers bypass-aware variants in payload suggestions.", "type": "string" } }, "type": "object" }, "vector": { "description": "Attack vector to retrieve methodology for. Each vector has its own methodology branch covering recon through exploitation. Authorized testing only.", "enum": [ "auth_bypass", "idor", "ssrf", "xss", "sqli", "xxe", "path_traversal", "cors", "csrf", "open_redirect", "deserialization", "race_condition", "ssti", "command_injection", "jwt_attack" ], "type": "string" } }, "required": [ "vector" ], "type": "object" }, "name": "pentest_guide", "outputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "anyOf": [ { "not": { "required": [ "error" ] }, "required": [ "vector", "authorized_use_reminder", "phases", "owasp_references", "attack_technique_ids", "nextToolSuggestions" ] }, { "required": [ "error" ] } ], "properties": { "attack_technique_ids": { "description": "Relevant ATT&CK technique IDs for cross-referencing with pentest_lookup_technique.", "items": { "description": "An ATT&CK technique ID.", "type": "string" }, "type": "array" }, "authorized_use_reminder": { "description": "Reminder that this methodology applies to authorized testing only. Included in every response.", "type": "string" }, "error": { "additionalProperties": {}, "description": "Present when the call failed. Absent on success.", "properties": { "code": { "description": "JSON-RPC error code for this failure.", "maximum": 9007199254740991, "minimum": -9007199254740991, "type": "integer" }, "data": { "additionalProperties": {}, "properties": { "reason": { "description": "Machine-readable failure mode.", "type": "string" }, "recovery": { "additionalProperties": {}, "description": "Actionable next step for the caller.", "properties": { "hint": { "type": "string" } }, "required": [ "hint" ], "type": "object" }, "retryable": { "description": "Whether retrying may succeed.", "type": "boolean" } }, "type": "object" }, "message": { "description": "Human-readable description of what went wrong.", "type": "string" } }, "required": [ "code", "message" ], "type": "object" }, "nextToolSuggestions": { "description": "Suggested tools and arguments derived from the playbook.", "items": { "additionalProperties": false, "description": "A suggested tool with arguments derived from the playbook.", "properties": { "args": { "additionalProperties": {}, "description": "Arguments derived from the methodology context.", "propertyNames": { "type": "string" }, "type": "object" }, "reason": { "description": "Relationship between the playbook and the suggested tool.", "type": "string" }, "toolName": { "description": "Suggested tool name (e.g., \"pentest_generate_payloads\").", "type": "string" } }, "required": [ "toolName", "reason", "args" ], "type": "object" }, "type": "array" }, "owasp_references": { "description": "Relevant OWASP Testing Guide test case IDs (e.g., \"WSTG-INPV-01\").", "items": { "description": "An OWASP test case ID.", "type": "string" }, "type": "array" }, "phases": { "description": "Ordered methodology phases. Contains only the requested phase when phase input is not \"all\".", "items": { "additionalProperties": false, "description": "A methodology phase covering one stage of the authorized testing workflow.", "properties": { "common_mistakes": { "description": "Pitfalls that lead to missed findings or noisy testing.", "items": { "description": "A common mistake.", "type": "string" }, "type": "array" }, "objectives": { "description": "Discovery or execution objectives for this phase.", "items": { "description": "An objective for this phase.", "type": "string" }, "type": "array" }, "phase": { "description": "Phase name (e.g., \"Reconnaissance\", \"Exploitation\").", "type": "string" }, "techniques": { "description": "Applicable techniques for this phase.", "items": { "additionalProperties": false, "description": "A specific technique for this phase with detection and mitigation context.", "properties": { "description": { "description": "How to perform the technique in authorized testing.", "type": "string" }, "detection": { "description": "Observable logs, signatures, and anomalies for this technique.", "type": "string" }, "mitigation": { "description": "Configuration or control that prevents or reduces impact.", "type": "string" }, "name": { "description": "Technique name.", "type": "string" }, "stack_note": { "description": "Stack-specific variant or consideration. Present only when target_context.stack was provided and a relevant note exists.", "type": "string" } }, "required": [ "name", "description", "detection", "mitigation" ], "type": "object" }, "type": "array" }, "tools_commonly_used": { "description": "Named tools commonly associated with this phase.", "items": { "description": "A tool commonly used in this phase.", "type": "string" }, "type": "array" } }, "required": [ "phase", "objectives", "techniques", "tools_commonly_used", "common_mistakes" ], "type": "object" }, "type": "array" }, "vector": { "description": "The requested attack vector.", "type": "string" } }, "type": "object" } }, { "description": "Look up a MITRE ATT&CK threat group or software entry by ID, name, or keyword. Results include ATT&CK identity, aliases, type, description, and associated techniques with procedure-level context from public ATT&CK reporting.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "properties": { "query": { "description": "ATT&CK threat group ID (e.g., \"G0007\"), software ID (e.g., \"S0002\"), or name/keyword (e.g., \"APT28\", \"Mimikatz\", \"Lazarus Group\"). ID lookup is exact and case-insensitive; name/keyword search returns the best match.", "type": "string" } }, "required": [ "query" ], "type": "object" }, "name": "pentest_lookup_group", "outputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "anyOf": [ { "not": { "required": [ "error" ] }, "required": [ "authorized_use_reminder", "id", "name", "aliases", "type", "description", "techniques_used", "attack_version" ] }, { "required": [ "error" ] } ], "properties": { "aliases": { "description": "Known alternate names from ATT&CK.", "items": { "description": "An alternate name for this group or software.", "type": "string" }, "type": "array" }, "attack_version": { "description": "ATT&CK dataset version used (e.g., \"Enterprise v19.1\").", "type": "string" }, "authorized_use_reminder": { "description": "Reminder that threat group data is for authorized testing and research only. Rendered first.", "type": "string" }, "description": { "description": "ATT&CK description (truncated to 800 characters).", "type": "string" }, "error": { "additionalProperties": {}, "description": "Present when the call failed. Absent on success.", "properties": { "code": { "description": "JSON-RPC error code for this failure.", "maximum": 9007199254740991, "minimum": -9007199254740991, "type": "integer" }, "data": { "additionalProperties": {}, "properties": { "reason": { "description": "Machine-readable failure mode. Declared by this tool: `no_match`: No group or software entry matched the query. Other values are possible when a failure originates below the handler.", "examples": [ "no_match" ], "type": "string" }, "recovery": { "additionalProperties": {}, "description": "Actionable next step for the caller.", "properties": { "hint": { "type": "string" } }, "required": [ "hint" ], "type": "object" }, "retryable": { "description": "Whether retrying may succeed.", "type": "boolean" } }, "type": "object" }, "message": { "description": "Human-readable description of what went wrong.", "type": "string" } }, "required": [ "code", "message" ], "type": "object" }, "id": { "description": "ATT&CK ID (e.g., \"G0007\" for a group, \"S0002\" for software).", "type": "string" }, "name": { "description": "Primary display name (e.g., \"APT28\", \"Mimikatz\").", "type": "string" }, "techniques_used": { "description": "Up to 20 techniques associated with the group or software, including procedure-level context and technique IDs.", "items": { "additionalProperties": false, "description": "A technique used by this group or software with procedure context.", "properties": { "description": { "description": "How this group or software used the technique, from public ATT&CK reporting.", "type": "string" }, "technique_id": { "description": "ATT&CK technique ID (e.g., \"T1190\").", "type": "string" }, "technique_name": { "description": "Technique name.", "type": "string" } }, "required": [ "technique_id", "technique_name", "description" ], "type": "object" }, "type": "array" }, "type": { "description": "\"group\" for intrusion sets (threat actors), \"software\" for malware and tools.", "enum": [ "group", "software" ], "type": "string" } }, "type": "object" } }, { "description": "Look up a MITRE ATT&CK technique by exact ID or keyword. Results include tactics, platforms, description, detection data, public procedure examples, mitigations, related sub-techniques, and dataset version.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "properties": { "include_subtechniques": { "default": true, "description": "Include sub-techniques in the result. Set to false when only the parent technique summary is needed.", "type": "boolean" }, "query": { "description": "ATT&CK technique ID (e.g., \"T1190\", \"T1059.001\") or keyword describing the technique (e.g., \"sql injection\", \"pass the hash\", \"web shell upload\"). ID lookup is exact; keyword lookup returns the best match plus related techniques.", "type": "string" } }, "required": [ "query" ], "type": "object" }, "name": "pentest_lookup_technique", "outputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "anyOf": [ { "not": { "required": [ "error" ] }, "required": [ "authorized_use_reminder", "technique_id", "name", "tactics", "description", "platforms", "detection", "mitigations", "procedure_examples", "sub_techniques", "attack_version" ] }, { "required": [ "error" ] } ], "properties": { "attack_version": { "description": "ATT&CK dataset version used (e.g., \"Enterprise v19.1\").", "type": "string" }, "authorized_use_reminder": { "description": "Reminder that technique data is for authorized testing and research only. Rendered first.", "type": "string" }, "description": { "description": "ATT&CK description of the technique.", "type": "string" }, "detection": { "additionalProperties": false, "description": "ATT&CK detection context for the technique.", "properties": { "data_sources": { "description": "ATT&CK data sources relevant to detection.", "items": { "description": "A relevant ATT&CK data source.", "type": "string" }, "type": "array" }, "indicators": { "description": "Concrete behavioral indicators and signatures.", "items": { "description": "A behavioral indicator or signature.", "type": "string" }, "type": "array" }, "summary": { "description": "Overview of how defenders detect this technique.", "type": "string" } }, "required": [ "summary", "data_sources", "indicators" ], "type": "object" }, "error": { "additionalProperties": {}, "description": "Present when the call failed. Absent on success.", "properties": { "code": { "description": "JSON-RPC error code for this failure.", "maximum": 9007199254740991, "minimum": -9007199254740991, "type": "integer" }, "data": { "additionalProperties": {}, "properties": { "reason": { "description": "Machine-readable failure mode. Declared by this tool: `no_match`: No technique matched the query. Other values are possible when a failure originates below the handler.", "examples": [ "no_match" ], "type": "string" }, "recovery": { "additionalProperties": {}, "description": "Actionable next step for the caller.", "properties": { "hint": { "type": "string" } }, "required": [ "hint" ], "type": "object" }, "retryable": { "description": "Whether retrying may succeed.", "type": "boolean" } }, "type": "object" }, "message": { "description": "Human-readable description of what went wrong.", "type": "string" } }, "required": [ "code", "message" ], "type": "object" }, "mitigations": { "description": "Recommended mitigations from ATT&CK.", "items": { "additionalProperties": false, "description": "A recommended ATT&CK mitigation with its ID, name, and effect description.", "properties": { "description": { "description": "How this mitigation reduces the technique's effectiveness.", "type": "string" }, "mitigation_id": { "description": "ATT&CK mitigation ID (e.g., \"M1050\").", "type": "string" }, "name": { "description": "Mitigation name.", "type": "string" } }, "required": [ "mitigation_id", "name", "description" ], "type": "object" }, "type": "array" }, "name": { "description": "Technique name.", "type": "string" }, "platforms": { "description": "Target platforms (e.g., \"Windows\", \"Linux\", \"Web Application\").", "items": { "description": "A target platform.", "type": "string" }, "type": "array" }, "procedure_examples": { "description": "Real-world usage examples from ATT&CK public reporting.", "items": { "additionalProperties": false, "description": "A real-world usage example from ATT&CK public reporting.", "properties": { "description": { "description": "How the group or software used this technique, from public ATT&CK reporting.", "type": "string" }, "group_or_software": { "description": "Threat group name or malware name that used this technique.", "type": "string" } }, "required": [ "group_or_software", "description" ], "type": "object" }, "type": "array" }, "sub_techniques": { "description": "Sub-techniques of this parent technique. Empty when querying a sub-technique itself, or when include_subtechniques is false.", "items": { "additionalProperties": false, "description": "A sub-technique ID, name, and brief description.", "properties": { "description": { "description": "Brief description of the sub-technique (first 200 chars).", "type": "string" }, "id": { "description": "Sub-technique ID (e.g., \"T1059.001\").", "type": "string" }, "name": { "description": "Sub-technique name.", "type": "string" } }, "required": [ "id", "name", "description" ], "type": "object" }, "type": "array" }, "tactics": { "description": "ATT&CK tactics this technique belongs to (e.g., \"Initial Access\", \"Execution\").", "items": { "description": "A tactic name.", "type": "string" }, "type": "array" }, "technique_id": { "description": "ATT&CK technique ID (e.g., \"T1190\").", "type": "string" } }, "type": "object" } }, { "description": "Rank ATT&CK techniques and OWASP test cases against an authorized target profile of technology stack, exposed services, authentication type, and operating system. Results include profile-specific relevance, detection opportunities, mitigations, and associated methodology vectors.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "properties": { "auth_type": { "description": "Authentication mechanism in use. Surfaces auth-specific attack techniques.", "enum": [ "jwt", "session_cookie", "api_key", "oauth2", "basic_auth", "ntlm", "kerberos", "none", "unknown" ], "type": "string" }, "limit": { "default": 15, "description": "Maximum number of techniques to return (1–50, default 15). Higher values give broader coverage; lower values focus on highest-relevance items.", "maximum": 50, "minimum": 1, "type": "integer" }, "os": { "description": "Target operating system. Narrows to OS-specific techniques.", "enum": [ "linux", "windows", "macos", "unknown" ], "type": "string" }, "services": { "description": "Exposed services and interfaces (e.g., [\"REST API\", \"GraphQL\", \"file upload\", \"admin panel\"]). Narrows technique relevance.", "items": { "description": "An exposed service or interface.", "type": "string" }, "type": "array" }, "stack": { "description": "Technology stack components (e.g., [\"Node.js\", \"Express\", \"PostgreSQL\", \"Redis\"]). Each element matched against technique platform and procedure examples.", "items": { "description": "A technology stack component.", "type": "string" }, "type": "array" } }, "type": "object" }, "name": "pentest_map_techniques", "outputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "anyOf": [ { "not": { "required": [ "error" ] }, "required": [ "authorized_use_reminder", "ranked_techniques", "owasp_test_cases", "profile_summary", "attack_version", "truncated", "shown", "cap" ] }, { "required": [ "error" ] } ], "properties": { "attack_version": { "description": "ATT&CK dataset version used for technique data.", "type": "string" }, "authorized_use_reminder": { "description": "Reminder that technique mapping is for authorized testing engagements only. Rendered first.", "type": "string" }, "cap": { "description": "The limit applied to ranked_techniques.", "type": "number" }, "error": { "additionalProperties": {}, "description": "Present when the call failed. Absent on success.", "properties": { "code": { "description": "JSON-RPC error code for this failure.", "maximum": 9007199254740991, "minimum": -9007199254740991, "type": "integer" }, "data": { "additionalProperties": {}, "properties": { "reason": { "description": "Machine-readable failure mode. Declared by this tool: `no_profile`: No profile fields were provided. Other values are possible when a failure originates below the handler.", "examples": [ "no_profile" ], "type": "string" }, "recovery": { "additionalProperties": {}, "description": "Actionable next step for the caller.", "properties": { "hint": { "type": "string" } }, "required": [ "hint" ], "type": "object" }, "retryable": { "description": "Whether retrying may succeed.", "type": "boolean" } }, "type": "object" }, "message": { "description": "Human-readable description of what went wrong.", "type": "string" } }, "required": [ "code", "message" ], "type": "object" }, "owasp_test_cases": { "description": "Relevant OWASP Testing Guide test cases for the profile (up to 10).", "items": { "additionalProperties": false, "description": "An OWASP test case relevant to the target profile.", "properties": { "name": { "description": "Test case name.", "type": "string" }, "relevance": { "description": "Why this test case applies to the provided target profile.", "type": "string" }, "test_id": { "description": "OWASP Testing Guide test case ID (e.g., \"WSTG-INPV-01\").", "type": "string" } }, "required": [ "test_id", "name", "relevance" ], "type": "object" }, "type": "array" }, "profile_summary": { "description": "One-sentence normalized summary of the supplied target profile.", "type": "string" }, "ranked_techniques": { "description": "Techniques ordered by relevance_score descending.", "items": { "additionalProperties": false, "description": "A ranked ATT&CK technique with relevance rationale and defense context.", "properties": { "detection_opportunity": { "description": "Primary observable detection opportunity (truncated to 200 characters).", "type": "string" }, "mitigation_summary": { "description": "Key mitigation recommendation for this technique.", "type": "string" }, "name": { "description": "Technique name.", "type": "string" }, "pentest_guide_vector": { "description": "Associated pentest_guide methodology vector. Absent when no direct mapping exists.", "type": "string" }, "relevance_rationale": { "description": "Explanation of why this technique is relevant to the provided target profile.", "type": "string" }, "relevance_score": { "description": "Relative relevance to the supplied target profile; higher scores indicate stronger matches.", "type": "number" }, "tactic": { "description": "Primary tactic (e.g., \"Initial Access\").", "type": "string" }, "technique_id": { "description": "ATT&CK technique ID (e.g., \"T1190\").", "type": "string" } }, "required": [ "technique_id", "name", "tactic", "relevance_score", "relevance_rationale", "detection_opportunity", "mitigation_summary" ], "type": "object" }, "type": "array" }, "shown": { "description": "Number of ranked techniques returned.", "type": "number" }, "truncated": { "description": "True when ranked_techniques was capped by limit.", "type": "boolean" } }, "type": "object" } } ] }
Verify it yourselfcurl -s https://api.teppi.xyz/v1/evidence/sha256:2640cd4e93b6d2f51f9d5af6b4fe092d3bef8134a9f963e417d087ace65e409c | sha256sum