"""
RedAmon Post-Exploitation Prompts

Prompts for post-exploitation phase with different session types.
"""


# Shared direction block reused across statefull + stateless variants. Each
# caller substitutes ``impactful_hint`` with the concrete action categories that
# warrant an ask_user check in that mode.
_POST_EXPLOITATION_DIRECTION = """## Direction

Check the original goal and custom instructions first.
If they specify post-exploitation actions, proceed directly.
Only use `action="ask_user"` if the goal does NOT specify what to do after exploitation.

Use `action="ask_user"` before impactful actions: {impactful_hint}.
"""


# =============================================================================
# POST-EXPLOITATION TOOLS (Statefull Mode - Meterpreter or Shell session)
# =============================================================================

POST_EXPLOITATION_TOOLS_STATEFULL = """
### Post-Exploitation Phase Tools (Statefull Mode)

You have an active Metasploit session. Use `metasploit_console` for all session interactions.

## Detect Your Session Type

Run `sessions -l` — the **Type** column tells you what you have:

| Type | Prompt | Commands |
|------|--------|----------|
| `meterpreter` | `meterpreter >` | Meterpreter commands (sysinfo, upload, migrate...) |
| `shell` / `command` | `$` or `#` | Standard Linux/Windows shell commands |

**Use the right commands for your session type.** Meterpreter commands fail in shell sessions and vice versa.

## Session Management (from msf6 > console)

```
sessions -l           -> List sessions (check type!)
sessions -i <id>      -> Enter session
background            -> Return to msf console (Meterpreter ONLY)
exit                  -> Return to msf console (shell sessions)
sessions -u <id>      -> Upgrade shell to Meterpreter (may fail on minimal systems)
sessions -k <id>      -> Kill session
```

## If Meterpreter Session

**Meterpreter-exclusive commands** (NOT available in shell):

| Command | Purpose |
|---------|---------|
| `sysinfo` | System info |
| `getuid` | Current user |
| `upload local remote` | File transfer to target |
| `download /path` | File transfer from target |
| `migrate <PID>` | Move to another process |
| `hashdump` | Dump password hashes (Windows) |
| `getsystem` | Privilege escalation (Windows) |
| `portfwd add -l P -p P -r host` | Port forwarding |
| `run post/multi/gather/...` | Post-exploitation modules |

**NOT in Meterpreter:** `echo`, `grep`, `awk`, `sed`, `chmod` -> drop to `shell` command first.

**stdapi failure** (`stdapi_fs_*: Operation failed`): Don't retry. Drop to `shell` immediately.

## If Shell Session

Standard shell. **DO NOT use Meterpreter commands** — they will fail. **Pick the command set
that matches the target OS** (run `uname` / `ver` first if unsure — the Linux block fails on a
Windows `cmd`/`command` session and vice versa).

Key post-exploitation commands (Linux):
```
whoami && id                    -> Current user and groups
uname -a                        -> Kernel and OS info
cat /etc/passwd                 -> List users
cat /etc/shadow                 -> Password hashes (if root)
sudo -l                         -> Check sudo permissions
ps aux                          -> Running processes
netstat -tulpn / ss -tulpn      -> Network connections
find / -perm -4000 2>/dev/null  -> SUID binaries
ip addr && ip route             -> Network interfaces and routing
cat /etc/os-release             -> OS version (for kernel exploits)
getcap -r / 2>/dev/null         -> Files with capabilities
```

Key post-exploitation commands (Windows):
```
whoami /all                     -> Current user, groups, privileges
systeminfo                      -> OS version, patches, arch (for kernel exploits)
net user & net localgroup       -> Local users and groups
whoami /priv                    -> Token privileges (SeImpersonate etc.)
tasklist /v                     -> Running processes
netstat -ano                    -> Network connections + owning PID
ipconfig /all & route print     -> Network interfaces and routing
icacls C:\\ /findsid *S-1-1-0*   -> World-writable / weak-ACL locations
```

## Pivoting (from msf6 console, not inside session)

```
route add <subnet> <session-id>     -> Route traffic through compromised host
# Example: route add 10.0.0.0/24 1
```

""" + _POST_EXPLOITATION_DIRECTION.format(
    impactful_hint="privilege escalation, data exfiltration, persistence, file modifications, lateral movement"
)


# =============================================================================
# POST-EXPLOITATION TOOLS (Stateless Mode)
# =============================================================================

POST_EXPLOITATION_TOOLS_STATELESS = """
### Post-Exploitation Phase Tools (Stateless Mode)

You are in POST-EXPLOITATION. The exploit works but there is NO persistent session.
Each command requires re-triggering the exploit.

## How to Run Commands on Target

**If you exploited via Metasploit module:**
1. `set CMD "<command>"`
2. `exploit`

**If you exploited via no-module fallback (execute_curl / execute_code / kali_shell):**
Re-run the same tool with the command changed in the payload.

""" + _POST_EXPLOITATION_DIRECTION.format(
    impactful_hint="file writes, persistence, data deletion"
)
