ad-lateral-movement-policy

Evaluate lateral movement requests against security, scope, and authorization gates.

Updated Jul 30, 2026
One-click install
npx skills add https://github.com/salmanabdurrahman/pi-pentest-agent --skill ad-lateral-movement-policy
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ad-lateral-movement-policy
Source: https://github.com/salmanabdurrahman/pi-pentest-agent/tree/main/skills/ad-lateral-movement-policy
Command: npx skills add https://github.com/salmanabdurrahman/pi-pentest-agent --skill ad-lateral-movement-policy

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill provides a rigorous, policy-driven decision framework for evaluating lateral movement requests, ensuring that all security, scope, and authorization gates are met before any activity occurs.

Core Features & Use Cases

  • Gate Checklist: Validates scope, authorization, risk, and operational readiness for complex movement paths.
  • Safer Alternatives: Offers non-intrusive methods like tabletop reviews and configuration audits to achieve architectural insights without active exploitation.
  • Evidence Discipline: Standardizes the recording of policy decisions and constraints to maintain auditability and compliance.

Quick Start

Use the ad-lateral-movement-policy skill to evaluate the security gates for a proposed lateral movement path between two specific hosts.

Frequently Asked Questions about ad-lateral-movement-policy

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I validate lateral movement requests during an authorized pentest?

To validate lateral movement requests during an authorized pentest, apply a policy-driven decision framework that enforces mandatory gate checks for scope, authorization, risk, and operational readiness before any activity occurs.

What is a lateral movement policy framework?

A lateral movement policy framework is a rigorous evaluation mechanism that ensures all security, scope, and authorization gates are met before any network movement activity occurs, maintaining strict auditability and compliance.

How do I assess scope and authorization for complex network movement paths?

Assess scope and authorization for complex network movement paths by applying strict source-to-destination validation, authorization caching, and risk approval gates to ensure operational readiness and compliance.

Are there safer alternatives to active exploitation for lateral movement testing?

Safer alternatives to active exploitation include non-intrusive methods like tabletop reviews and configuration audits, which provide architectural insights without active exploitation while maintaining strict policy boundaries.

How do I maintain evidence discipline and auditability for pentest decisions?

Maintain evidence discipline for pentest decisions by standardizing the recording of policy decisions and constraints, ensuring all lateral movement evaluations remain fully auditable and compliant with security policies.

Can I use this framework for policy-only boundaries without active exploitation?

Yes, this framework satisfies the requirement for policy-only boundaries by enforcing mandatory gate checks and providing safer architectural alternatives, ensuring compliance without active exploitation.