initial-access

Detail initial access techniques including phishing and credential stuffing mapped to MITRE ATT&CK TA0001.

2.9k|469|Updated Mar 4, 2026
One-click install
npx skills add https://github.com/SnailSploit/Claude-Red --skill initial-access
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: initial-access
Source: https://github.com/SnailSploit/Claude-Red/tree/main/Skills/offensive-initial-access
Command: npx skills add https://github.com/SnailSploit/Claude-Red --skill initial-access

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill provides a comprehensive checklist and methodology for executing various initial access techniques in offensive security engagements, mapping to MITRE ATT&CK TA0001.

Core Features & Use Cases

  • Technique Coverage: Details phishing, credential stuffing, exposed service exploitation, supply chain attacks, and more.
  • Defense Evasion: Includes strategies for bypassing perimeter and endpoint defenses like SWGs, DNS, AV, and EDR.
  • Use Case: When planning the initial phase of a red team exercise, use this Skill to systematically explore and execute the most effective initial access vectors against the target environment.

Quick Start

Use the initial-access skill to explore spear-phishing techniques for gaining a foothold.

Frequently Asked Questions about initial-access

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I gain initial access during a red team engagement?

To gain initial access during a red team engagement, you can use this Skill's methodology covering phishing, credential stuffing, and exposed service exploitation to systematically map vectors against MITRE ATT&CK TA0001.

What are the best ways to bypass EDR and perimeter defenses for initial access?

Bypassing EDR and perimeter defenses for initial access requires strategies included in this Skill to evade SWGs, DNS filtering, and antivirus stacks while executing payload hosting and infection vectors.

How does credential stuffing work for obtaining an initial foothold?

Credential stuffing for an initial foothold works by systematically testing compromised credentials against exposed services, a technique mapped within this Skill's methodology to help red teams bypass perimeter defenses.

Can I use this methodology to plan spear-phishing campaigns against modern defense stacks?

Yes, you can use this methodology to plan spear-phishing campaigns against modern defense stacks, providing detailed strategies for payload hosting and evading endpoint defenses to gain a secure foothold.

Do I need to understand MITRE ATT&CK TA0001 before executing initial access techniques?

Understanding MITRE ATT&CK TA0001 is necessary as this Skill requires knowledge of various infection vectors, payload hosting, and modern cyber defense stacks to effectively execute initial access techniques.

What initial access vectors are covered beyond phishing?

Beyond phishing, the initial access vectors covered include credential stuffing, exploitation of exposed services, and supply chain attacks, providing a comprehensive checklist for offensive security engagements.