initial-access

Plan initial-access techniques for offensive security engagements.

338|59|Updated May 19, 2026
One-click install
npx skills add https://github.com/hypnguyen1209/offensive-claude --skill initial-access-hypnguyen1209
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: initial-access
Source: https://github.com/hypnguyen1209/offensive-claude/tree/main/skills/initial-access
Command: npx skills add https://github.com/hypnguyen1209/offensive-claude --skill initial-access-hypnguyen1209

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides practical guidance to plan, simulate, and execute initial-access techniques for offensive security engagements, enabling controlled red-team exercises and risk assessment.

Core Features & Use Cases

  • Phishing campaign planning: design convincing lure emails and payload delivery tactics that align with engagement rules.
  • Payload delivery & evasion concepts: outline delivery methods, bypass considerations, and post-delivery objectives in lab environments.
  • Threat model awareness: highlight HTML smuggling, ISO/IMG bypass, supply-chain considerations, and credential-stuffing scenarios to evaluate defenses.

Quick Start

Provide your target context and I will outline an initial-access plan using phishing, payload delivery, and evasion techniques.

Frequently Asked Questions about initial-access

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan an initial-access phishing campaign for a red-team engagement?

Payload delivery evasion concepts outline delivery methods, EDR bypass considerations, and post-delivery objectives. They evaluate target defenses by simulating threat models in controlled lab environments.

How does HTML smuggling facilitate initial access during offensive security assessments?

HTML smuggling enables initial access by dropping payload files through browser-generated blobs to bypass network filters. It evaluates target defenses against HTML smuggling, ISO/IMG bypass, and supply-chain attack scenarios.

Can I use ISO bypass techniques to evade EDR for payload delivery?

Yes, ISO/IMG bypass techniques evade EDR by leveraging container files to execute payloads. They are applied to evaluate defensive controls and outline post-delivery objectives safely within lab environments.

What is the best way to simulate credential stuffing for initial foothold risk assessment?

The best way to simulate credential stuffing for initial foothold risk assessment is applying structured attack vectors against target environments. This evaluates defense mitigations and ensures repeatable, auditable results.

What are the limitations of using initial-access techniques for supply-chain attacks?

Limitations of initial-access supply-chain attacks include requiring lab-safe execution guidelines to avoid unintended impact. They demand a structured understanding of attack vectors and mitigations to ensure controlled risk assessment.