iom-pentest

Automate penetration testing workflows via IoM MCP tools for reconnaissance and escalation.

482|68|Updated Sep 5, 2023
One-click install
npx skills add https://github.com/chainreactors/malice-network --skill iom-pentest
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: iom-pentest
Source: https://github.com/chainreactors/malice-network/tree/main/.claude/commands/iom-pentest
Command: npx skills add https://github.com/chainreactors/malice-network --skill iom-pentest

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Automates autonomous penetration testing workflows through IoM MCP tools to orchestrate reconnaissance, privilege escalation, credential harvesting, lateral movement, and persistence.

Core Features & Use Cases

  • End-to-end IoM MCP driven pentest lifecycle automation with phase-based orchestration
  • OODA loop based adaptive decision-making across reconnaissance, escalation, credentials, movement, and persistence
  • OPSEC-aware execution guidance, session management, and structured reporting for authorized assessments

Quick Start

Launch this skill and start the automated IoM-based pentest workflow to run reconnaissance, escalation, and lateral movement in an authorized environment.

Frequently Asked Questions about iom-pentest

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate penetration testing workflows with MCP tooling?

Automating penetration testing workflows with MCP tooling requires orchestrating reconnaissance, privilege escalation, credential harvesting, and lateral movement through phase-aware decision logic and OPSEC considerations. This skill drives that end-to-end lifecycle autonomously.

What is an OODA loop in the context of red-team assessments?

An OODA loop in red-team assessments is an adaptive decision-making cycle of Observe, Orient, Decide, and Act used to continuously adjust penetration tactics. This skill applies it across reconnaissance, escalation, and lateral movement phases.

Do I need an active implant session to run IoM-based pentest automation?

Yes, you need an active implant session to run IoM-based pentest automation. The workflow also requires access to IoM MCP tooling and IAM privilege context commands implemented via mcp__iom__execute_command for authorized assessments.

Can I use automated pentest workflows for Windows endpoints and enterprise networks?

Yes, you can use automated pentest workflows for Windows endpoints and enterprise networks. The skill orchestrates privilege escalation, credential harvesting, and lateral movement specifically across these environments for authorized assessments.

How do I maintain OPSEC during automated lateral movement and persistence?

Maintaining OPSEC during automated lateral movement and persistence requires phase-aware execution guidance and session management. This skill integrates OPSEC considerations directly into the adaptive decision-making loop for authorized red-team engagements.

What are the limitations of using autonomous penetration testing in IoM environments?

Limitations of autonomous penetration testing in IoM environments include the strict requirement for a working implant session and specific mcp__iom__execute_command implementations. It is constrained to authorized assessments and requires continuous IAM privilege context validation.