offensive-security

Execute authorized offensive security testing workflows with structured commands and safety checks.

4|Updated Apr 9, 2026
One-click install
npx skills add https://github.com/thejordanleopold/claude-code-skills-distilled --skill offensive-security
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: offensive-security
Source: https://github.com/thejordanleopold/claude-code-skills-distilled/tree/main/offensive-security
Command: npx skills add https://github.com/thejordanleopold/claude-code-skills-distilled --skill offensive-security

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides structured guidance, techniques, and practical command references for authorized offensive security testing, enabling safe, scoped engagements.

Core Features & Use Cases

  • Recon and initial access techniques for authorized engagements, including OSINT, active scanning, and service discovery.
  • Web application attack patterns and defense-aware exploitation workflows, with example payloads and remediation considerations.
  • Privilege escalation, lateral movement, and persistence patterns across Linux, Windows, and Active Directory in controlled labs and engagements.
  • Cloud and container offensive techniques for misconfiguration discovery, IAM escalation, and containment-aware testing.

Quick Start

Begin with a clearly scoped engagement, then consult the recon and initial access sections to plan your approach.

Frequently Asked Questions about offensive-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a structured penetration test in an authorized environment?

To perform authorized offensive security testing, use structured workflows that cover reconnaissance, web application attacks, privilege escalation, and Active Directory attacks. The process requires explicit permission, a defined scope, and auditable procedures with safety checks to prevent harm.

What is the best way to escalate privileges during a red team exercise?

Privilege escalation during red team exercises involves leveraging specific patterns across Linux, Windows, and Active Directory environments. The approach provides technique-specific commands for lateral movement and persistence, ensuring actions remain within controlled labs and consented engagement scopes.

Can I use this for cloud and container security testing?

Cloud and container security testing is supported through techniques for misconfiguration discovery and IAM escalation. The workflows provide containment-aware testing steps to ensure cloud environments remain secure while identifying potential vulnerabilities during authorized engagements.

Do I need defined scope and explicit permission before starting a pentest?

Explicit permission and a defined scope are mandatory before starting any offensive security testing. The structured guidance enforces safety checks and auditable procedures to guarantee all reconnaissance, exploitation, and lateral movement actions occur strictly within consented environments.

What web application attack patterns are available for CTF challenges?

Web application attack patterns for CTF challenges include defense-aware exploitation workflows with example payloads. These structured techniques cover initial access and service discovery, providing remediation considerations alongside the practical commands needed to execute authorized tests.