offensive-security-analyst

Plan and execute authorized offensive security engagements with scoping, PoC development, and MITRE ATT&CK mapping.

7|1|Updated May 19, 2026
One-click install
npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill offensive-security-analyst
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: offensive-security-analyst
Source: https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill/tree/main/offensive-security-analyst
Command: npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill offensive-security-analyst

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Guides teams to plan and execute authorized offensive security work with clear scope, rules of engagement, and reproducible findings.

Core Features & Use Cases

  • Engagement scoping and ROE workflow: Define scope, ROE, and emergency stop conditions, ensuring testing stays within approved boundaries.
  • Reconnaissance, vulnerability validation, and PoC development: Conduct OSINT, verify findings with reproducible PoCs, and document attack-path strategies.
  • Attack-path mapping and remediation reporting: Map findings to MITRE ATT&CK techniques and deliver remediation-focused reports for engineering teams.

Quick Start

Outline your authorized scope and ROE, then start reconnaissance and PoC development for the approved targets.

Frequently Asked Questions about offensive-security-analyst

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan authorized penetration testing with clear rules of engagement?

Plan authorized penetration testing by defining the engagement scope, rules of engagement (ROE), and emergency stop conditions to ensure testing stays within approved boundaries and maintains operational safety.

How do I map attack paths to MITRE ATT&CK techniques during red-team operations?

Map attack paths to MITRE ATT&CK techniques by validating vulnerabilities with reproducible PoCs, documenting the exploitation chain, and aligning the findings with specific ATT&CK tactics for structured remediation reporting.

What is the best way to document reproducible PoCs for penetration testing findings?

Document reproducible PoCs for penetration testing by validating discovered vulnerabilities through structured execution, capturing the precise reproduction steps, and mapping the results to the client-focused remediation deliverables.

Can I scope offensive security engagements and define emergency stop conditions before reconnaissance?

Yes, you can scope offensive security engagements and define emergency stop conditions before reconnaissance by establishing a structured ROE workflow that sets approved target boundaries prior to any active OSINT gathering.

Does MITRE ATT&CK mapping fit into standard remediation reporting for engineering teams?

MITRE ATT&CK mapping fits into remediation reporting by translating validated attack-path strategies into structured, client-focused deliverables that provide engineering teams with clear, actionable vulnerability remediation guidance.

When should I not use automated reconnaissance in offensive security engagements?

You should not use automated reconnaissance when it exceeds the defined rules of engagement (ROE) or violates the approved scope, as strict boundary enforcement is required to maintain authorized testing compliance.