offensive-windows-boundaries

Map Windows security boundaries for privilege escalation planning and sandbox research.

1|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/riparino/Claude-Cyber --skill offensive-windows-boundaries
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: offensive-windows-boundaries
Source: https://github.com/riparino/Claude-Cyber/tree/main/Claude-Red/Skills/offensive-windows-boundaries
Command: npx skills add https://github.com/riparino/Claude-Cyber --skill offensive-windows-boundaries

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps security teams and researchers map Windows security boundaries and attack surfaces to inform privilege escalation planning, sandbox research, and defense design.

Core Features & Use Cases

  • Enumerates kernel/user boundaries, sandbox boundaries (LPAC, AppContainer), COM/RPC boundaries, and hypervisor boundaries.
  • Provides a taxonomy-driven view for attack surface enumeration and security architecture analysis.
  • Use Case: assess a Windows target to identify protection gaps and plan mitigations or controlled testing.

Quick Start

Run this skill to enumerate Windows boundary types and plan security assessments.

Frequently Asked Questions about offensive-windows-boundaries

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enumerate Windows security boundaries for privilege escalation planning?

To enumerate Windows security boundaries for privilege escalation, map kernel/user, sandbox, COM/RPC, and hypervisor boundaries using a taxonomy-driven approach to identify attack surfaces and plan controlled testing.

What's the best way to map Windows sandbox boundaries like AppContainer and LPAC?

Mapping Windows sandbox boundaries like AppContainer and LPAC involves identifying trust transitions and protection gaps within the security architecture. This taxonomy-driven enumeration provides actionable guidance for sandbox research and defense design.

Can I use this for hypervisor boundary and trust transition analysis?

Yes, this Skill enumerates hypervisor boundaries and trust transitions alongside kernel/user and COM/RPC boundaries. It applies taxonomy-based boundary enumeration to inform security architecture assessments and red-team planning.

Does this approach support defensive security architecture reviews as well as red-team planning?

Yes, mapping Windows security boundaries supports both red-team planning and defensive reviews. Enumerating attack surfaces and trust transitions helps security teams identify protection gaps and design effective mitigations across Windows environments.

What Windows boundary types are covered in attack surface enumeration?

Attack surface enumeration covers kernel/user boundaries, sandbox boundaries like LPAC and AppContainer, COM/RPC boundaries, and hypervisor boundaries. This taxonomy-driven mapping identifies trust transitions to guide privilege escalation planning.