offsec-campaign-orchestrator

Orchestrate multi-stage offensive security campaigns with target dossiers and request maps.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill offsec-campaign-orchestrator
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: offsec-campaign-orchestrator
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/meta/offsec-campaign-orchestrator
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill offsec-campaign-orchestrator

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill solves the fragmentation of offensive security testing by providing a unified, stateful framework to manage complex, multi-stage hunting campaigns from initial reconnaissance to final reporting.

Core Features & Use Cases

  • Campaign Orchestration: Coordinates crown-jewel identification, target dossier maintenance, and deep-hunt workflows.
  • Traffic Analysis: Integrates HAR and Burp request imports into a structured offensive request map.
  • Exploit Chaining: Facilitates the transition from isolated primitives to high-impact exploit chains.
  • Use Case: A security researcher can use this to map out a target's attack surface, import captured traffic, and systematically execute a deep-hunt on business logic while maintaining a persistent dossier of findings.

Quick Start

Invoke the offsec campaign orchestrator to initialize a new target dossier and begin the crown-jewel identification process for the specified domain.

Frequently Asked Questions about offsec-campaign-orchestrator

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I manage multi-stage pentesting workflows and track isolated exploit primitives?

Manage multi-stage pentesting workflows by orchestrating end-to-end offensive campaigns that maintain persistent target dossiers, track isolated exploit primitives, and synthesize them into high-impact exploit chains.

What is the best way to organize bug bounty hunting campaigns from reconnaissance to reporting?

Organize bug bounty hunting campaigns using a unified, stateful framework that coordinates crown-jewel identification, deep-hunt workflows, and evidence synthesis from initial reconnaissance through to final reporting.

Can I import HAR and Burp request files to map an attack surface during security assessments?

You can import HAR and Burp request files to map an attack surface. The framework integrates captured traffic into a structured offensive request map for systematic security assessments.

How do I maintain persistent state and evidence synthesis for manual security assessments?

Maintain persistent state for manual security assessments by initializing a target dossier that continuously tracks findings, manages request maps, and synthesizes evidence across multi-stage attack workflows.

Does this offensive security framework work for tracking business logic vulnerabilities during a deep-hunt?

This offensive security framework works for tracking business logic vulnerabilities by systematically executing deep-hunt workflows on target domains while maintaining a persistent dossier of findings and hypotheses.

What are the limitations of using a stateful framework for penetration testing campaign management?

A stateful framework for penetration testing requires structured hypothesis tracking and persistent state management, meaning unstructured or ad-hoc testing without clear campaign phases may not fit the orchestrated workflow.