pentest-playbook

Orchestrate a 7-phase offensive security methodology for penetration testing and bug bounty hunting.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill pentest-playbook-entrovyx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pentest-playbook
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/meta/pentest-playbook
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill pentest-playbook-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill solves the lack of a structured, repeatable methodology in offensive security engagements, preventing missed attack vectors and inefficient manual testing.

Core Features & Use Cases

  • 7-Phase Pipeline: Provides a standardized workflow from passive reconnaissance to final reporting.
  • Lateral Pivot Decision Matrix: Offers critical guidance on when to switch attack vectors to maximize impact.
  • Use Case: Use this skill when starting a new bug bounty or pentest engagement to ensure comprehensive coverage of all attack surfaces, including cloud, web, and infrastructure.

Quick Start

Load the pentest-playbook skill to initiate the passive reconnaissance phase for your target domain.

Frequently Asked Questions about pentest-playbook

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is the best way to structure a penetration testing methodology for bug bounty hunting?

A structured penetration testing methodology uses a 7-phase offensive security lifecycle to standardize workflows from passive reconnaissance to final reporting, preventing missed attack vectors and inefficient manual testing. It ensures systematic vulnerability discovery across web, cloud, and infrastructure targets.

How do I conduct comprehensive reconnaissance and lateral movement across cloud and infrastructure targets?

Comprehensive reconnaissance and lateral movement require orchestrating a standardized 7-phase offensive security pipeline. This methodology facilitates systematic vulnerability discovery across web, cloud, and infrastructure targets while using a lateral pivot decision matrix to guide when to switch attack vectors.

When should I pivot attack vectors during a pentest engagement to maximize impact?

You should pivot attack vectors during a pentest engagement when defined pivot triggers and verification gates indicate a need to switch targets. A lateral pivot decision matrix provides critical guidance on when to change attack vectors to maximize security finding impact.

Can I use a single offensive security workflow for web, cloud, and infrastructure bug bounty targets?

Yes, a single offensive security workflow can cover web, cloud, and infrastructure bug bounty targets. This 7-phase pipeline ensures comprehensive coverage of all attack surfaces by facilitating systematic reconnaissance and exploitation across diverse environments during a single engagement.

How do I ensure my penetration testing findings are reproducible and high-impact?

To ensure reproducible and high-impact penetration testing findings, adhere to defined verification gates within a 7-phase offensive security methodology. This structured approach standardizes vulnerability discovery and enforces verification before final reporting, yielding reliable security results.