post-exploitation

Coordinate post-exploitation operations across escalation, persistence, lateral movement, data collection, and exfiltration.

60|14|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/brucesongs/kali-claw --skill post-exploitation
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: post-exploitation
Source: https://github.com/brucesongs/kali-claw/tree/main/skills/post-exploitation
Command: npx skills add https://github.com/brucesongs/kali-claw --skill post-exploitation

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Post-exploitation coordination empowers security teams and testers to manage the full attack chain after initial access, enabling consistent escalation, persistence, lateral movement, data collection, and exfiltration planning across engagements.

Core Features & Use Cases

  • End-to-end post-exploitation workflow orchestration across Windows and Linux targets.
  • Centralized guidance with payload references, test cases, and learning materials for repeatable assessments.
  • Use Case: In a red-team engagement, coordinate techniques to expand control while collecting assets and simulating defender responses.

Quick Start

Load this skill and follow the guided playbook to coordinate escalation, persistence, lateral movement, data collection, and exfiltration across an engagement.

Frequently Asked Questions about post-exploitation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is post-exploitation in a red-team engagement?

Post-exploitation coordinates escalation, persistence, lateral movement, data collection, and exfiltration across multi-platform environments. It enables deterministic playbooks for red-team engagements, security assessments, and defense exercises to maximize control after initial access.

How do I coordinate lateral movement and persistence across multiple targets?

You coordinate lateral movement and persistence by loading this skill to follow a guided playbook that orchestrates end-to-end post-exploitation workflows, defining required tools, techniques, and success criteria for deterministic automated execution across targets.

Does this post-exploitation workflow support both Windows and Linux targets?

Yes, the post-exploitation workflow orchestrates end-to-end operations across both Windows and Linux targets. It provides centralized guidance with payload references and test cases for repeatable multi-platform assessments.

Can I automate attack chain playbooks for security assessments?

Yes, you can automate attack chain playbooks. The skill defines required tools, workflows, usage patterns, core phases, techniques, and success criteria to enable deterministic playbooks and automated execution for ongoing defense exercises.

What's the best way to manage data collection and exfiltration during a pentest?

The best way to manage data collection and exfiltration is using a coordinated post-exploitation workflow that defines specific techniques and success criteria, ensuring consistent planning and execution across multi-platform environments during engagements.

Are there limitations when scaling post-exploitation techniques across large environments?

Limitations involve coordinating complex attack chains at scale across multi-platform environments. The skill addresses this by providing centralized guidance, payload references, and deterministic playbooks to maintain consistency during large red-team engagements.