What problem does it solve?
Security teams and penetration testers often lack a structured, comprehensive guide to testing Proxmox VE virtualization hosts, leading to missed attack surfaces like guest escapes, API misconfigurations, and supply chain attack paths that can compromise entire isolated networks.
Core Features & Use Cases
- Full Attack Surface Coverage: Includes guidance for testing Proxmox web UI, REST API, KVM/QEMU VMs, LXC containers, network pivoting, and post-exploitation activities.
- Pre-Built Tools & References: Comes with a one-shot enumeration script, CVE reference matrices for Proxmox 8.x/9.x, and lab-specific configuration details for realistic testing scenarios.
- Use Case: A red teamer can use this skill to pivot from a compromised web server into an isolated Proxmox-managed network, extract CI/CD deploy keys, poison internal dependencies, and trace a full supply chain attack path to production systems.
Quick Start
Use the proxmox-pentesting skill to perform a full security assessment of a target Proxmox VE host, including reconnaissance, vulnerability identification, guest escape testing, and lateral movement validation.