security-pentest-exploitation-planning

Plan exploitation and adversary simulation for authorized penetration tests.

Updated May 28, 2026
One-click install
npx skills add https://github.com/SensLiao/Claude-code-setting --skill security-pentest-exploitation-planning
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-pentest-exploitation-planning
Source: https://github.com/SensLiao/Claude-code-setting/tree/main/skills/security-pentest-exploitation-planning
Command: npx skills add https://github.com/SensLiao/Claude-code-setting --skill security-pentest-exploitation-planning

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a structured approach to planning and scoping the exploitation and adversary simulation layers of an authorized penetration test, ensuring safety and compliance with regulations.

Core Features & Use Cases

  • Planning for Exploitation: Helps operators understand the role of each tool, scope them within the ROE, and map them to relevant standards and techniques.
  • Adversary Simulation: Provides a reference for adversary simulation frameworks like Sliver and Caldera, focusing on planning rather than execution.
  • Cloud and AD Tooling: Offers guidance on cloud exploitation and Active Directory tools like Pacu and BloodHound, emphasizing planning and non-destructive operations.

Quick Start

Use the security-pentest-exploitation-planning skill to review the planning requirements for an AWS exploitation task within the scope of an authorized penetration test.

Frequently Asked Questions about security-pentest-exploitation-planning

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan exploitation steps for an authorized penetration test?

Adversary simulation planning uses frameworks like Sliver and Caldera as reference models. This approach focuses on mapping tool roles and techniques to standards during the planning phase, ensuring non-destructive operations before any authorized execution.

Can I use BloodHound and Pacu for Active Directory and cloud exploitation planning?

BloodHound and Pacu are referenced for Active Directory and cloud exploitation planning. The framework guides scoping these tools within the ROE, emphasizing planning and non-destructive operations rather than direct execution.

What is the role of the Rules of Engagement in penetration test exploitation?

The Rules of Engagement (ROE) define the authorized scope and boundaries for penetration test exploitation. This framework requires manual gate checks and ROE authorization to ensure all planned adversary simulation and tool usage remains compliant and safe.

Does this adversary simulation framework execute attacks automatically?

This adversary simulation framework does not execute attacks automatically. It functions strictly as a planning and reference resource, requiring a manual gate and explicit ROE authorization before any exploitation or simulation actions proceed.

What are the limitations of using a planning-only approach for penetration testing?

A planning-only approach limits users to reference and scoping tasks without executing actual exploitation. Operators must manually authorize and execute techniques through separate tools, ensuring all actions remain within the defined ROE boundaries.

Related Skills