vmware-vcenter-attack

Identify and simulate attacks on VMware vCenter Server and Workspace ONE vulnerabilities.

5|Updated May 27, 2026
One-click install
npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill vmware-vcenter-attack-cybersecwoman
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vmware-vcenter-attack
Source: https://github.com/cybersecwoman/Kiro-BugHunter/tree/main/skills/vmware-vcenter-attack
Command: npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill vmware-vcenter-attack-cybersecwoman

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a comprehensive approach to identifying and exploiting vulnerabilities in VMware vCenter Server and Workspace ONE, enabling red team operations and security assessments.

Core Features & Use Cases

  • Vulnerability Identification: Scans for common and critical vulnerabilities in vCenter Server and Workspace ONE.
  • Exploit Simulation: Simulates the exploitation of identified vulnerabilities without causing actual harm.
  • Audit and Reporting: Generates detailed reports on the security posture of the targeted systems.

Quick Start

Run the skill with the target vCenter Server's IP address: /vmware-vcenter-attack target.com

Frequently Asked Questions about vmware-vcenter-attack

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I identify vulnerabilities in VMware vCenter Server during a security audit?

To identify vulnerabilities in VMware vCenter Server, you simulate attacks using known CVEs and version fingerprinting. This process scans for critical flaws and default credentials, generating detailed reports on the system's security posture.

Can I simulate CVE exploitation against VMware Workspace ONE without causing harm?

Yes, you can simulate CVE exploitation against VMware Workspace ONE without causing actual harm. The attack simulation tests known vulnerabilities safely, enabling red team operations while maintaining system integrity during the security assessment.

What do I need to run a red team attack simulation on vCenter Server?

To run a red team attack simulation on vCenter Server, you need external access to the target systems. Provide the target IP address or domain, and the skill will handle version fingerprinting and default credential checks automatically.

Does vCenter Server security auditing check for default credentials?

Yes, vCenter Server security auditing includes default credential checks as a core feature. Alongside version fingerprinting and CVE exploitation simulation, it verifies if default credentials are active to assess target vulnerability.

What is the best way to fingerprint VMware vCenter versions for security assessments?

The best way to fingerprint VMware vCenter versions is by running an automated attack simulation against the target IP. This identifies the exact version and maps it against known vulnerabilities to streamline red team operations.