engagement-flow

Featured

Use when starting, planning, or running a multi-phase pentest or red-team engagement — to sequence the Cyber Kill Chain phases with quality gates instead of jumping straight to exploitation

AI & Automation 382 stars 66 forks Updated 5 days ago MIT

Install

View on GitHub

Quality Score: 89/100

Stars 20%
86
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Engagement Flow ## Overview A pentest/red-team engagement is a **phased pipeline with gates**, not a pile of techniques run ad hoc. This skill sequences the 9-phase Lockheed Martin Cyber Kill Chain and routes each phase to its commands, domain skills, and discipline checks. It is the offensive analog of brainstorming → writing-plans → executing-plans: scope the work, plan it, then execute phase by phase. Don't jump to exploitation. Earlier phases earn the access that later phases need, and each gate keeps quality high before you advance. ## The pipeline ```dot digraph killchain { rankdir=LR; scope -> recon -> weaponize -> deliver -> exploit -> install -> c2 -> actions -> report; scope [label="0 SCOPE"]; recon [label="1 RECON"]; weaponize [label="2 WEAPONIZE"]; deliver [label="3 DELIVER"]; exploit [label="4 EXPLOIT"]; install [label="5 INSTALL"]; c2 [label="6 C2"]; actions [label="7 ACTIONS"]; report [label="8 REPORT"]; } ``` Each transition requires a **gate** (`/engage.gate`): required artifacts present, findings carry CWE+CVSS+ATT&CK+evidence, and the automated checks pass. Gate FAIL → fix the gap before advancing. ## How to run it 1. Pick the workflow preset for the engagement type (web-app, network, red-team, cloud, mobile, ad-domain, bug-bounty) and drive phases with the `/engage.*` commands. 2. **Phase 0 (scope):** emit `.engage/scope/scope.json`. **REQUIRED:** scope-discipline. 3. **Phases 1-7:** before any target interaction → scope-di...

Details

Author
hypnguyen1209
Repository
hypnguyen1209/offensive-claude
Created
4 months ago
Last Updated
5 days ago
Language
Python
License
MIT

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category