بنقرة واحدة
host-privesc-hunter
Local privilege-escalation assessment on an authorized host where you already have a foothold (operator-provided shell/session). Runs and interprets enumeration - linpeas/LinEnum/pspy/linux-exploit-suggester on Linux; winPEAS/Seatbelt/PowerUp on Windows - and maps findings to concrete escalation paths via GTFOBins (sudo/SUID) and LOLBAS, plus writable services/cron/systemd/scheduled-tasks, kernel-exploit candidates, secrets in files/history, and token/capability abuse. Proves escalation with the least-damage check (id/whoami as root/SYSTEM) and stops. The post-exploitation companion to network-pentest-hunter and the AD chain. Requires .claude/security-scope.yaml red_team_ops.host_privesc: approved and the host in scope. Grounded in redteam-ops.
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.