一键导入
host-privesc-hunter
Local privilege-escalation assessment on an authorized host where you already have a foothold (operator-provided shell/session). Runs and interprets enumeration - linpeas/LinEnum/pspy/linux-exploit-suggester on Linux; winPEAS/Seatbelt/PowerUp on Windows - and maps findings to concrete escalation paths via GTFOBins (sudo/SUID) and LOLBAS, plus writable services/cron/systemd/scheduled-tasks, kernel-exploit candidates, secrets in files/history, and token/capability abuse. Proves escalation with the least-damage check (id/whoami as root/SYSTEM) and stops. The post-exploitation companion to network-pentest-hunter and the AD chain. Requires .claude/security-scope.yaml red_team_ops.host_privesc: approved and the host in scope. Grounded in redteam-ops.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。