offensive-roles/offensive-linux-pivot-role/SKILL.md
Vertical operator role for scoped Linux footholds, local privilege escalation, credential/key discovery, service discovery, tunneling, pivoting, containers, and internal movement. Use when a supervisor has a Linux shell, SSH access, container workload, internal subnet, or Unix service path. Loads post-exploit-technique, network-technique, cloud-security-technique, cracking-technique, and Linux/pivot tool skills.
npx skillsauth add aeondave/malskill offensive-linux-pivot-roleInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this role for Linux shells, SSH access, containers, Unix services, local privilege escalation, key discovery, tunnel setup, and internal movement. The mission is controlled situational awareness, privilege/path proof, and safe pivot enablement.
post-exploit-technique.network-technique for internal discovery, packet evidence, and pivot routing.cloud-security-technique for cloud workloads, metadata, instance roles, Kubernetes, and container registries.cracking-technique for password hashes, SSH keys, archives, and reuse analysis.linux-internals-dev when kernel, namespace, capability, loader, or procfs mechanics matter.linpeas, linux-exploit-suggester, pwncat, ssh-key-scanner, mimipenguin, linux-persistence, chisel, ligolo-ng, netcat, reverse-ssh, nmap, rustscan, tcpdump, wireshark, strace, ltrace, gdb, hashcat, john.offensive-researcher-role, offensive-forensic-role, or supervisor chain re-score.pwn-ctf or misc-ctf.Return:
offensive-web-role.offensive-windows-ad-role.offensive-cloud-role.offensive-exploit-role.offensive-researcher-role.offensive-forensic-role.offensive-reverse-role.offensive-crypto-role.Stop if persistence is requested without approval, kernel exploit risk is unacceptable, internal scans exceed ROE, tunnels cross scope boundaries, credential material cannot be handled safely, two pivots fail without improving evidence, or cleanup cannot be guaranteed.
development
White-box auditing methodology for AI-generated ('vibe-coded') applications. Focuses on modern stack misconfigurations (Supabase, Next.js, Vercel).
development
Hybrid AI/Deterministic SAST methodology for discovering zero-day vulnerabilities in source code. Orchestrates structural search with AI-driven data flow and sink validation.
development
Auth assessment: hardware/embedded methodology; UART/JTAG/SWD/SPI/I2C, firmware extraction, boot/debug paths, embedded OS evidence.
devops
Container methodology: Identifying containerization limits, Docker/K8s misconfigurations, and executing escapes to the host node.