offensive-roles/offensive-linux-pivot-role/SKILL.md
Vertical operator role for scoped Linux footholds, local privilege escalation, credential/key discovery, service discovery, tunneling, pivoting, containers, and internal movement. Use when a supervisor has a Linux shell, SSH access, container workload, internal subnet, or Unix service path. Loads post-exploit-technique, network-technique, cloud-security-technique, cracking-technique, and Linux/pivot tool skills.
npx skillsauth add aeondave/malskill offensive-linux-pivot-roleInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this role for Linux shells, SSH access, containers, Unix services, local privilege escalation, key discovery, tunnel setup, and internal movement. The mission is controlled situational awareness, privilege/path proof, and safe pivot enablement.
post-exploit-technique.network-technique for internal discovery, packet evidence, and pivot routing.cloud-security-technique for cloud workloads, metadata, instance roles, Kubernetes, and container registries.cracking-technique for password hashes, SSH keys, archives, and reuse analysis.linux-internals-dev when kernel, namespace, capability, loader, or procfs mechanics matter.linpeas, linux-exploit-suggester, pwncat, ssh-key-scanner, mimipenguin, linux-persistence, chisel, ligolo-ng, netcat, reverse-ssh, nmap, rustscan, tcpdump, wireshark, strace, ltrace, gdb, hashcat, john.offensive-researcher-role, offensive-forensic-role, or supervisor chain re-score.pwn-ctf or misc-ctf.Return:
offensive-web-role.offensive-windows-ad-role.offensive-cloud-role.offensive-exploit-role.offensive-researcher-role.offensive-forensic-role.offensive-reverse-role.offensive-crypto-role.Stop if persistence is requested without approval, kernel exploit risk is unacceptable, internal scans exceed ROE, tunnels cross scope boundaries, credential material cannot be handled safely, two pivots fail without improving evidence, or cleanup cannot be guaranteed.
development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.