Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Offensive Security Analyst

  • 27 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Guides authorized offensive security work: engagement scoping, reconnaissance, vulnerability validation, exploitation PoCs, attack-path chaining, and remediation reporting.

About

Guides authorized offensive security and red-team work covering scoping, recon, vulnerability validation, PoC exploitation, MITRE ATT&CK mapping, and remediation reporting. A developer uses it when planning penetration tests, validating findings with reproducible PoCs, or writing offensive findings for remediation.

  • Requires written authorization and defines ROE, severity rubric, and emergency stop
  • Chains findings into attack paths from initial access to objective with evidence

Offensive Security Analyst by the numbers

  • 27 all-time installs (skills.sh)
  • Ranked #1,533 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill offensive-security-analyst

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs27
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Guides authorized offensive security work: engagement scoping, reconnaissance, vulnerability validation, exploitation PoCs, attack-path chaining, and remediation reporting.

Files

SKILL.mdMarkdownGitHub ↗

Offensive Security Analyst

When to Use

  • Plan or execute authorized penetration tests, red-team exercises, or exploit validation
  • Confirm rules of engagement, in-scope assets, test windows, and emergency stop conditions
  • Perform reconnaissance, vulnerability validation, PoC development, and attack-path chaining within scope
  • Prioritize exploitable findings by impact and likelihood
  • Write remediation-focused offensive security reports and retest plans

When NOT to Use

  • Investigate SOC alerts, logs, or suspicious activity → defensive-security-analyst
  • Define security strategy, policy, or GRC program direction → cybersecurity
  • Add CI/CD or supply-chain security controls → devsecops
  • Implement enterprise security tooling and guardrails → information-security-engineer
  • Test LLM prompts, agent tools, or AI jailbreak resistance → ai-redteam

Related skills

NeedSkill
CVD intake, embargo, advisory publicationtechnical-program-manager-security-cvd
Blue-team triage and detectionsdefensive-security-analyst
Security program, policies, IR programcybersecurity
Pipeline and supply-chain testing in CIdevsecops
LLM/agent adversarial testingai-redteam
Findings documentation for customerstech-writer-researcher

Core Workflows

1. Engagement scope and authorization

Do not test without written authorization.

1. Confirm signed SOW/ROE: in-scope assets, methods, windows, contacts 2. Define out-of-scope (prod data destruction, social engineering, DoS unless approved) 3. Set severity rubric aligned with customer 4. Establish emergency stop and escalation path 5. Use isolated lab or designated test tenants when possible

See `references/engagement_scope.md` for ROE checklist and severity rubric.

2. Reconnaissance and enumeration

passive OSINT → asset inventory → service/version ID → auth surface mapping → prioritize targets

Document everything: source, timestamp, tool, raw output hash or path.

See `references/recon_enumeration.md` for recon phases and asset tracking.

3. Vulnerability assessment and validation

1. Run scans appropriate to scope (authenticated where allowed) 2. Validate each finding manually—no report-only scanner noise 3. Classify: exploitable, conditional, informational 4. Map to CWE/CVE and ATT&CK where applicable 5. Note compensating controls that block exploitation

See `references/vulnerability_assessment.md` for validation criteria and false positive filters.

4. Exploitation and attack paths

PoC requirements:

  • Minimal steps to demonstrate impact
  • Evidence: request/response, screenshot, command output
  • Clear preconditions (role, network position, config)
  • Stop at agreed impact (e.g., proof of RCE without lateral movement unless scoped)

Chain findings into attack paths: initial access → privilege → objective.

See `references/exploitation_chain.md` for PoC template and chaining worksheet.

5. Post-exploitation (when in scope)

Only within ROE:

  • Credential access proof (hashed, not exfiltrating real secrets unnecessarily)
  • Lateral movement to agreed segment
  • Data access proof without excessive collection

Document cleanup: accounts created, shells, persistence removed before closeout.

6. Reporting and remediation

Per finding:

FieldContent
TitleBusiness-readable
SeverityPer agreed rubric
DescriptionWhat and where
ImpactConfidentiality, integrity, availability
ReproductionNumbered steps
EvidenceRedacted artifacts
RemediationSpecific fix + validation retest

Deliver executive summary + technical appendix; schedule retest for critical/high.

See `references/reporting_remediation.md` for report structure and retest checklist.

When to load references

  • Scope, ROE, authorizationreferences/engagement_scope.md
  • Recon and enumerationreferences/recon_enumeration.md
  • Scanning and validationreferences/vulnerability_assessment.md
  • PoCs and attack pathsreferences/exploitation_chain.md
  • Reports and retestreferences/reporting_remediation.md

Related skills

Securityauditappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.