AgentStack
SKILL verified Apache-2.0 Self-run

Pt Post Exploitation

skill-santosomar-ethical-hacking-agent-skills-pt-post-exploitation · by santosomar

Performs authorized post-exploitation activities to assess impact, lateral movement paths, credential exposure, and detection gaps after initial compromise. Use when a foothold has been validated and the test requires controlled impact expansion analysis.

No reviews yet
0 installs
15 views
0.0% view→install

Install

$ agentstack add skill-santosomar-ethical-hacking-agent-skills-pt-post-exploitation

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Pt Post Exploitation? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Post-Exploitation

Authorized Use Only

Run post-exploitation tasks only after explicit approval for this phase. Keep actions controlled, reversible, and auditable. Avoid destructive changes and unnecessary access to sensitive data.

Objectives

  1. Measure realistic impact after initial access.
  2. Evaluate privilege escalation and lateral movement opportunities.
  3. Identify credential and data exposure paths.
  4. Assess logging, detection, and response effectiveness.

Workflow

  1. Confirm phase boundaries:
  • Allowed techniques, prohibited actions, and stop conditions
  • Approved systems, accounts, and time windows
  1. Stabilize foothold context:
  • Document current privileges and reachable assets
  • Capture baseline telemetry and controls in place
  1. Conduct controlled post-exploitation checks:
  • Privilege escalation feasibility
  • Credential access and reuse opportunities
  • Lateral movement paths through trust relationships
  • Data access paths tied to business impact
  1. Evaluate defense visibility:
  • Which actions generated alerts
  • How quickly detection and containment occurred
  1. Cleanup and rollback:
  • Remove all artifacts created during testing
  • Verify environment returns to expected state

Output Template

# Post-Exploitation Output

## Initial Context
- Entry point:
- Starting privilege:
- Scope constraints:

## Escalation and Movement Findings
- Finding:
  - Preconditions:
  - Evidence:
  - Result:
  - Impact:

## Credential and Data Exposure
- Exposure path:
  - Affected assets/data:
  - Business risk:

## Detection and Response
- Alerts observed:
- Time to detect:
- Time to contain:
- Gaps:

## Cleanup Verification
- Artifacts removed:
- Validation notes:

Quality Checks

  • Every action is within approved boundaries.
  • Evidence supports reproducibility without sensitive data leakage.
  • Findings map clearly from technical path to business consequence.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.