vuln-exploit-technique
Installation
SKILL.md
Vuln-exploit technique
Goal: reliably achieve initial access by exploiting a confirmed vulnerability, then hand off a stable session to post-exploitation.
When this technique applies
vuln-search-techniquehas produced confirmed, prioritized findings.- A specific CVE, vulnerability class, or service weakness is confirmed in scope.
- Need to turn a confirmed vulnerability into a shell/session (initial access).
- Engagement requires documented exploitation path, not just finding identification.
Boundary
- Input from
vuln-search-technique: confirmed infrastructure/service vulnerability with CVE, version, service details. Web class vulns →web-exploit-technique. - Not covered: post-exploitation lateral movement, privilege escalation after initial shell — those are separate engagements.
- Memory-corruption methodology: turning a confirmed binary corruption primitive (stack/heap overflow, UAF, format string) into controlled impact → load
offensive-techniques/binary-exploitation-technique/. - Offensive coding: custom exploit development at depth (Python exploit harnesses, C PoCs, shellcode, ROP, heap exploitation) → load
coding/python-patterns/,coding/c-patterns/,offensive-coding/shellcode-dev/,offensive-coding/rop-development-dev/, oroffensive-coding/heap-exploitation-dev/as needed. - EDR evasion: payload evasion for hardened targets → load
offensive-coding/edr-evasion-dev/.