tool-selection
Installation
SKILL.md
Tool Selection
Purpose
Use this skill to choose the smallest effective toolset for the current phase of an authorized assessment.
Phase-Based Selection
- Pre-Engagement: no active testing by default; confirm scope, windows, credentials, exclusions, and safety limits before selecting tools.
- Discovery and Reconnaissance:
amass,subfinder,nmap,masscan,theharvester,recon-ng,dnsrecon,dnsenum,httpx,whatweb,gowitness,gobuster,feroxbuster,dirsearch,dirbuster,dirb,ldapsearch,ldapdomaindump,rpcclient,smbclient,smbmap,nbtscan,onesixtyone,snmpwalk,kerbrute,adfind,powerview,sharphound,aws-cli,az-cli,gcloud,kubectl,tcpdump,curl - Threat Modeling and Test Planning: use discovery outputs to narrow
nmap,dnsrecon,theharvester,recon-ng,httpx,whatweb,gowitness,searchsploit,semgrep,bloodhound,certipy,impacket-lookupsid,scoutsuite,kubectl,trivy,adfind,powerview,sharphound, andrubeuscoverage instead of expanding tool count. - Vulnerability Analysis:
nuclei,nikto,burp-suite,owasp-zap,ffuf,wfuzz,gobuster,feroxbuster,dirsearch,dirbuster,dirb,dalfox,commix,testssl-sh,searchsploit,prowler,aws-cli,az-cli,gcloud,scoutsuite,pacu,semgrep,enum4linux-ng,ldapsearch,ldapdomaindump,rpcclient,smbclient,smbmap,nbtscan,onesixtyone,snmpwalk,wpscan,bloodhound,certipy,kubectl,kube-bench,kube-hunter,trivy,gitleaks,trufflehog,netexec,sqlmap,impacket-getuserspns,impacket-getnpusers,mimikatz,rubeus,powerview,sharphound,adfind,procdump,lazagne,linpeas,winpeas,pspy,linux-exploit-suggester,seatbelt,certutil,bitsadmin,curl,plink,chisel,rclone,7zip,winrar,nessus,openvas - Validation and Controlled Impact Demonstration:
burp-suite,owasp-zap, focusednmap, narrowffuf,wfuzz, targetednucleireruns,sqlmapwith the lowest safe settings,commixonly for explicitly approved command-injection validation,hydraonly for explicitly approved low-rate credential checks, offlinejohn-the-ripperorhashcatfor approved hash auditing,responderandmitm6only when name-resolution testing is explicitly authorized, tightly scoped execution or credential checks withevil-winrm,impacket-psexec,impacket-wmiexec,impacket-smbexec,impacket-secretsdump, andimpacket-ntlmrelayxonly when the rules of engagement clearly permit them, tightly scoped credential or ticket validation withmimikatz,rubeus,procdump, andlazagneonly when explicitly approved, tightly scoped tunneling and transfer checks withnetcat,socat,proxychains,plink,chisel,curl,certutil,bitsadmin,rclone,7zip, andwinraronly when the rules of engagement clearly permit them, andmetasploit-frameworkonly for explicitly approved, narrowly bounded auxiliary or exploit validation paths - Detection and Response Assessment:
wiresharkplus defender-side telemetry - Reporting: normalize evidence, tie each observation to an asset, and map findings to business impact.
- Retest and Closure: rerun only the minimum tool and scope needed to confirm the fix.