Privesc Win
pale-knight/redteam-skillWindows local privilege escalation from a low-privilege shell to Administrator or SYSTEM. Covers quiet vs loud enumeration, SeImpersonate/Potato family including LocalPotato, token privileges (SeBackup/SeRestore/SeManageVolume/SeLoadDriver/SeDebug), service/DLL/COM/scheduled-task abuse, AlwaysInstallElevated and UAC boundary, KrbRelayUp-style domain-joined local admin, and version-gated kernel LPE. Use when the operator already has a Windows foothold and needs local SYSTEM. Endpoint blocks hand off to /edr-bypass then return here.
At a glance
This skill is for Legal and helps you escalate privileges on windows systems, bypass windows security controls, and enumerate privilege escalation paths.
git clone --depth 1 https://github.com/pale-knight/redteam-skill
cp -r redteam-skill/skills/privesc-win ~/.claude/skills/privesc-win
windowsPrivilege EscalationSeimpersonatePotatoKernel ExploitUac Bypass
Also in pale-knight/redteam-skill
View the repoActive Directory exploitation after domain credentials exist: Kerberos (AS-REP/Kerberoast including cracking the ticket then using the accou...
Active Directory reconnaissance with or without credentials: user/group/computer enumeration, ACL/delegation, ADCS, modern Windows LAPS, Blo...
CI/CD pipeline and software-supply-chain exploitation: Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps, Gitea/Forgejo, self-hosted runne...
Cloud control-plane exploitation for AWS, Azure/Entra, GCP, and Alibaba Cloud: IAM/RAM privilege escalation, impersonation, cross-account tr...
Cloud control-plane reconnaissance for AWS, Azure/Entra, GCP, and Alibaba Cloud: identity, IAM/RAM, trust, resources, metadata, and managed-...
Credential operations: secret discovery, classification, extraction, conversion, offline cracking of hashes the operator already has as a cr...
Endpoint defense evasion after an operator-selected chain already has a valid execution path but AV/EDR/AMSI/WDAC/PPL/memory/kernel telemetr...
Kubernetes and container exploitation: identity/RBAC, secrets, kubelet/etcd, managed-cloud workload identities, container-to-node escape inc...
Client-side initial access and social-engineering attack module. Use when the operator selects a human/client/browser/identity-delivery atta...
OS post-exploitation after a stable host foothold: quiet host recon, host-native persistence (Windows Run/tasks/services/COM/WMI and Linux S...
Linux local privilege escalation from a low-privilege shell to root. Covers quiet vs loud enumeration, sudo/GTFOBins, CVE-2025-32463 chwoot...
通用网络与资产信息收集。面向 IP、CIDR、主机名、企业/域名等尚未明确攻击面的目标,完成资产扩展、主机发现、TCP/UDP端口发现、服务/版本/协议识别...
Other Legal skills
Applies Anthropic's official brand colors and typography to any sort of artifact that may benefit from having Anthropic's look-and-feel. Use...
Review the changes since a fixed point (commit, branch, tag, or merge-base) along two axes — Standards (does the code follow this repo's doc...
Meeting notes page — title bar with attendees, agenda checklist, decisions block, action items table with owners + dates, and a "next meetin...
An editorial-style poster — newsprint paper, dateline, oversized serif headline with a struck-through word and italic accent, a 2-column bod...
A standalone pricing page — header, plan tiers, feature comparison table, and an FAQ. Use when the brief asks for "pricing", "plans", "subsc...
Apple Human Interface Guidelines as 14 agent skills covering platforms, foundations, components, patterns, inputs, and technologies for iOS,...