Authorized internal security reference for selecting techniques, workflow summaries, OPSEC notes, prerequisites, and mitigations across internal recon, credential access, privilege escalation, lateral movement, persistence, tunneling, AD, ADCS, Exchange, SharePoint, and evasion scenarios. Use for pentest planning, report drafting, or converting the extracted intranet wiki into narrower skills.
Scanned 9/5/2026
Install to Claude Code
npx -y skills add antigalautgr-ops/VulnClaw --skill references --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of References?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/antigalautgr-ops-references)More formats (shields.io, HTML) on the badges page.
---
name: intranet-pentest-playbook
description: Authorized internal security reference for selecting techniques, workflow summaries, OPSEC notes, prerequisites, and mitigations across internal recon, credential access, privilege escalation, lateral movement, persistence, tunneling, AD, ADCS, Exchange, SharePoint, and evasion scenarios. Use for pentest planning, report drafting, or converting the extracted intranet wiki into narrower skills.
---
# Intranet Pentest Playbook
Use this skill only for authorized internal security work.
## When To Use
- The task involves internal network, Windows, AD, ADCS, Exchange, or SharePoint assessment work.
- The user needs to choose among multiple post-compromise or internal attack paths.
- The user wants to condense the extracted intranet wiki into formal operator workflows, reports, or narrower skills.
## When Not To Use
- The task is mainly web application testing rather than internal security work.
- The user only needs tool syntax instead of technique guidance.
- A narrower existing skill already covers the requested workflow.
## Workflow
1. Start with `references/intranet-playbook-index.md`, then narrow the request to the smallest matching category set.
2. Read only the matching files in `references/`.
3. If a specific technique is needed, open the linked source markdown under `original extracted intranet-security-wiki source`.
4. Preserve OPSEC context: note noisy actions, likely alerts, prerequisites, and access assumptions when the source entry provides them.
5. For report or skill authoring tasks, condense selected techniques into repeatable operator workflows instead of mirroring the raw wiki layout.
## Category Map
- 横向移动: `references/intranet-playbook-01-lateral-movement.md`
- 免杀与规避: `references/intranet-playbook-02-evasion-and-anti-detection.md`
- 凭证窃取: `references/intranet-playbook-03-credential-theft.md`
- 权限提升: `references/intranet-playbook-04-privilege-escalation.md`
- 权限维持: `references/intranet-playbook-05-persistence.md`
- 隧道代理: `references/intranet-playbook-06-tunneling-and-proxy.md`
- 信息收集: `references/intranet-playbook-07-information-gathering.md`
- 域渗透攻击: `references/intranet-playbook-08-active-directory-attacks.md`
- ADCS攻击: `references/intranet-playbook-09-adcs-attacks.md`
- Exchange攻击: `references/intranet-playbook-10-exchange-attacks.md`
- SharePoint攻击: `references/intranet-playbook-11-sharepoint-attacks.md`
## Notes
- Start with the narrowest category that fits the request.
- Use `references/intranet-playbook-index.md` as the first stop for category selection.
- Surface prerequisites before suggesting commands.
- Reuse only the minimum number of techniques needed for the user's scenario.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!