Skip to content
Back to skills

Offensive Initial Access

ASecurity

Initial access techniques checklist: phishing (spear/smishing), credential stuffing, exposed service exploitation, supply chain attacks, watering hole, VPN/RDP brute force, public-facing application exploitation. Maps to MITRE ATT&CK TA0001. Use when planning initial access phases of red team engagements.

  • 76 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 21, 2026
ai-agentsgoshelltestinggitdatabasesecurity

Security analysis

A100/100

Pro scans all 6 files and shows the line behind each finding

Scanned September 21, 2026

npx -y skills add Miosa-osa/OSA --skill offensive-initial-access --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Offensive Initial Access?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Offensive Initial Access
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/miosa-osa-offensive-initial-access/badge)](https://www.skillsdirectory.com/skills/miosa-osa-offensive-initial-access)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: offensive-initial-access
description: "Initial access techniques checklist: phishing (spear/smishing), credential stuffing, exposed service exploitation, supply chain attacks, watering hole, VPN/RDP brute force, public-facing application exploitation. Maps to MITRE ATT&CK TA0001. Use when planning initial access phases of red team engagements."
category: security
triggers:
  - "initial access"
  - "offensive initial access"
  - "infrastructure"
  - "infrastructure attack"
  - "infrastructure exploitation"
  - "initial access methodology"
tools:
  - file_read
  - file_glob
  - file_grep
  - file_write
  - file_edit
  - dir_list
  - shell_execute
  - web_fetch
  - web_search
  - delegate
---

# SKILL: Modern Initial Access

## Metadata
- **Skill Name**: initial-access
- **Folder**: offensive-initial-access
- **Source**: https://github.com/SnailSploit/offensive-checklist/blob/main/initial-access.md

## Description
Initial access techniques checklist: phishing (spear/smishing), credential stuffing, exposed service exploitation, supply chain attacks, watering hole, VPN/RDP brute force, public-facing application exploitation. Maps to MITRE ATT&CK TA0001. Use when planning initial access phases of red team engagements.

## Trigger Phrases
Use this skill when the conversation involves any of:
`initial access, phishing, spear phishing, credential stuffing, exposed service, supply chain, watering hole, VPN brute force, RDP attack, MITRE TA0001, initial foothold`


<!-- progressive-disclosure -->
## Methodology references

Read the relevant sections below before following a technique. Read them in order
for the complete original methodology. Confirm the target and testing scope with
the user before performing any active checks.

- [Full Methodology](references/methodology-01.md) — part 1; consult for this stage and its examples.
- [Windows Script Host](references/methodology-02.md) — part 2; consult for this stage and its examples.
- [Installation](references/methodology-03.md) — part 3; consult for this stage and its examples.
- [RAG (Retrieval Augmented Generation) Database Poisoning](references/methodology-04.md) — part 4; consult for this stage and its examples.

Files in this skill

  • SKILL.md2.2 KB
  • references/detail.md20.9 KB
  • references/methodology-01.md14.2 KB
  • references/methodology-02.md14.2 KB
  • references/methodology-03.md13.6 KB
  • references/methodology-04.md1.2 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…