Install
openclaw skills install pentest-workbenchComprehensive offensive security workflow for bug bounty, vulnerability assessment, penetration testing, and exploitation. Use when performing security testing, analyzing vulnerable targets, conducting privilege escalation, building exploits, or running reconnaissance. Covers: TCP buffer overflows (vulnserver), web application testing (VulnerableWordpress/WPScan), honeypot analysis (Cowrie), GTFOBins/LOLBAS privesc, pwn.college fundamentals, and offensive toolchain automation. Triggers on: run a pentest, exploit this, buffer overflow, privesc, OSCP, CTF, bug bounty, vulnerability assessment, rev shell, test this target.
openclaw skills install pentest-workbenchnmap, masscan, rustscan for port discoveryTools from linked repos:
netstalking-osint — automated OSINT recon workflowsPentest-Tools (40+ categories) — scanner/framework discovery, network_enumBuffer Overflow (vulnserver pattern):
Web:
Privesc (GTFOBins):
# Check sudo/suid binaries
sudo -l
find / -perm -4000 2>/dev/null
# Shell escape from restricted editor
:!/bin/bash
AD Attacks (Pentest-Tools):
references/buffer-overflow.md (vulnserver anatomy, exploit dev)references/privesc.md (GTFOBins/LOLBAS, Linux/Windows escalation)references/tools-inventory.md (all linked tools catalogued)Vulnserver runs on port 9999. Vulnerable commands:
| Command | Trigger Function | Buffer Size | Overflow Offset |
|---|---|---|---|
| TRUN | Function3 | 2000 | ~2003 (EIP at ~2007) |
| GMON | Function3 | 2000 | Similar to TRUN |
| KSTET | Function2 | 60 | ~64 |
| GTER | Function1 | 140 | ~144 |
| LTER | Function3 | 2000 | Via transformation |
| HTER | Function4 | 1000 | Hex-encoded |
Key insight: essfunc.dll EssentialFunc10-14 also use strcpy into small buffers (140, 60, 2000, 2000, 1000).
Exploit strategy:
| Tool | Purpose | Key Command |
|---|---|---|
| nmap | Port enum | nmap -sCV -p- -T4 target |
| Burp Suite | Web testing | Proxy, Repeater, Intruder |
| sqlmap | SQL injection | sqlmap -r req.txt --batch |
| msfvenom | Shellcode gen | msfvenom -p linux/x64/shell_tcp LHOST=x R |
| CrackMapExec | AD attacks | cme smb target -u user -p pass |
| Evil-WinRM | Remote shell | evil-winrm -i target -u user -p pass |