ZBS Index What actually exists in applied AI, with the source next to it

skill

privesc-windows

Use when escalating privileges on a Windows host — SeImpersonate Potato chains (GodPotato/PrintNotifyPotato), service & DLL hijacking, UAC bypass (fodhelper/ICMLuaUtil), kernel EoP + BYOVD (CVE-2025-29824), token-rights abuse, LSASS/SAM/DPAPI credential harvesting

Description as published by the maintainer. Source

  • active

active — Most recent push to the repository was 2026-07-03.

Signals

These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.

Signal Value What it measures Window Observed Source
GitHub stars 337 Stars on the repository that contains this skill, not on the skill itself. A collection of fifty skills shares one number, so it says nothing about this particular skill. cumulative, all time GitHub
Last commit 2026-07-03 Most recent push to the containing repository. It may reflect work on a different skill in the same collection. point in time GitHub
repository status active The repository holding this skill exists and is not archived. as of fetch GitHub

Will this work with your setup?

Install location suggests this is meant for claude-code. The author tagged this repository "claude-code-skills" on GitHub. That is their statement of intent, not a test result.

We have not run this skill against a task with and without it enabled, so we cannot tell you whether it improves anything, what it costs in tokens, or whether it duplicates behaviour your harness already has. When we have run that test, the result will appear on this page with the task, the versions and the budget it used.

The skill definition lives at skills/privesc-windows/SKILL.md in https://github.com/hypnguyen1209/offensive-claude.

Where to get it

Related, by what their authors tagged them

  • hypnguyen1209-offensive-claude-active-directory-attack — last commit 2026-07-03, shares exploit-development, offensive-security, redteam
    Use when attacking a Windows Active Directory domain — Kerberos roasting/delegation, coercion + NTLM/Kerberos relay (CV…
  • hypnguyen1209-offensive-claude-ai-agent-redteam — last commit 2026-07-03, shares exploit-development, offensive-security, redteam
    Use when red-teaming an agentic AI / LLM application — indirect & zero-click prompt injection, MCP tool poisoning, pers…
  • hypnguyen1209-offensive-claude-ai-security — last commit 2026-07-03, shares exploit-development, offensive-security, redteam
    Use when attacking an AI/ML system or model — prompt injection & jailbreaks (Crescendo, Skeleton Key, Best-of-N), RAG/v…
  • hypnguyen1209-offensive-claude-browser-exploitation — last commit 2026-07-03, shares exploit-development, offensive-security, redteam
    Use when building a client-side browser exploit — V8/JSC JIT type confusion to renderer R/W, V8 heap-sandbox escape, re…
  • hypnguyen1209-offensive-claude-cicd-supply-chain — last commit 2026-07-03, shares exploit-development, offensive-security, redteam
    Use when attacking or auditing a CI/CD pipeline or software supply chain — pwn requests, poisoned pipeline execution, c…
  • hypnguyen1209-offensive-claude-cloud-security — last commit 2026-07-03, shares exploit-development, offensive-security, redteam
    Use when attacking AWS/Azure/GCP cloud — IAM/identity privilege escalation, IMDS/metadata SSRF, Entra device-code & PRT…
  • hypnguyen1209-offensive-claude-coding-mastery — last commit 2026-07-03, shares exploit-development, offensive-security, redteam
    Use when writing security tooling, exploits, scanners, or C2 in Python/C/Go/Rust/ASM — systems & network programming, a…
  • hypnguyen1209-offensive-claude-container-k8s-escape — last commit 2026-07-03, shares exploit-development, offensive-security, redteam
    Use when breaking out of a container or escalating inside Kubernetes — runc/BuildKit CVEs, privileged/capability/cgroup…
  • hypnguyen1209-offensive-claude-crypto-analysis — last commit 2026-07-03, shares exploit-development, offensive-security, redteam
    Use when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD m…
  • hypnguyen1209-offensive-claude-edr-evasion — last commit 2026-07-03, shares exploit-development, offensive-security, redteam
    Use when bypassing EDR/AV to run a payload — hook unhooking, direct/indirect syscalls, PPID spoofing, process injection…

These share tags the maintainers applied themselves, such as exploit-development, offensive-security, redteam. Common tags like "mcp" or "ai" are ignored for this: agreeing with six hundred other projects is not a similarity.

This is not a recommendation and not a test result. It is a map of what the authors said their work is about.

Also from hypnguyen1209

How the author describes it

Topics the maintainer set on GitHub: claude-code, claude-code-skills, exploit-development, offensive-security, redteam.

Bring your own setup

We take apart real AI setups every week and show what broke, what cost too much, and what the trace actually said. If you run agents on real work, that is where the useful conversation is.

Join ZBS AI Practice Lab

Sources

  1. hypnguyen1209/offensive-claude on GitHub — GitHub, observed , trust tier 3.