offsec-campaign-orchestrator

Orchestrate multi-stage offensive security campaigns with target dossiers and request maps.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill offsec-campaign-orchestrator
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: offsec-campaign-orchestrator
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/meta/offsec-campaign-orchestrator
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill offsec-campaign-orchestrator

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill solves the fragmentation of offensive security testing by providing a unified, stateful framework to manage complex, multi-stage hunting campaigns from initial reconnaissance to final reporting.

Core Features & Use Cases

  • Campaign Orchestration: Coordinates crown-jewel identification, target dossier maintenance, and deep-hunt workflows.
  • Traffic Analysis: Integrates HAR and Burp request imports into a structured offensive request map.
  • Exploit Chaining: Facilitates the transition from isolated primitives to high-impact exploit chains.
  • Use Case: A security researcher can use this to map out a target's attack surface, import captured traffic, and systematically execute a deep-hunt on business logic while maintaining a persistent dossier of findings.

Quick Start

Invoke the offsec campaign orchestrator to initialize a new target dossier and begin the crown-jewel identification process for the specified domain.

Frequently Asked Questions about offsec-campaign-orchestrator

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I manage multi-stage pentesting workflows and track isolated exploit primitives?▼

Manage multi-stage pentesting workflows by orchestrating end-to-end offensive campaigns that maintain persistent target dossiers, track isolated exploit primitives, and synthesize them into high-impact exploit chains.

What is the best way to organize bug bounty hunting campaigns from reconnaissance to reporting?▼

Organize bug bounty hunting campaigns using a unified, stateful framework that coordinates crown-jewel identification, deep-hunt workflows, and evidence synthesis from initial reconnaissance through to final reporting.

Can I import HAR and Burp request files to map an attack surface during security assessments?▼

You can import HAR and Burp request files to map an attack surface. The framework integrates captured traffic into a structured offensive request map for systematic security assessments.

How do I maintain persistent state and evidence synthesis for manual security assessments?▼

Maintain persistent state for manual security assessments by initializing a target dossier that continuously tracks findings, manages request maps, and synthesizes evidence across multi-stage attack workflows.

Does this offensive security framework work for tracking business logic vulnerabilities during a deep-hunt?▼

This offensive security framework works for tracking business logic vulnerabilities by systematically executing deep-hunt workflows on target domains while maintaining a persistent dossier of findings and hypotheses.

What are the limitations of using a stateful framework for penetration testing campaign management?▼

A stateful framework for penetration testing requires structured hypothesis tracking and persistent state management, meaning unstructured or ad-hoc testing without clear campaign phases may not fit the orchestrated workflow.