# Offensive Data Exfiltration (agent skill)

> Offensive Data Exfiltration is an agent skill (a SKILL.md file) from SnailSploit/Claude-Red. Dense methodology covering DNS exfiltration (dnscat2, iodine, dns2tcp), HTTPS tunneling (domain fronting, CDN abuse, legitimate service channels), ICMP tunneling (icmpsh, ptunnel-ng), cloud storage. It works with Claude Code and has 7,321 GitHub stars across a repository of 4 listed skills.

Dense methodology covering DNS exfiltration (dnscat2, iodine, dns2tcp), HTTPS tunneling (domain fronting, CDN abuse, legitimate service channels), ICMP tunneling (icmpsh, ptunnel-ng), cloud storage dead drops (S3 presigned URLs, Azure Blob SAS tokens, GCS signed URLs), email-based exfil (SMTP, EWS, draft method), steganography (image, audio, document metadata), encoding/encryption (base64 chunking, XOR, AES), covert channels (custom protocol tunneling, HTTP header encoding, timing channels),…

## Key facts

| Fact | Value |
|---|---|
| Repository | https://github.com/SnailSploit/Claude-Red |
| Skill path | Skills/post-exploitation/offensive-data-exfiltration/SKILL.md |
| Skill name | offensive-data-exfiltration |
| GitHub stars | 7,321 |
| Installs on skills.sh | not listed |
| License | MIT |
| Skills in repo | 4 |
| Plugin marketplace | no |
| Official | no |
| Works with | Claude Code |
| Category | Data & analysis |
| Last commit | Sep 19, 2026 |

## Add this skill

### Claude Code

```sh
git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git
cp -r Claude-Red/Skills/post-exploitation/offensive-data-exfiltration ~/.claude/skills/offensive-data-exfiltration   # personal, or .claude/skills in a project
```

In the Claude apps, zip the skill folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).

### ChatGPT / Codex

```sh
git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git
cp -r Claude-Red/Skills/post-exploitation/offensive-data-exfiltration .agents/skills/offensive-data-exfiltration   # repo; ~/.agents/skills for all projects
```

### Cursor

```sh
git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git
cp -r Claude-Red/Skills/post-exploitation/offensive-data-exfiltration .cursor/skills/offensive-data-exfiltration   # project; ~/.cursor/skills for all projects
```

Sources (checked 2026-10-07): https://code.claude.com/docs/en/skills, https://support.claude.com/en/articles/12512180-using-skills-in-claude, https://learn.chatgpt.com/docs/build-skills, https://cursor.com/docs/context/skills

---

Canonical page: https://appsgit.com/skills/snailsploit-offensive-data-exfiltration
Source: appsgit (https://appsgit.com), the app store for github. Data from the GitHub API, refreshed nightly.
Machine access: JSON API https://appsgit.com/api/v1/apps (OpenAPI: https://appsgit.com/openapi.json), MCP server https://mcp.appsgit.com/mcp, full index https://appsgit.com/llms-full.txt.
