All skills
hardw00t avatar

/network-pentest

@f9bb3b2

Internal network and Active Directory penetration testing skill for corporate environments. Use when performing authorized internal network assessments, AD attack path analysis, lateral movement, privilege escalation, and post-exploitation across Windows/Linux estates. Covers BloodHound, Impacket, NetExec/CrackMapExec, Responder, Rubeus, mimikatz, certipy. Triggers on requests to pentest internal networks, attack AD, perform lateral movement, Kerberoast, DCSync, or escalate privileges.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/network-pentest

This session only. Nothing lands on disk.

payloadscme_modules.md

≈801 tokens on demand. Your agent reads this file only when SKILL.md points to it.

CrackMapExec / NetExec Module Recommendations

Curated module list for internal engagements. Invoke with nxc <proto> <target> ... -M <module>.

Information gathering (SMB)

Module Purpose
enum_av Identify AV/EDR product on target
enum_dns Pull DNS records from SMB share //dc/SYSVOL\policies
get_netconnections Discover outbound network connections from host
get_description AD computer description field harvesting
get_localgroups Local groups + membership via SAMR
get_loggedon_users Live logged-on users
get_sessions Active SMB sessions
spider_plus Share spidering with include/exclude filters, content search
veeam Look for Veeam creds on Veeam backup servers
met_inject Mssql linked-server enumeration

Credential access

Module Purpose
lsassy Remote LSASS dump + offline pypykatz parse
nanodump LSASS dump via NanoDump (stealthier)
handlekatz LSASS via process handle duplication
mimikatz Invoke in-memory mimikatz (loud; triggers EDR)
masky Abuse ADCS ESC1 via template from computer context
dpapi Decrypt DPAPI-protected secrets (requires master key)
rdcman Extract Remote Desktop Connection Manager stored creds
wifi Dump Wi-Fi profiles + cleartext passwords

AD / LDAP modules

Module Purpose
adcs Enumerate ADCS templates and mark ESC1/ESC4/ESC6/ESC8 candidates
laps Retrieve LAPS-managed local admin passwords
gmsa Dump gMSA NT hashes for readable accounts
maq Print ms-DS-MachineAccountQuota value
group-mem Recursively resolve a group's members
user-desc Pull description fields for all user objects (cleartext password hunt)
whoami Who am I in the domain (groups, SID)
subnets Get AD Sites subnet definitions

Coercion

Module Purpose
petitpotam MS-EFSR coercion
shadowcoerce MS-FSRVP coercion
dfscoerce MS-DFSNM coercion
printerbug MS-RPRN coercion (SpoolSample)
coerce_plus Auto-select coercion primitive and fire

Exploitation

Module Purpose
zerologon Test / exploit CVE-2020-1472 (destructive — resets DC$ password)
noPac CVE-2021-42278/42287 sAMAccountName spoofing
printnightmare PrintNightmare RCE test
ms17-010 EternalBlue detection
smbghost CVE-2020-0796 SMBv3 compression bug

Recommended default run (passive)

nxc smb targets.txt -u "$USER" -p "$PASS" \
  -M enum_av -M get_sessions -M get_loggedon_users -M spider_plus

nxc ldap dc.corp.local -u "$USER" -p "$PASS" \
  -M adcs -M laps -M gmsa -M maq -M user-desc

Safety

  • zerologon: the test will break DC netlogon until the DC$ password is reset — DO NOT RUN without authorization and customer rollback plan.
  • mimikatz module loads mimikatz in memory — EDR-visible. Prefer lsassy with obfuscation for routine LSASS dumps.
  • spider_plus with DOWNLOAD_FLAG=True can exfiltrate files — confirm this is in scope and configure --max-size.

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The network-pentest skill is a highly structured, well-documented resource designed for authorized internal network and Active Directory penetration testing workflows. It provides clear playbooks, references, and configuration templates for using industry-standard security tools. No malicious behaviors, obfuscation techniques, or unauthorized data exfiltration paths were detected.

  • Socket16d

    13 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/network-pentest