All skills
hardw00t avatar

/network-pentest

@f9bb3b2

Internal network and Active Directory penetration testing skill for corporate environments. Use when performing authorized internal network assessments, AD attack path analysis, lateral movement, privilege escalation, and post-exploitation across Windows/Linux estates. Covers BloodHound, Impacket, NetExec/CrackMapExec, Responder, Rubeus, mimikatz, certipy. Triggers on requests to pentest internal networks, attack AD, perform lateral movement, Kerberoast, DCSync, or escalate privileges.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/network-pentest

This session only. Nothing lands on disk.

referencesad_attack_matrix.md

≈1.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Active Directory Attack Matrix

Concise mapping of the most common AD abuse primitives, preconditions, execution, detection surface, and MITRE ATT&CK IDs.

Technique Precondition Primitive Result MITRE
Kerberoasting Any domain user, SPN set on target Request TGS, crack RC4/AES offline Service account password T1558.003
AS-REP Roasting DONT_REQ_PREAUTH on user AS-REQ without pre-auth, crack AS-REP User password T1558.004
DCSync GetChanges + GetChangesAll on domain MS-DRSR replication Any/All NT hashes incl. krbtgt T1003.006
Unconstrained delegation Host flagged TRUSTED_FOR_DELEGATION Coerce DC auth -> TGT stored in LSASS Domain TGT T1558
Constrained delegation msDS-AllowedToDelegateTo on principal S4U2self + S4U2proxy TGS as any user to listed SPN T1558.003
RBCD Write msDS-AllowedToActOnBehalfOfOtherIdentity on target Create computer (MAQ>0), S4U chain SYSTEM on target T1134.003
ACL: GenericAll on user GenericAll over target user Reset password / set SPN Account takeover T1098
ACL: GenericAll on group GenericAll over privileged group AddMember self -> group Group membership T1098
ACL: WriteDACL WriteDACL on object Add GenericAll ACE to self Full control T1222.001
ACL: WriteOwner WriteOwner on object Take ownership -> grant rights Full control T1222.001
GPO abuse GenericWrite/WriteDACL on GPO linked to target Add immediate scheduled task to GPO SYSTEM on all linked hosts T1484.001
ADCS ESC1 Enrollable template w/ ENROLLEE_SUPPLIES_SUBJECT + client-auth EKU Certipy req with altName Auth as arbitrary user T1649
ADCS ESC4 Write on a cert template Make template ESC1-like, then exploit Same as ESC1 T1649
ADCS ESC8 HTTP/HTTPS enrollment + NTLM accepted NTLM relay to /certsrv Cert as coerced principal (often DC$) T1649
Golden Ticket krbtgt NT hash + domain SID Forge arbitrary TGT Any identity, offline T1558.001
Silver Ticket Service account NT hash + domain SID Forge TGS for one SPN Service-scoped access, no DC traffic T1558.002
Skeleton Key Admin on DC misc::skeleton in mimikatz Master password on LSASS T1556.001
DPAPI master key theft LSA secrets or Administrator creds mimikatz dpapi::*, lsadump::backupkeys Decrypt user secrets domain-wide T1555.004
Shadow Credentials Write msDS-KeyCredentialLink on user Whisker / pyWhisker add key PKINIT auth as target T1556
Kerberos pre-auth downgrade User must allow RC4 Force RC4 TGS -> easier to crack Offline crack T1558.003

Preferred execution tooling

Attack Primary tool Alternate
Kerberoasting GetUserSPNs.py -request Rubeus kerberoast
AS-REP roast GetNPUsers.py Rubeus asreproast
DCSync secretsdump.py -just-dc-user <one> mimikatz lsadump::dcsync
S4U (constrained) getST.py -impersonate Rubeus s4u
RBCD addcomputer.py + rbcd.py + getST.py PowerMad + Rubeus
ACL edits dacledit.py, owneredit.py PowerView
GPO abuse pyGPOAbuse.py, SharpGPOAbuse PowerView/GPOABuse
ADCS certipy Certify / PSPKIAudit
Golden / Silver ticketer.py mimikatz kerberos::golden
Shadow Creds certipy shadow auto Whisker / pyWhisker

Decision flow from a low-priv domain user

[Any domain user creds]
  |
  +-- List Kerberoastable / AS-REP users ---> crack offline
  |
  +-- Enumerate ACLs (BloodHound ACL pass) ---> find write primitives
  |
  +-- Enumerate ADCS templates (certipy find --vulnerable) ---> ESC1/4/8
  |
  +-- MachineAccountQuota > 0 ? ---> RBCD against writable computer
  |
  +-- Readable LAPS / gMSA ?  ---> escalate to local admin
  |
  +-- Shadow Credentials writable target? ---> PKINIT as target

Blast-radius guidance (run before executing)

Action Recommended authorization level
Read-only enum (LDAP, SharpHound default) Standard ROE
Kerberoast / AS-REP (offline crack only) Standard ROE
Coercion (PetitPotam, PrinterBug) Explicit — affects DC/target responsiveness
DCSync (krbtgt or full NTDS) Explicit, documented, scheduled
Golden/Silver ticket forgery Explicit; time-box and log
Skeleton Key Avoid unless lab — persistence primitive
Persistence (AdminSDHolder, DSRM) Engagement-specific written approval

Tool versions validated

  • impacket >= 0.12
  • certipy-ad >= 4.8
  • Rubeus >= 2.3
  • bloodhound-python >= 1.7.2

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The network-pentest skill is a highly structured, well-documented resource designed for authorized internal network and Active Directory penetration testing workflows. It provides clear playbooks, references, and configuration templates for using industry-standard security tools. No malicious behaviors, obfuscation techniques, or unauthorized data exfiltration paths were detected.

  • Socket16d

    13 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/network-pentest