All skills
hardw00t avatar

/network-pentest

@f9bb3b2

Internal network and Active Directory penetration testing skill for corporate environments. Use when performing authorized internal network assessments, AD attack path analysis, lateral movement, privilege escalation, and post-exploitation across Windows/Linux estates. Covers BloodHound, Impacket, NetExec/CrackMapExec, Responder, Rubeus, mimikatz, certipy. Triggers on requests to pentest internal networks, attack AD, perform lateral movement, Kerberoast, DCSync, or escalate privileges.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/network-pentest

This session only. Nothing lands on disk.

referencesbounty_patterns_2024_2026.md

≈1.5k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Bug Bounty Patterns 2024-2026 — network-pentest

Overview

Network-layer implications of post-2023 bug-bounty discoveries: HTTP/2 CONNECT tunneling used for internal port-scanning, TE.0 request-smuggling as a recon primitive, and Kubernetes SA token theft feeding classic lateral movement. Sources: PortSwigger Top 10 2024/2025, cloud-security threat data 2025. Last validated: 2026-04. Emit findings via ../schemas/finding.json.

Pattern Index

# Pattern Severity Primary Source
P22 HTTP/2 CONNECT-method internal port scanning High PortSwigger Top 10 2025
P21 TE.0 / 0.CL request smuggling as network recon primitive Critical PortSwigger Top 10 2024
P19 Service-Account token theft feeding lateral movement / pivoting High Cloud Security Threat Data 2025

Patterns

P22. HTTP/2 CONNECT Internal Port Scanning (Network Perspective)

  • CVE / Source: PortSwigger "Top 10 2025" — "Playing with HTTP/2 CONNECT".
  • Summary: HTTP/2 CONNECT requests against public LBs/gateways create raw tunnels to authority:port, enabling internal port scanning and service discovery from outside the perimeter. Where DAST sees a single endpoint, a network-pentest lens sees an on-net pivot.
  • Affected surface: Perimeter load balancers (HAProxy, nginx w/ experimental H2, Envoy) with CONNECT enabled; reverse proxies exposing WebSocket-over-H2 endpoints; AWS ALB with HTTP/2 client.
  • Detection (automated):
    # Probe each unique public endpoint with nghttp2:
    nghttp -v -m 1 --header=':method: CONNECT' --header=':authority: 127.0.0.1:22' "https://$T"
    # Script a sweep of private ranges + common service ports:
    for ip in 10.0.0.{1..254}; do
      for port in 22 80 443 2375 5984 6379 8500 9200 11211; do
        nghttp -qv --header=':method: CONNECT' --header=":authority: ${ip}:${port}" "https://$T"
      done
    done
  • Exploitation / PoC: Successful 200 + DATA frames = tunnel open; pivot with chisel-style forwarders or raw TCP through the H2 tunnel.
  • Indicators: Edge logs with CONNECT method against :authority: in RFC1918 / loopback / metadata ranges.
  • Mitigation: Disable CONNECT at edge unless explicitly required; explicitly deny :authority to private ranges; egress filtering on LB nodes.
  • Cross-refs: DAST P22; cloud-security P15; CWE-441.

P21. TE.0 / 0.CL Smuggling as Network Recon Primitive

  • CVE / Source: PortSwigger "Top 10 2024" — TE.0 smuggling family.
  • Summary: Beyond credential theft, smuggling a request into a shared backend connection reveals internal routing behaviour (hostname-stripping proxies, internal-only routes, staging hosts). For network-pentest scope, this functions as a blackbox route enumerator.
  • Affected surface: Shared front-end/back-end pairs; perimeter Cloud LBs; multi-tenant reverse proxies; internal-only hosts reachable via X-Forwarded-Host manipulation.
  • Detection (automated):
    • Run Burp's HTTP Request Smuggler against each (front-end, back-end) pair reached from your external vantage.
    • Interpret findings as network-topology disclosure: smuggled GET / with an internal Host: reveals vhost existence.
  • Exploitation / PoC: See DAST P21; network recon use-case = enumerating Host: internal-admin.corp that front-end would not expose via its public vhost table.
  • Indicators: Smuggled responses carrying internal Server: banners, error pages from services not publicly routed.
  • Mitigation: As DAST P21.
  • Cross-refs: DAST P21; CWE-444.

P19. Service-Account Token Theft Fuelling Lateral Movement

  • CVE / Source: Cloud Security Threat Data 2025 — 22% of observed cloud environments showed SA-token theft pivoting prod → financial systems.
  • Summary: Once a foothold pod is achieved (via exposed service / known CVE / CI compromise), the pod's mounted SA token is stolen and reused against the K8s API from an external host — effectively turning the token into an on-net credential for the post-exploitation phase. Network pentest must include API-server reachability + TLS-SNI / IP allow-list checks.
  • Affected surface: Self-hosted K8s with public API server; managed K8s with broad master-authorized-networks / control plane CIDR allow-list; bastion hosts with static egress IPs present in allow-list.
  • Detection (automated):
    # Network reachability of kube-apiserver from attacker vantage
    curl -sk "https://${APISERVER}:6443/version"
    # If reachable, attempt token-based read:
    curl -sk -H "Authorization: Bearer ${STOLEN_TOKEN}" "https://${APISERVER}:6443/api/v1/namespaces"
  • Exploitation / PoC: Use stolen token from compromised CI runner to drive cluster actions from attacker laptop; lateral movement from that external vantage.
  • Indicators: API-server access logs with unusual source IP using existing SA token; DNS lookup of kubernetes.default.svc from outside pod network.
  • Mitigation: Private API-server endpoint; authorized-network allow-list limited to bastion /32s; short-lived projected tokens (bound audience + exp); egress filtering on pods to block kubernetes.default.svc calls not needed by workload.
  • Cross-refs: Container P19; Cloud P13; CWE-522, CWE-200.

Cross-skill links

  • DAST: primary treatments of P21 and P22 — ../../dast-automation/references/bounty_patterns_2024_2026.md.
  • Container / Cloud: P19 originating surface — ../../container-security/references/bounty_patterns_2024_2026.md, ../../cloud-security/references/bounty_patterns_2024_2026.md.

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The network-pentest skill is a highly structured, well-documented resource designed for authorized internal network and Active Directory penetration testing workflows. It provides clear playbooks, references, and configuration templates for using industry-standard security tools. No malicious behaviors, obfuscation techniques, or unauthorized data exfiltration paths were detected.

  • Socket16d

    13 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/network-pentest