All skills
hardw00t avatar

/network-pentest

@f9bb3b2

Internal network and Active Directory penetration testing skill for corporate environments. Use when performing authorized internal network assessments, AD attack path analysis, lateral movement, privilege escalation, and post-exploitation across Windows/Linux estates. Covers BloodHound, Impacket, NetExec/CrackMapExec, Responder, Rubeus, mimikatz, certipy. Triggers on requests to pentest internal networks, attack AD, perform lateral movement, Kerberoast, DCSync, or escalate privileges.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/network-pentest

This session only. Nothing lands on disk.

referencesnmap_cheatsheet.md

≈655 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Nmap Cheatsheet

Host discovery, port scanning, and service/script enumeration. For fast /16+ sweeps, pair with masscan then feed live hosts back to nmap for version detection.

Host discovery

# ARP/ICMP sweep on a local subnet (no port scan)
nmap -sn 192.168.1.0/24

# Ping-agnostic host discovery (use when ICMP is blocked)
nmap -Pn -sS -p 22,80,135,139,445,3389,5985 192.168.1.0/24

# Pull live hosts into a file for downstream tools
nmap -sn 10.0.0.0/16 -oG - | awk '/Up$/{print $2}' > live.txt

Port scanning

# Fast top-100 ports
nmap -F 192.168.1.0/24 -oA fast_scan

# Full TCP sweep, tuned for internal speed
nmap -p- -T4 --min-rate 5000 --max-retries 2 target -oA full_tcp

# UDP top-50 (slow, noisy)
nmap -sU --top-ports 50 -T4 target -oA udp_top50

# Stealth SYN scan (requires root/CAP_NET_RAW)
nmap -sS -Pn -p- target

Version + default scripts

# The standard "service enum" pass against common Windows/AD ports
nmap -sV -sC -p 21,22,23,25,53,80,88,110,135,139,143,389,443,445,464,\
593,636,1433,1521,2049,3268,3269,3306,3389,5432,5985,5986,8080,8443 \
  target -oA services

Script categories useful for internal/AD pentest

# SMB vuln & info
nmap --script "smb-vuln-*" -p445 target
nmap --script smb-os-discovery,smb-security-mode,smb2-security-mode,smb-enum-shares -p445 target

# LDAP
nmap --script "ldap-*" -p389,636,3268,3269 target

# Kerberos user enumeration (requires a userlist)
nmap -p88 --script krb5-enum-users --script-args krb5-enum-users.realm='CORP.LOCAL',userdb=users.txt target

# MSRPC
nmap --script msrpc-enum -p135 target

# HTTP discovery
nmap --script "http-title,http-enum,http-methods" -p80,443,8080,8443 target

Masscan handoff (for /16+ scopes)

# Masscan is orders of magnitude faster for discovery, but has no service detection
masscan -p1-65535 --rate 10000 10.0.0.0/16 -oL masscan.lst

# Pull unique host:port pairs, then nmap -sV only those
awk '/^open/{print $4":"$3}' masscan.lst | sort -u > targets.lst
nmap -sV -sC -Pn -iL <(cut -d: -f1 targets.lst | sort -u) -oA targeted

Output formats

nmap -oA run            # all three: .nmap .gnmap .xml
nmap -oX run.xml        # for XSLT/nessus-style parsing
nmap -oJ run.json       # (requires --append-output and recent nmap)

Timing & evasion (authorized engagements only)

# Slow / polite (avoid IDS thresholds)
nmap -T2 --max-rate 50 target

# Fragmented packets, source port spoof, decoy (detective controls testing)
nmap -f -g 53 -D RND:5 target

Tool versions validated

  • nmap >= 7.94
  • masscan >= 1.3.2

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The network-pentest skill is a highly structured, well-documented resource designed for authorized internal network and Active Directory penetration testing workflows. It provides clear playbooks, references, and configuration templates for using industry-standard security tools. No malicious behaviors, obfuscation techniques, or unauthorized data exfiltration paths were detected.

  • Socket16d

    13 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/network-pentest