network-pentest
Network Penetration Testing
STOP — Authorization check (read before any execution)
This skill executes offensive techniques against live infrastructure. Before any action:
- Confirm a written engagement letter / SOW is in scope and in-date.
- Confirm Rules of Engagement (ROE) covering: target CIDRs, excluded hosts, allowed techniques (coercion? DCSync? password spray?), permitted hours, source-IP allowlist, and customer emergency contact.
- Confirm the authorization explicitly names the domain(s) and tenant(s) you are about to test.
- If ANY of the above is unclear, ambiguous, or missing — STOP and request clarification. Do not proceed on the basis of verbal approval, chat-channel approval, or inferred scope.
Destructive/high-blast-radius actions (DCSync against production DCs, Zerologon, Skeleton Key, GPO edits, krbtgt reset, cert forgery) require a second, specific written approval in addition to the base engagement letter. Every such action must be logged with timestamp, operator, and justification for the customer's IR reconciliation.
Prefer read-only enumeration and dry-run modes first. Escalate only when the previous step establishes the precondition. Never chain offensive actions speculatively.
This skill enables comprehensive internal network and Active Directory penetration testing: reconnaissance, credential attacks, lateral movement, privilege escalation, and domain dominance. It is a thin router — heavy content lives in workflows/, references/, and payloads/. Load only the file you need.