network-pentest

Installation
SKILL.md

Network Penetration Testing

STOP — Authorization check (read before any execution)

This skill executes offensive techniques against live infrastructure. Before any action:

  1. Confirm a written engagement letter / SOW is in scope and in-date.
  2. Confirm Rules of Engagement (ROE) covering: target CIDRs, excluded hosts, allowed techniques (coercion? DCSync? password spray?), permitted hours, source-IP allowlist, and customer emergency contact.
  3. Confirm the authorization explicitly names the domain(s) and tenant(s) you are about to test.
  4. If ANY of the above is unclear, ambiguous, or missing — STOP and request clarification. Do not proceed on the basis of verbal approval, chat-channel approval, or inferred scope.

Destructive/high-blast-radius actions (DCSync against production DCs, Zerologon, Skeleton Key, GPO edits, krbtgt reset, cert forgery) require a second, specific written approval in addition to the base engagement letter. Every such action must be logged with timestamp, operator, and justification for the customer's IR reconciliation.

Prefer read-only enumeration and dry-run modes first. Escalate only when the previous step establishes the precondition. Never chain offensive actions speculatively.


This skill enables comprehensive internal network and Active Directory penetration testing: reconnaissance, credential attacks, lateral movement, privilege escalation, and domain dominance. It is a thin router — heavy content lives in workflows/, references/, and payloads/. Load only the file you need.

Installs
20
GitHub Stars
95
First Seen
Feb 2, 2026
network-pentest — hardw00t/ai-security-arsenal