Skip to main content
ClaudeWave
Skill282 estrellas del repoactualizado yesterday

pentest-network-internal

This Claude Code skill simulates internal network attacks by mapping network topology, enumerating services and Active Directory structures, auditing credential weaknesses, and testing lateral movement paths. Use it during authorized security assessments to identify vulnerabilities from an internal attacker perspective, including weak passwords, misconfigured services, and Active Directory trust weaknesses that could enable privilege escalation or asset compromise.

Instalar en Claude Code
Copiar
git clone --depth 1 https://github.com/jd-opensource/JoySafeter /tmp/pentest-network-internal && cp -r /tmp/pentest-network-internal/skills/pentest-network-internal ~/.claude/skills/pentest-network-internal
Después abre una sesión nueva de Claude Code; el skill carga automáticamente.

SKILL.md

# Pentest Network Internal

## Purpose
Simulate an internal attacker to identify weak credentials, misconfigured services, and Active Directory paths to high-value assets.

## Core Workflow
1. **Network Discovery**: Map the internal network, live hosts, and open ports using `nmap` and `masscan`.
2. **Service Enumeration**: Identify running services, versions, and potential entry points (SMB, RDP, SSH, etc.).
3. **Vulnerability Scanning**: Check for known service vulnerabilities (e.g., EternalBlue, ZeroLogon) using `nuclei` and `nmap-scripts`.
4. **Credential Auditing**: Test weak passwords and default credentials using `hydra` and `netexec` (CrackMapExec).
5. **Active Directory Enum**: Map AD trust relationships, users, and groups using `bloodhound` and `ldapdomaindump`.
6. **Lateral Movement**: Simulate movement between hosts using valid credentials or exploits.

## References
- `references/tools.md`
- `references/workflows.md`