network-pentest

Simulate attacker techniques across internal networks and Active Directory environments.

90|14|Updated Jan 12, 2026
One-click install
npx skills add https://github.com/hardw00t/ai-security-arsenal --skill network-pentest
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: network-pentest
Source: https://github.com/hardw00t/ai-security-arsenal/tree/main/skills/network-pentest
Command: npx skills add https://github.com/hardw00t/ai-security-arsenal --skill network-pentest

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill enables security teams to assess internal network resilience and Active Directory defenses by simulating attacker techniques across corporate environments, from discovery to post-exploitation.

Core Features & Use Cases

  • Reconnaissance and mapping of AD environment using BloodHound, Impacket, and Responder to reveal attack paths.
  • Credential access and lateral movement testing with CrackMapExec, Mimikatz, and related tooling.
  • Post-exploitation workflows and domain data collection to assess persistence and domain dominance.

Quick Start

Run an initial internal network assessment against the target domain using BloodHound, Impacket, and Responder to map AD relationships.

Frequently Asked Questions about network-pentest

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map Active Directory attack paths during an internal network assessment?

Active Directory attack paths are mapped during an internal network assessment by using BloodHound and Impacket to collect domain data and reveal lateral movement opportunities. This allows security teams to simulate attacker techniques and evaluate AD security relationships.

What is the best way to test lateral movement and credential access in a corporate environment?

Testing lateral movement and credential access in a corporate environment involves using CrackMapExec and Mimikatz to simulate post-exploitation attacker techniques. This evaluates domain resilience by identifying credential access opportunities and lateral movement pathways across the network.

Can I use Impacket and Responder for internal network reconnaissance?

Yes, Impacket and Responder are used for internal network reconnaissance to map AD environments and reveal attack paths. They support discovery workflows that evaluate internal network resilience by simulating attacker techniques across corporate networks.

Do I need BloodHound and CrackMapExec to perform post-exploitation workflows?

BloodHound and CrackMapExec are required to perform post-exploitation workflows and domain data collection. These tools support reconnaissance, privilege escalation, lateral movement, and credential access testing to assess persistence and domain dominance.

Does internal network penetration testing support privilege escalation and domain dominance evaluation?

Internal network penetration testing supports privilege escalation and domain dominance evaluation by simulating attacker techniques from discovery to post-exploitation. This assesses internal network resilience and Active Directory defenses across corporate environments.