Pentest Commands

Catalog penetration testing commands for Nmap, Metasploit, and related tools.

Updated Mar 20, 2026
One-click install
npx skills add https://github.com/sixscripts-ai/ghostssh --skill pentest-commands-sixscripts-ai
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Pentest Commands
Source: https://github.com/sixscripts-ai/ghostssh/tree/main/skills/pentest-commands
Command: npx skills add https://github.com/sixscripts-ai/ghostssh --skill pentest-commands-sixscripts-ai

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Provide a comprehensive reference of penetration testing commands, enabling security professionals to quickly locate and apply the right tool options.

Core Features & Use Cases

  • Comprehensive command references for common pentest tools (Nmap, Metasploit, Nikto, SQLMap, Hydra, John the Ripper, Aircrack-ng, Tshark/Wireshark) across network discovery, vulnerability assessment, exploitation, credential cracking, and traffic analysis.
  • Example-driven usage with practical flags and workflows to speed up authorized security engagements.
  • Use Case Scenarios: quickly prepare for a LAN audit, web app assessment, or wireless security test by selecting a tool and retrieving relevant commands and recommended options.

Quick Start

Ask for the most relevant pentest commands for a given tool or target to get started.

Frequently Asked Questions about Pentest Commands

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are the best Nmap commands for network discovery during a pentest?

Nmap commands for network discovery provide a structured catalog of flags and practical examples to speed up authorized LAN audits and vulnerability assessments. You retrieve relevant commands by querying the reference with a target or tool to get recommended workflows.

How do I use SQLMap and Nikto for web app vulnerability assessments?

SQLMap and Nikto commands for web app vulnerability assessments are provided as example-driven usage with practical flags. You apply these structured command references to execute authorized security tests on web applications efficiently.

Can I find Metasploit and Hydra commands for credential cracking and exploitation?

Metasploit and Hydra commands for credential cracking and exploitation are included in the reference catalog. You access example-driven workflows with specific flags to carry out authorized red-team engagements and vulnerability assessments.

Does this reference include Aircrack-ng and Wireshark commands for wireless security testing?

Aircrack-ng and Tshark/Wireshark commands for wireless security testing are included in the command catalog. You get structured examples and recommended options to conduct authorized wireless network assessments and traffic analysis.

When should I use John the Ripper over Hydra for password cracking?

John the Ripper and Hydra commands are both cataloged for credential cracking. You compare their specific flags and recommended workflows to select the appropriate tool for your authorized security engagement.

Are there safety notes and prerequisites for running penetration testing commands?

Safety notes and prerequisites are enforced within the penetration testing command reference to ensure responsible use. You must apply these structured workflows exclusively to authorized red-team and vulnerability assessments across networks and web apps.