{"enrichment":{"faq":[{"a":"Network Attack provides layer-2 and layer-3 poisoning techniques (LLMNR, ARP, DHCPv6), NTLM relay with coercion-based exploitation, and traffic interception methods. It includes TUN-based pivoting tools like Ligolo-ng and Chisel for establishing pivots across network segments, plus wireless assessment capabilities for WPA2/WPA3 credential capture. For Active Directory\u2013specific relay work and Kerberos attacks, refer to the active-directory-attack skill.","q":"What network attack lateral movement tools does network-attack cover?"},{"a":"Network Attack executes NTLM relay and coercion-based exploitation on internal networks through responder-based LLMNR poisoning, ntlmrelayx relay chains, and coercion techniques like PetitPotam and PrinterBug. These methods capture credentials and relay them across SMB and other protocols to achieve lateral movement and remote code execution on target systems within the network segment.","q":"How does network-attack perform NTLM relay and SMB exploitation?"},{"a":"Network Attack establishes pivots and tunnels across network segments using tools like Ligolo-ng (TUN-based), Chisel (SSH reverse proxy), and DNS tunneling (iodine, dnscat2). These enable traffic forwarding through compromised hosts to reach isolated network zones and maintain persistent access across segmented infrastructure.","q":"What pivoting and tunneling capabilities are in network-attack?"},{"a":"Network Attack includes wireless assessment for WPA2/WPA3 credential capture and exploitation. It covers evil twin attacks, 802.1X attacks, and WPA-Enterprise assessment. For comprehensive wireless penetration testing, network-attack provides the tools and techniques to identify and exploit wireless network vulnerabilities.","q":"Can network-attack exploit wireless networks and capture WPA2/WPA3?"},{"a":"Network Attack identifies and exploits network service vulnerabilities for remote code execution through techniques targeting MSSQL (xp_cmdshell), WinRM abuse, RDP/SSH downgrade attacks, and known CVEs like EternalBlue (MS17-010). It enables reconnaissance of internal network services and systematic exploitation for lateral movement and privilege escalation.","q":"How does network-attack identify and exploit network service vulnerabilities?"},{"a":"Network Attack covers ARP spoofing, VLAN hopping (DTP, 802.1Q), and man-in-the-middle interception using tools like bettercap and sslstrip. These layer-2 techniques enable traffic capture, credential harvesting, and session hijacking across network segments for internal network penetration testing.","q":"What does network-attack cover for ARP spoofing and MitM attacks?"}],"shadow_tags":["layer-2-attacks","credential-interception","tunnel-pivoting","wireless-security","protocol-exploitation","traffic-manipulation","network-reconnaissance","lateral-escalation","service-abuse","coercion-techniques"],"summary_rewrite":"Network Attack covers layer-2 and layer-3 poisoning (LLMNR, ARP, DHCPv6), NTLM relay with coercion, traffic interception, and network-service exploitation for lateral movement. It includes TUN-based pivoting with tools like Ligolo-ng and Chisel, plus wireless assessment for WPA2/WPA3. Hand off AD-specific relay work and Kerberos attacks to the active-directory-attack skill."},"files":[{"bytes":10264,"path":"skills/network-attack/SKILL.md","sha256":"03c62565365cb446431d023e64204e10561aa8ca673a41cbf0cae007fdcb90e7","url":"https://skillfed.io/files/hypnguyen1209/offensive-claude/network-attack/2859e5f5/SKILL.md"}],"id":"hypnguyen1209/offensive-claude/network-attack","links":{"html":"https://skillfed.io/hypnguyen1209/offensive-claude/network-attack","md":"https://skillfed.io/hypnguyen1209/offensive-claude/network-attack.md","repo":"https://github.com/hypnguyen1209/offensive-claude"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":58,"language":"Python","last_updated":"2026-07-03","license":"MIT","name":"network-attack","publisher":"hypnguyen1209","stars":326},"relations":{"similar":[{"id":"yaklang/hack-skills/network-protocol-attacks"},{"id":"yaklang/hack-skills/ntlm-relay-coercion"},{"id":"blacklanternsecurity/red-run/auth-coercion-relay"},{"id":"hypnguyen1209/offensive-claude/active-directory-attack"},{"id":"blacklanternsecurity/red-run/ad-discovery"},{"id":"zebbern/claude-code-guide/active-directory-attacks"},{"id":"blacklanternsecurity/red-run/adcs-access-and-relay"},{"id":"hypnguyen1209/offensive-claude/initial-access"},{"id":"zebbern/claude-code-guide/privilege-escalation-methods"},{"id":"elementalsouls/Claude-BugHunter/hunt-ntlm-info"}]},"slug":{"owner":"hypnguyen1209","repo":"offensive-claude","skill":"network-attack"},"version":"2859e5f5"}
