Pivoting Tunneling
This skill guides you through pivoting and tunneling strategies to reach internal networks from a compromised host during authorized penetration tests. It covers SSH port forwarding, SOCKS proxies, and specialized tools like Chisel, Ligolo-ng, and sshuttle, with a decision tree to select the right approach based on available access and network constraints.
Pivoting Tunneling teaches network pivoting and tunneling techniques to route traffic through compromised hosts and reach internal networks during authorized penetration tests.
AI-generated summary based on this skill's SKILL.md
Decision gist · record as of 2026-04-01
Pivoting Tunneling teaches network pivoting and tunneling techniques to route traffic through compromised hosts and reach internal networks during authorized penetration tests. This skill guides you through pivoting and tunneling strategies to reach internal networks from a compromised host during authorized penetration tests. It covers SSH port forwarding, SOCKS proxies, and specialized tools like Chisel, Ligolo-ng, and sshuttle, with a decision tree to select the right approach based on available access and network constraints.
Use it when
- Pivoting Tunneling provides multiple methods: SSH port forwarding for direct tunnels, SOCKS proxies for flexible routing.
- Pivoting Tunneling covers SSH port forwarding (local and remote), SOCKS proxy setup.
Install
blacklanternsecurity/red-run/pivoting-tunneling · repository language: Python
generated, unverified - the skill's exact subdirectory could not be determined; check the repository on GitHub
Open directory. Skills are indexed for reading, not audited. Review a skill's body before installing it.
Frequently asked questions
AI-generated answers based on this skill's SKILL.md and metadata
What is network pivoting and how does Pivoting Tunneling help?
Pivoting Tunneling teaches you network pivoting—using a compromised host as a gateway to reach internal networks during authorized penetration tests. The skill covers SSH port forwarding, SOCKS proxies, and tools like Chisel, Ligolo-ng, and sshuttle, with a decision tree to select the right approach based on available access and network constraints.
How to pivot through networks using Pivoting Tunneling techniques?
Pivoting Tunneling provides multiple methods: SSH port forwarding for direct tunnels, SOCKS proxies for flexible routing, and specialized tools like Chisel for encrypted tunnels and Ligolo-ng for advanced pivoting. The skill includes a decision framework to match your technique to available access levels and network topology.
What tunneling pivot techniques does this skill cover?
Pivoting Tunneling covers SSH port forwarding (local and remote), SOCKS proxy setup, and dedicated tools including Chisel for encrypted tunneling, Ligolo-ng for complex pivots, and sshuttle for transparent tunneling. Each technique is matched to specific scenarios and network constraints you'll encounter.
How does Pivoting Tunneling enable lateral movement?
Pivoting Tunneling teaches lateral movement by establishing secure tunnels from a compromised host into restricted network segments. You learn to chain connections, bypass segmentation, and navigate firewall restrictions using appropriate forwarding and proxy techniques suited to your access level and target environment.
Can Pivoting Tunneling help bypass network segmentation?
Yes. Pivoting Tunneling covers techniques to bypass network segmentation and firewall restrictions during authorized testing. It teaches you to select tunneling methods—SSH forwarding, SOCKS proxies, or specialized tools—based on available access, helping you reach internal networks from a compromised external host.
What tools and configuration methods are included?
Pivoting Tunneling covers configuration and execution of tools like Chisel, Ligolo-ng, and sshuttle alongside native SSH port forwarding and SOCKS proxy setup. The skill provides a decision tree to help you choose the right tool and configuration for your specific network constraints and penetration testing scenario.
Let your AI agent find skills like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 56,283 agent skills by what they can do, searchable in plain language.
wish › “Learn network pivoting and tunneling techniques for penetration testing”
Give your agent the search over MCP, or paste the wish link into any chat. No install? Search from any chat →
Related skills
Pinggy Tunnel creates instant public URLs for local services using SSH reverse tunnels, with no daemon installation needed. Free tier offers 60-minute tunnels with random subdomains; Pro tier ($3/mo) adds persistent URLs and longer session times. Supports HTTP, HTTPS, TCP, and TLS tunneling with optional access controls like basic auth, bearer tokens, IP whitelisting, and CORS.
Rustunnel lets you create public tunnels for local services across HTTP, TCP, UDP, and peer-to-peer protocols. Use it to test webhooks, share development environments, access databases remotely, or run load-balanced pools—all controlled through MCP tools that integrate with Claude Code and other AI agents.
Master network tunneling and pivoting techniques to access internal systems from compromised hosts. This skill covers SSH port forwarding, reverse SOCKS proxies via Chisel, transparent TUN-based pivoting with Ligolo-ng, socat relays, DNS/ICMP/HTTP tunneling, ProxyChains configuration, Windows pivoting methods, and multi-layer chaining strategies.
This skill applies falsification-first methodology to network and streaming incidents where the obvious cause is likely a red herring. Rather than stacking assumptions, it guides you through layered isolation—testing the same request across different paths to pinpoint exactly which hop (client, CDN, proxy, or backend) is responsible. Use it for connection resets, SSE stalls, fixed-time drops, certificate errors, or LAN mysteries where symptoms like "works sometimes" or "fails after N seconds" point to multiple possible layers.
This skill helps you troubleshoot connection problems with Windows App, Azure Virtual Desktop, and direct PC connections on macOS. It guides you through identifying whether your connection is using optimal UDP Shortpath or falling back to slower WebSocket transport, checks for VPN or proxy interference, and parses Windows App logs to uncover auth failures or protocol negotiation issues.
Tunnel Doctor isolates and resolves conflicts when Tailscale coexists with proxy/VPN tools like Shadowrocket, Clash, or Surge on macOS. It addresses route table corruption, environment variable misconfigurations, system proxy bypass issues, SSH double-tunneling, and VM/container proxy propagation problems—covering scenarios from browser 503 errors to Docker timeouts and WSL SSH access.
More skills optimize-network (MIT) · linux-lateral-movement (MIT) · network-attack (MIT) · Edgesecurityaccess Wireguard Vpn (NOASSERTION) · Network Netcat (NOASSERTION) · recon-port-scan (Apache-2.0) · Auth Coercion Relay (GPL-3.0) · homelab-wireguard-vpn (MIT)