offensive-network-attacks

Featured

Dense description covering ARP spoofing, LLMNR/NBT-NS/mDNS poisoning, DNS poisoning, MITM attacks, VLAN hopping, DHCP attacks, 802.1X/NAC bypass, IPv6 attacks. Tools: Bettercap, Responder, mitm6, Ettercap, Wireshark. MITRE T1557, T1040. Use when conducting internal network assessments or testing Layer 2/3 attack surface.

AI & Automation 3,234 stars 523 forks Updated 1 weeks ago MIT

Install

View on GitHub

Quality Score: 91/100

Stars 20%
100
Recency 20%
90
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Network Attacks (Layer 2/3) -- Offensive Methodology You are attacking Layer 2/3 infrastructure during an authorized internal engagement. ARP, DHCP, broadcast name resolution, VLAN trunking, and IPv6 autoconfiguration are all unauthenticated -- you exploit that trust to intercept credentials, redirect traffic, and cross network boundaries. ## Quick Workflow 1. Map your position -- VLAN, subnet, gateway, DNS, DHCP lease, IPv6 status. 2. Passively sniff with tcpdump/Wireshark to discover hosts and cleartext credentials. 3. Run Responder in analyze mode to observe LLMNR/NBT-NS/mDNS queries. 4. Enable Responder poisoning to capture NTLMv2 hashes. 5. Relay captured hashes with ntlmrelayx against hosts without SMB signing. 6. ARP spoof the gateway for targeted MITM and credential interception. 7. Probe VLAN boundaries via DTP negotiation and 802.1Q double tagging. 8. Exploit IPv6 autoconfiguration with mitm6 for DNS takeover and NTLM relay. --- ## ARP Spoofing ARP has no authentication. You send gratuitous ARP replies to associate your MAC with the gateway IP in the victim's cache, routing their traffic through you. ### Bettercap ARP Module ```bash sudo bettercap -iface eth0 net.probe on # discover live hosts net.show set arp.spoof.targets 10.0.0.50 # single target set arp.spoof.fullduplex true # poison both victim and gateway arp.spoof on ``` ### arpspoof and Ettercap ```bash echo 1 > /proc/sys/net/ipv4/ip_forward arpspo...

Details

Author
SnailSploit
Repository
SnailSploit/Claude-Red
Created
6 months ago
Last Updated
1 weeks ago
Language
Python
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category

Testing & QA Featured

offensive-lateral-movement

Comprehensive lateral movement tradecraft for authorized red team engagements covering credential-based movement (pass-the-hash, pass-the-ticket, overpass-the-hash), NTLM relay attacks (ntlmrelayx with PetitPotam, DFSCoerce, PrinterBug coercion), remote execution protocols (WMI, WinRM, DCOM, PsExec and alternatives), RDP session hijacking, and network pivoting through tunneling tools (chisel, ligolo-ng, SSH tunnels, SOCKS proxies). Provides operator-ready command sequences for mimikatz, crackmapexec/netexec, impacket suite, and evil-winrm with emphasis on OPSEC considerations, SMB signing bypass, and detection evasion. Maps to MITRE ATT&CK T1021 (Remote Services), T1550 (Use Alternate Authentication Material), and sub-techniques. Includes defender-perspective detection guidance for blue team awareness and a rapid engagement cheatsheet for common lateral movement scenarios encountered during internal penetration tests and assumed-breach exercises.

3,234 Updated 1 weeks ago
SnailSploit
AI & Automation Listed

active-directory-attacks

Provide comprehensive techniques for attacking Microsoft Active Directory environments. Covers reconnaissance, credential harvesting, Kerberos attacks, lateral movement, privilege escalation, and domain dominance for red team operations and penetration testing.

2 Updated yesterday
Ghosteken
AI & Automation Featured

active-directory-attacks

Provide comprehensive techniques for attacking Microsoft Active Directory environments. Covers reconnaissance, credential harvesting, Kerberos attacks, lateral movement, privilege escalation, and domain dominance for red team operations and penetration testing.

281 Updated 1 months ago
lingxling