Run an authorized network penetration test: host discovery, port/service enumeration, vulnerability identification, exploitation, and lateral movement/pivoting — within an agreed scope and rules of engagement. Use to actively test internal/external network security you're authorized to assess.
Pro scans all 2 files and shows the line behind each finding
Scanned 9/19/2026
npx -y skills add jassics/awesome-claude-security --skill network-pentest --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Network Pentest?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/jassics-network-pentest)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: network-pentest
description: >-
Run an authorized network penetration test: host discovery, port/service
enumeration, vulnerability identification, exploitation, and lateral
movement/pivoting — within an agreed scope and rules of engagement. Use to
actively test internal/external network security you're authorized to assess.
---
# Goal
Evidence-backed network findings and demonstrated impact (where authorized), mapped
to a methodology and ranked — without straying outside scope or causing disruption.
# Prerequisites
- **Authorization and explicit scope**: in-scope ranges/hosts, exclusions, testing
window, rules of engagement, and allowed techniques. Do not touch out-of-scope
systems. Coordinate to avoid outages.
# Methodology (see `reference.md` for ports/services/checks)
1. **Host discovery** — identify live hosts within scope (respecting rate limits).
2. **Port & service enumeration** — open ports, service/version fingerprinting,
default/again-exposed admin services.
3. **Vulnerability identification** — map services to known weaknesses and
misconfigurations; validate, don't just trust a scanner.
4. **Exploitation** (only if authorized, to the depth agreed) — confirm exploitable
issues with controlled, non-destructive proof.
5. **Post-exploitation / lateral movement** — assess what the foothold reaches:
credential exposure, trust relationships, pivoting — within RoE.
6. **Document** — findings with evidence, impact, and remediation; log what you did
for deconfliction.
# Output
A findings table: host/service · issue · evidence · impact · remediation, plus a
network attack-path view (`security-diagramming:attack-tree`) for notable chains.
Confirmed issues → `security-reporting:finding`.
# Notes
Validate before exploiting and keep proofs non-destructive — this is assessment, not
disruption. Stay strictly in scope and log activity for deconfliction. The
highest-impact network findings are usually exposed admin services, weak/again-used
credentials, and flat networks enabling lateral movement (see
`network-segmentation-review`).
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!