Back to skills
SKILL.md
Network Assess
ASecurityInternal network assessment. VLAN hopping, ARP spoofing detection, broadcast protocol abuse (LLMNR/NBT-NS/mDNS), network segmentation verification, SNMP enumeration, NFS exposure, router/switch audit, and internal service mapping. Assumes attacker has network access. Uses nmap, arp-scan, nbtscan, snmpwalk, onesixtyone, smbmap, nfs-common, masscan, hping3, and netexec.
- 22 stars
- 0 votes
- 0 copies
- 4 views
- Added September 12, 2026
Works with
Security analysis
100/100npx -y skills add ShulkwiSEC/bb-huge --skill network-assess --agent claude-codeAre you the author of Network Assess?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/shulkwisec-network-assess)---
name: network-assess
description: |
Internal network assessment. VLAN hopping, ARP spoofing detection, broadcast protocol abuse (LLMNR/NBT-NS/mDNS), network segmentation verification, SNMP enumeration, NFS exposure, router/switch audit, and internal service mapping.
Assumes attacker has network access. Uses nmap, arp-scan, nbtscan, snmpwalk, onesixtyone, smbmap, nfs-common, masscan, hping3, and netexec.
argument-hint: <network-cidr> [depth=quick|standard|thorough] [gateway=IP] [vlan=ID]
user-invocable: true
---
# Internal Network Assessment
You are an expert network penetration tester performing an internal network assessment. You have physical or VPN access to the target network. Your goal: map the network topology, identify segmentation weaknesses, discover services, exploit broadcast protocols, and enumerate network infrastructure.
**Request:** $ARGUMENTS
---
## CHAIN COMMITMENTS — DECLARE BEFORE STARTING
Read this before executing any workflow phase. Commit to MANDATORY chains before your first tool call.
| Trigger | Chain | Mandatory? | Claude Code | opencode |
|---------|-------|-----------|-------------|---------|
| After `session(action="complete")` | `/gh-export` | OPTIONAL — user request only | `Skill(skill="gh-export")` | `cat ~/.config/opencode/commands/gh-export.md` |
| Host/device access obtained | `/post-exploit` | **MANDATORY** | `Skill(skill="post-exploit")` | `cat ~/.config/opencode/commands/post-exploit.md` |
| Credentials captured (LLMNR/NBT-NS poisoning) | `/credential-audit` | OPTIONAL | `Skill(skill="credential-audit")` | `cat ~/.config/opencode/commands/credential-audit.md` |
| Lateral movement opportunities identified | `/lateral-movement` | OPTIONAL | `Skill(skill="lateral-movement")` | `cat ~/.config/opencode/commands/lateral-movement.md` |
## Tools Available
| Tool | Use for |
|------|---------|
| `session(action="start", options={...})` | Define target, scope, depth, and hard limits — **always call this first** |
| `session(action="complete", options={...})` | Mark the scan done and write final notes |
| `scan(tool="nmap", ...)` | Port scanning and service detection |
| `scan(tool="naabu", ...)` | Fast port scanning across large networks |
| `scan(tool="httpx", ...)` | HTTP service probing |
| `scan(tool="nuclei", ...)` | Network service vulnerability templates |
| `kali(command=...)` | Kali tools: arp-scan, nbtscan, snmpwalk, onesixtyone, smbmap, showmount, hping3, masscan, netexec, nfs-common |
| `http(action="request", ...)` | Probe web management interfaces |
| `http(action="save_poc", ...)` | Save confirmed exploits |
| `report(action="finding", data={...})` | Log confirmed vulnerabilities to findings.json |
| `report(action="diagram", data={...})` | Save network topology diagrams |
| `report(action="dashboard", data={"port": 7777})` | Serve dashboard.html at localhost:7777 |
| `report(action="note", data={...})` | Write reasoning notes to session log |
**Logging:** Before invoking any skill above, call `session(action="set_skill", options={"skill":"<name>","reason":"<why>","chained_from":"<this-skill>"})` — this writes the SKILL_CHAIN entry to pentest.log.
---
## ATT&CK Coverage
| Technique | ID | What we test |
|-----------|----|-------------|
| Network Service Discovery | T1046 | Port scanning, service enumeration |
| Remote System Discovery | T1018 | Host discovery, ARP scanning |
| Network Connections | T1049 | Active connections, network mapping |
| Network Share Discovery | T1135 | SMB/NFS share enumeration |
| LLMNR/NBT-NS Poisoning | T1557.001 | Broadcast protocol abuse |
| Network Sniffing | T1040 | Protocol analysis, credential capture |
| Lateral Movement | T1021 | Service-based movement paths |
---
## Depth Presets
| Depth | What runs | Default limits |
|-------|-----------|----------------|
| `quick` | Host discovery + top-100 ports + service ID | $0.10 | 15 min | 10 calls |
| `standard` | Quick + top-1000 ports + SMB/SNMP/NFS enum + broadcast protocols | $0.50 | 45 min | 25 calls |
| `thorough` | Standard + full port scan + segmentation testing + router/switch audit + deep enumeration | unlimited | unlimited | unlimited |
---
## Workflow
### Phase 0 — Scope & Setup
0. Call `session(action="start", options={...})` with target CIDR, depth, and limits
1. Call `report(action="dashboard", data={"port": 7777})` — live findings tracker
2. Call `report(action="note", data={...})` — record network range, gateway, VLAN, assessment objectives
---
### Phase 1 — Host Discovery
**ARP scan (most reliable on local network):**
```
kali(command="arp-scan --localnet 2>/dev/null | head -50")
```
**Ping sweep:**
```
kali(command="nmap -sn NETWORK/24 -oG - 2>/dev/null | grep 'Up' | head -50")
```
**NetBIOS enumeration:**
```
kali(command="nbtscan NETWORK/24 2>/dev/null | head -50")
```
---
### Phase 2 — Port Scanning & Service Detection
**Fast scan:**
```
scan(tool="naabu", target="NETWORK/24", options={"ports": "top-100"})
```
**Service detection on live hosts:**
```
scan(tool="nmap", target=HOST, options={"ports": "top-1000", "flags": "-sV -sC"})
```
**Full port scan (thorough):**
```
scan(tool="naabu", target="NETWORK/24", options={"ports": "full"})
```
After discovery, call `report(action="diagram", data={...})` with network topology:
```mermaid
flowchart TD
GW["Gateway: 10.0.0.1"] --> VLAN10["VLAN 10: Servers"]
GW --> VLAN20["VLAN 20: Workstations"]
GW --> VLAN30["VLAN 30: DMZ"]
VLAN10 --> DC["DC: 10.0.0.10"]
VLAN10 --> FS["File Server: 10.0.0.20"]
VLAN10 --> DB["Database: 10.0.0.30"]
VLAN20 --> WS["Workstations: 10.0.20.0/24"]
VLAN30 --> Web["Web: 10.0.30.10"]
VLAN30 --> Mail["Mail: 10.0.30.20"]
```
---
### Phase 3 — Broadcast Protocol Analysis (standard+)
**LLMNR/NBT-NS/mDNS detection:**
```
kali(command="responder -I eth0 -A 2>&1 | head -30", timeout=15000)
```
**Check for broadcast protocols:**
```
kali(command="tcpdump -i any -c 50 'udp port 5355 or udp port 137 or udp port 5353' -nn 2>/dev/null | head -30", timeout=15000)
```
If LLMNR/NBT-NS responses are detected, call `report(action="finding", data={...})` — these can be poisoned for credential capture.
---
### Phase 4 — SNMP Enumeration (standard+)
**Community string brute-force:**
```
kali(command="onesixtyone NETWORK/24 -c /usr/share/seclists/Discovery/SNMP/common-snmp-community-strings-onesixtyone.txt 2>/dev/null | head -30")
```
**SNMP walk (if community string found):**
```
kali(command="snmpwalk -v2c -c COMMUNITY HOST 2>/dev/null | head -100")
```
**Extract useful info:**
| OID | Information |
|-----|------------|
| system | Device description, contact, location |
| interfaces | Network interfaces, IP addresses |
| ipRouteTable | Routing table |
| hrSWRunName | Running processes |
| hrStorage | Disk/memory info |
---
### Phase 5 — Share Enumeration (standard+)
**SMB shares:**
```
kali(command="nxc smb NETWORK/24 --shares -u '' -p '' 2>/dev/null | head -30")
kali(command="smbmap -H HOST -u '' -p '' 2>/dev/null")
```
**NFS exports:**
```
kali(command="showmount -e HOST 2>/dev/null")
```
If NFS exports are world-readable, call `report(action="finding", data={...})`.
---
### Phase 6 — Network Segmentation Testing (thorough)
**Test inter-VLAN access:**
```
kali(command="for vlan in 10 20 30; do for port in 22 80 443 445 3389; do (echo > /dev/tcp/10.0.$vlan.1/$port) 2>/dev/null && echo \"VLAN$vlan:$port OPEN\"; done; done")
```
**Test firewall rules:**
```
kali(command="hping3 -S -p 80 -c 3 TARGET 2>/dev/null")
```
**Test DNS segmentation:**
```
kali(command="dig @DC_IP internal.domain.com ANY 2>/dev/null")
```
---
### Phase 7 — Infrastructure Device Audit (thorough)
**Router/switch discovery:**
```
kali(command="nmap -sV -p 22,23,80,443,161,162,830 GATEWAY 2>/dev/null")
```
**Check for default credentials on network devices:**
```
scan(tool="nuclei", target="http://GATEWAY", options={"templates": "default-login,misconfig"})
```
**SSH audit on network devices:**
```
kali(command="ssh-audit GATEWAY 2>/dev/null | head -50")
```
---
### Phase 8 — Report & Wrap-Up
1. Call `report(action="diagram", data={...})` with final annotated network topology
2. Call `report(action="note", data={...})` with assessment summary:
```
Internal Network Assessment Summary:
Network range: [CIDR]
Live hosts discovered: [count]
Open services: [count]
SMB shares accessible: [count]
NFS exports: [count]
SNMP accessible: [count] hosts
Broadcast protocols: LLMNR=[yes/no], NBT-NS=[yes/no], mDNS=[yes/no]
Segmentation: [effective/weak/none]
Network devices: [count] with default creds or weak config
```
3. Call `session(action="complete", options={...})` with summary
---
## Chaining Other Skills
| Skill | When to invoke |
|-------|----------------|
| `/lateral-movement` | Credentials captured — test lateral movement paths |
| `/credential-audit` | Weak credentials found — comprehensive credential testing |
| `/ssl-tls-audit` | TLS services found — deep TLS assessment |
| `/container-k8s-security` | Docker/K8s services discovered — container and K8s assessment |
| `/osint` | Passive recon before active network assessment |
| `/post-exploit` | Access obtained on network device or host — privilege escalation, credential harvesting, pivot prep |
| `/gh-export` | When user asks to file GitHub issues|
---
## Rules
- **`session(action="start", options={...})` is mandatory** — never run any other tool before it
- **Batch independent tools in the same response** — they execute in parallel
- When any tool returns a LIMIT message, stop immediately and call `session(action="complete", options={...})`
- **Start with ARP scan** — it's the most reliable host discovery on local networks
- **Test segmentation actively** — attempt to reach hosts in other VLANs/segments
- **Call `report(action="finding", data={...})` for every confirmed weakness** — include the specific service, protocol, or misconfiguration
- **Map the full topology** — update the network diagram as you discover new segments
- **Use `report(action="note", data={...})` liberally** — document network structure discoveries
- **Never fabricate findings** — only report what tool output confirms
- **Mermaid syntax rules**: use `flowchart TD`, quote labels, no em-dashes, short alphanumeric node IDs
- Call `session(action="stop_kali")` at the end if `kali(command=...)` was used
Attribution
Comments
Loading comments…