Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Network Pentester

  • 30 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Guides authorized network and infrastructure penetration testing: scoping and ROE, host/service enumeration, AD attack paths, segmentation testing, and remediation reporting.

About

Guides authorized network and infrastructure penetration testing including rules of engagement, enumeration, Active Directory attack paths, segmentation validation, and remediation-focused reporting. A developer uses it when planning or executing external or internal network assessments with written authorization.

  • Emphasizes written authorization, ROE boundaries, and emergency stop procedures
  • Covers host/service enumeration, AD lateral movement, and retest of critical findings

Network Pentester by the numbers

  • 30 all-time installs (skills.sh)
  • Ranked #1,492 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill network-pentester

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs30
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Guides authorized network and infrastructure penetration testing: scoping and ROE, host/service enumeration, AD attack paths, segmentation testing, and remediation reporting.

Files

SKILL.mdMarkdownGitHub ↗

Network Pentester

When to Use

  • Plan or execute authorized external or internal network and infrastructure assessments
  • Draft or validate rules of engagement, asset lists, test windows, and emergency stop procedures
  • Perform host and service enumeration, banner/version correlation, and manual validation of scanner output
  • Test network services (SSH, RDP, SMB, LDAP, databases, management planes) within agreed impact
  • Document Active Directory attack paths, credential exposure, and in-scope lateral movement
  • Validate segmentation, firewall rules, and east-west controls between zones
  • Apply high-level wireless assessment methodology when explicitly scoped
  • Produce remediation-focused reports and retest critical/high network findings

When NOT to Use

  • OWASP web app, API, or session/auth testing → web-pentester
  • Cross-engagement pentest program when network is not the primary specialty → penetration-tester
  • Jailbreak LLMs, prompt injection, or agent tool abuse → ai-redteam
  • Lead red team campaigns, purple team, or detection validation programs → red-team-specialist
  • Triage SIEM/EDR alerts or SOC playbooks → soc-analyst
  • Lead live incident command or war-room comms → incident-responder
  • Implement IAM, WAF, SIEM, or cloud org guardrails → information-security-engineer, cloud-security-engineer
  • Provision VPCs, clusters, or IaC without offensive testing → infrastructure-engineer

Related skills

NeedSkill
Web/API OWASP and proxy-based app testingweb-pentester
Broader pentest types (web + network + cloud workload in one ROE)penetration-tester
Red team campaigns, purple team, ATT&CK emulationred-team-specialist
Security program, pentest governance, GRCcybersecurity
Remediate findings (IdP, EDR, network ACLs, hardening)information-security-engineer
Cloud control implementation and misconfig fixescloud-security-engineer
Platform networking and IaC designinfrastructure-engineer
LLM/agent adversarial testingai-redteam
Customer-facing pentest reportstech-writer-researcher

Core Workflows

1. Scope and authorization

Do not test without written authorization.

1. Confirm signed SOW/ROE: IP ranges, hostnames, AD domains, methods, windows, contacts 2. Define out-of-scope (third parties, production PII, DoS unless approved, out-of-window systems) 3. Agree severity rubric, evidence handling, and credential/data minimization 4. Establish emergency stop and escalation path 5. Prefer isolated lab VLANs, jump hosts, or designated test forests when possible

See `references/network_pentester_scope.md` and `references/scoping_and_rules_of_engagement.md`.

2. Enumeration and service testing

asset inventory → live host discovery → port/service ID → version & config review → validate findings

Document source, timestamp, tool, and raw output references. Validate automated scanner results manually before reporting.

See `references/enumeration_and_service_testing.md`.

3. AD, lateral movement, and segmentation (in scope only)

  • Map identity attack paths only per ROE (domain admin is not a default goal unless scoped)
  • Document lateral movement with minimal PoC; redact secrets in evidence
  • Test segmentation between zones; record allowed vs denied paths with packet/trace proof when useful
  • Wireless: methodology and safe testing only when scoped—see segmentation/wireless reference

See `references/active_directory_and_lateral_movement.md` and `references/segmentation_wireless_and_external.md`.

4. Reporting, remediation, and retest

Per finding: title, severity, impact, reproduction, evidence, remediation, retest criteria. Deliver executive summary + technical appendix; schedule retest for critical/high.

See `references/reporting_retest_safe_practices.md`.

When to load references

TopicReference
Role boundariesreferences/network_pentester_scope.md
Authorization and ROEreferences/scoping_and_rules_of_engagement.md
Host/service enumerationreferences/enumeration_and_service_testing.md
AD and lateral movementreferences/active_directory_and_lateral_movement.md
Segmentation, wireless, externalreferences/segmentation_wireless_and_external.md
Reports, retest, safe practicesreferences/reporting_retest_safe_practices.md

Related skills

Securityauditappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.