Internal infrastructure penetration testing from a network foothold. Use when the user mentions internal pentest, lateral movement, privilege escalation (LPE), LSASS dump, Mimikatz/NanoDump/secretsdump, PsExec, WMI, WinRM, NTLM relay, Responder, mitm6, LLMNR/NBT-NS poisoning, IPv6 takeover, DPAPI, GPP cpassword, LAPS, KeePass, SUID/GTFOBins, sudo NOPASSWD, container escape, kernel exploit, MSSQL link, or generic Windows/Linux post-exploitation.
Installation
Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.
04-infra-internal/08-lateral-movement.md — PsExec/WMI/WinRM, PtH/PtT, RDP, DB links, SSH.
04-infra-internal/09-persistence.md — scheduled task, service, SSH key, web shell.
How to operate
Confirm foothold type (drop-box, VPN, joined VM, starting credential) and ROE allowances for noisy primitives.
Passive before active: 30–60 minutes of broadcast capture before any TX often surfaces NTLMv2 or DHCP context.
For each user question, locate the matching phase file and stable ID; expand How to test for tooling. Note per-item destructive (⚠) and post-ex (🎯) markers per CONVENTIONS.md.
AD-specific attack chains → switch to pentest-active-directory for depth (BloodHound, Kerberos, ADCS, NTLM-relay→DA).
Track every dropped binary / service / scheduled task for cleanup at engagement end.