Borrowing it
Nothing to install: this file belongs to fb0sh/pentester. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/fb0sh/pentester/main/.agents/skills/third-party/intranet-pentest-advanced/SKILL.mdgit clone --depth 1 https://github.com/fb0sh/pentesterWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/fb0sh/pentester/intranet-pentest-advanced)<a href="https://agentmods.dev/skills/fb0sh/pentester/intranet-pentest-advanced"><img src="https://agentmods.dev/badge/skills/fb0sh/pentester/intranet-pentest-advanced/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/fb0sh/pentester/intranet-pentest-advanced"><img src="https://agentmods.dev/badge/skills/fb0sh/pentester/intranet-pentest-advanced.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00050 | $0.00964 |
| Opus 5 | $0.00025 | $0.00482 |
| Sonnet 5 | $0.00010 | $0.00193 |
| Haiku 4.5 | $0.00005 | $0.00096 |
Grade A, and why
intranet-pentest-advanced scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to intranet-pentest-advanced — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
What it actually says
内网渗透高级 Skill
当任务从互联网评估转入主机、域或内网操作时使用本 Skill。需要已获得初始访问权限或立足点。
前置条件:如果尚未获得初始访问,先完成外网渗透获取立足点。
场景路由
| 目标类型 | 首选参考 |
|---|---|
| 横向移动(PsExec/WMI/WinRM/DCOM/SSH/RDP/PTH/PTT) | references/intranet-playbook-01-lateral-movement.md |
| 规避与反检测(AMSI绕过/ETW/注入/伪装/签名二进制滥用) | references/intranet-playbook-02-evasion-and-anti-detection.md |
| 凭据窃取(Mimikatz/Kerberoasting/DCSync/浏览器Vault) | references/intranet-playbook-03-credential-theft.md |
| 提权与持久化(Token/Service/Potato/Cron/Registry/WMI) | references/intranet-playbook-04-privilege-escalation.md + 05-persistence.md |
| 隧道与代理(FRP/Chisel/Ligolo/SOCKS/SSH/DNS/ICMP) | references/intranet-playbook-06-tunneling-and-proxy.md |
| 信息收集 | references/intranet-playbook-07-information-gathering.md |
| AD 攻击(BloodHound/AS-REP/Kerberoasting/Golden/Silver) | references/intranet-playbook-08-active-directory-attacks.md |
| ADCS 攻击(ESC1-8/Certipy/Certreq) | references/intranet-playbook-09-adcs-attacks.md |
| Exchange 攻击 | references/intranet-playbook-10-exchange-attacks.md |
| SharePoint 攻击 | references/intranet-playbook-11-sharepoint-attacks.md |
测试流程
1. 信息收集
- 内网拓扑、网段、主机发现
- 域信息、信任关系
- 服务识别与漏洞探测
2. 凭据获取
- Mimikatz 抓取内存凭据
- Kerberoating / AS-REP Roasting
- 浏览器/密码管理器凭据提取
- DCSync(需域管权限)
3. 横向移动
- Pass-the-Hash / Pass-the-Ticket
- PsExec / WMI / WinRM / DCOM
- SSH / RDP 横向
4. 权限提升
- Token 篡改 / 服务滥用
- Potato 家族
- 域提权(GPO/ACL滥用)
5. 持久化
- 计划任务 / WMI 事件订阅
- 注册表 / 启动项 / 服务
- 黄金票据 / 白银票据
6. 隧道与代理
- SOCKS 代理 / SSH 转发
- FRP / Chisel / Ligolo
- DNS / ICMP 隧道
7. AD/ADCS 专项
- BloodHound 路径分析
- ADCS 证书模板滥用
- Exchange/SharePoint 攻击链
参考文档
references/06-intranet-and-host-operations-integrated.md— 内网操作整合参考references/intranet-playbook-01~11-*.md— 各专项 Playbook(11 个)references/intranet-pentest-playbook-skill.md— Playbook 入口
What ships with it
15 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- references/06-intranet-and-host-operations-integrated.md 63 KB
- references/intranet-pentest-playbook-openai.yaml 306 B
- references/intranet-pentest-playbook-skill.md 2.7 KB
- references/intranet-playbook-01-lateral-movement.md 7.1 KB
- references/intranet-playbook-02-evasion-and-anti-detection.md 5.6 KB
- references/intranet-playbook-03-credential-theft.md 10 KB
- references/intranet-playbook-04-privilege-escalation.md 7.0 KB
- references/intranet-playbook-05-persistence.md 5.1 KB
- references/intranet-playbook-06-tunneling-and-proxy.md 5.1 KB
- references/intranet-playbook-07-information-gathering.md 7.1 KB
- references/intranet-playbook-08-active-directory-attacks.md 6.1 KB
- references/intranet-playbook-09-adcs-attacks.md 2.1 KB
- references/intranet-playbook-10-exchange-attacks.md 2.0 KB
- references/intranet-playbook-11-sharepoint-attacks.md 996 B
- references/intranet-playbook-index.md 740 B
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 77 lines · 50 tokens per session scan A 419ea0be669f
intranet-pentest-advanced is a skill published in the GitHub repository fb0sh/pentester (23 stars, last pushed 1mo ago), licensed MIT. It adds 50 tokens to every session and 964 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to intranet-pentest-advanced, differing in 0 lines, and is treated as a copy.
Other skills, from other repositories
transilience-report-style
Threat Intelligence Report Design System — ReportLab-based PDF generation for A4 reports with Transilience branding, typography, and layout standards.
firewall-review
Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate Benchmark guidance, a custom customer-policy benchmark, and consolidated network-team Excel profiles including grouped…
hackerone
HackerOne bug bounty automation - parses scope CSVs, deploys parallel pentesting agents per asset, validates PoCs, and generates platform-ready submission reports.
pci-secure-software
Automated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation. Deterministically enumerates every applicable Test Requirement from a pinned catalog, gathers source/doc evidence, and emits an evidence-bound per-requirement verdict (MET / NOTMET /…
pentest-engagement
Run a professional penetration engagement OR a network vulnerability scan from a scope. WEB mode (apex domains / app URLs) — mandatory surface expansion, systematic OWASP attack-class coverage, reversible active exploitation, authoritative validation, Transilience PDF. NETWORK mode (a list of IPs/CIDRs, e.g. 1500…
attack-path-stitcher
Stitches confirmed single-asset findings into multi-hop attack paths across the organization. Builds a graph where nodes are assets and edges are confirmed exploit hops citing the findings that enable them.