Skip to content
Merged
15 changes: 14 additions & 1 deletion capabilities/network-ops/capability.yaml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
schema: 1
name: network-ops
version: "2.0.0"
version: "2.1.0"
Comment thread
mkultraWasHere marked this conversation as resolved.
description: >
Network operations and Active Directory exploitation. Multi-agent
pipeline for autonomous red teaming with Nmap scanning, Netexec
Expand Down Expand Up @@ -30,6 +30,19 @@ workers:
dependencies:
python:
- "loguru>=0.7.0"
- "impacket>=0.12.0"
scripts:
- scripts/install_coercion_tools.sh

checks:
- name: nmap
command: "command -v nmap >/dev/null 2>&1"
- name: petitpotam
command: "test -f /opt/PetitPotam/PetitPotam.py"
- name: dfscoerce
command: "test -f /opt/DFSCoerce/dfscoerce.py"
- name: shadowcoerce
command: "test -f /opt/ShadowCoerce/shadowcoerce.py"

keywords:
- network-ops
Expand Down
20 changes: 20 additions & 0 deletions capabilities/network-ops/scripts/install_coercion_tools.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
#!/usr/bin/env bash
# Install coercion scripts for NTLM relay attacks.
# Runs at sandbox provision time via dependencies.scripts.
set -euo pipefail

REPOS=(
"https://github.com/topotam/PetitPotam /opt/PetitPotam"
"https://github.com/Wh04m1001/DFSCoerce /opt/DFSCoerce"
"https://github.com/ShutdownRepo/ShadowCoerce /opt/ShadowCoerce"
)

for entry in "${REPOS[@]}"; do
read -r url dest <<< "$entry"
if [ -d "$dest" ]; then
echo "[*] $dest already exists, skipping"
else
echo "[+] Cloning $(basename "$dest") to $dest"
git clone --depth 1 "$url" "$dest"
fi
done
7 changes: 5 additions & 2 deletions capabilities/network-ops/skills/ad-attack-patterns/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -92,10 +92,13 @@ Reference for common AD attack chains. Each pattern lists prerequisites, tool se

**Prerequisites:** Ability to coerce authentication, relay target that accepts NTLM (SMB signing disabled, LDAP signing not required, or AD CS HTTP endpoint).

**Preferred:** Use `impacket_ntlmrelay_attack` — a single tool call that starts the relay, fires coercion, monitors for success, and returns combined output. This avoids the sequencing problem where ntlmrelayx must be running before coercion fires.

| Step | Tool | Action |
|---|---|---|
| 1. Start relay listener | `impacket_ntlmrelayx` | Listen and relay to target (SMB/LDAP/AD CS) |
| 2. Coerce authentication | See coercion method selection below | Force target to authenticate to relay |
| Combined (preferred) | `impacket_ntlmrelay_attack` | Start relay + fire coercion + capture result in one call |
| 1. Start relay listener (manual) | `impacket_ntlmrelayx` | Listen and relay to target (SMB/LDAP/AD CS) |
| 2. Coerce authentication (manual) | See coercion method selection below | Force target to authenticate to relay |
| 3. Relay captures and forwards | ntlmrelayx relays auth | Escalation depends on relay target |

**Relay targets by impact:**
Expand Down
Loading
Loading