LogoAwesome Skills
  • Search
  • Category
  • Tag
  • Blog
LogoAwesome Skills
LogoAwesome Skills

Discover Open-Source Agent Skills for AI Coding Assistants

Product

  • Search
  • Category
  • Tag
  • Blog

Resources

  • Claude Skill Docs
  • Antigravity Skills Docs

Tools

  • Claude Code
  • OpenCode
  • Cursor
  • Codex
  • Antigravity

Company

  • Privacy Policy
  • Terms of Service
  • Sitemap

©2026 Awesome Skills. All rights reserved.

Privacy PolicyTerms
Back to Skills

network-protocol-attacks

Network protocol attack playbook. Use when exploiting layer 2/3 protocols including ARP spoofing, LLMNR/NBT-NS/mDNS poisoning, WPAD abuse, DHCPv6 attacks, VLAN hopping, STP manipulation, DNS spoofing, IPv6 attacks, and IDS/IPS evasion.

1,311stars179forksUpdated 7/8/2026
Security#security#penetration-testing#mitm#red-team#networking

Security Assessment

High Risk(35/100)

Detected risks:

Agent-reviewed override(Offensive L2/L3 network-attack playbook (ARP/LLMNR poisoning, VLAN hopping, MITM, IDS/IPS evasion). Local assessor didn't match its terminology; flagged manually from the doc's description. Genuine offensive tooling, per gotcha #7.)
Security Score35/100

About network-protocol-attacks

An offensive-security playbook in the yaklang hack-skills collection, covering attacks against low-level network protocols for authorized penetration testing and red-team assessments. Per its description it spans layer 2 and layer 3 techniques such as ARP spoofing, LLMNR/NBT-NS/mDNS poisoning, WPAD abuse, DHCPv6 attacks, VLAN hopping, STP manipulation, DNS spoofing, and IPv6-related attacks, as well as IDS/IPS evasion. It is framed as an expert playbook for operators assessing how resilient an internal network is to man-in-the-middle and traffic-manipulation attacks that exploit trust in local-network protocols. In a catalog context it is adversary-simulation tooling used to validate network segmentation, monitoring, and hardening. Because these techniques can intercept or disrupt traffic, they must be used only within an authorized engagement on networks the tester is permitted to assess. Defensive teams can use the same categories to prioritize protections such as dynamic ARP inspection, disabling LLMNR/NBT-NS, DHCP snooping, and segmentation, and to tune IDS/IPS for the evasion methods.

FAQ

What does this skill cover?

Layer 2/3 network attacks including ARP spoofing, LLMNR/NBT-NS/mDNS poisoning, WPAD abuse, DHCPv6 attacks, VLAN hopping, STP manipulation, DNS spoofing, IPv6 attacks, and IDS/IPS evasion.

When is it used?

In authorized penetration tests and red-team assessments evaluating how resistant an internal network is to man-in-the-middle and traffic-manipulation attacks.

What layer does it target?

Primarily local-network layer 2 and layer 3 protocols, where attacks exploit implicit trust in protocols like ARP, LLMNR, and DHCP.

Is authorization required?

Yes — these techniques can intercept or disrupt traffic and must only be used on networks the tester is explicitly permitted to assess.

How do defenders respond?

By enabling dynamic ARP inspection, disabling LLMNR/NBT-NS, using DHCP snooping and segmentation, and tuning IDS/IPS for the evasion methods.

All Files

2 files
NAME_RESOLUTION_POISONING.md6.2 KB
View
SKILL.md9.2 KB
View

Install network-protocol-attacks

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill

Repository

yaklang/hack-skills

Related Skills

ccf-idea-reviewer

2,958

ccf-integrity-auditor

2,958

finance-sentiment

3,382

ccf-humanization

2,958