Network protocol attack playbook. Use when exploiting layer 2/3 protocols including ARP spoofing, LLMNR/NBT-NS/mDNS poisoning, WPAD abuse, DHCPv6 attacks, VLAN hopping, STP manipulation, DNS spoofing, IPv6 attacks, and IDS/IPS evasion.
Detected risks:
An offensive-security playbook in the yaklang hack-skills collection, covering attacks against low-level network protocols for authorized penetration testing and red-team assessments. Per its description it spans layer 2 and layer 3 techniques such as ARP spoofing, LLMNR/NBT-NS/mDNS poisoning, WPAD abuse, DHCPv6 attacks, VLAN hopping, STP manipulation, DNS spoofing, and IPv6-related attacks, as well as IDS/IPS evasion. It is framed as an expert playbook for operators assessing how resilient an internal network is to man-in-the-middle and traffic-manipulation attacks that exploit trust in local-network protocols. In a catalog context it is adversary-simulation tooling used to validate network segmentation, monitoring, and hardening. Because these techniques can intercept or disrupt traffic, they must be used only within an authorized engagement on networks the tester is permitted to assess. Defensive teams can use the same categories to prioritize protections such as dynamic ARP inspection, disabling LLMNR/NBT-NS, DHCP snooping, and segmentation, and to tune IDS/IPS for the evasion methods.
Layer 2/3 network attacks including ARP spoofing, LLMNR/NBT-NS/mDNS poisoning, WPAD abuse, DHCPv6 attacks, VLAN hopping, STP manipulation, DNS spoofing, IPv6 attacks, and IDS/IPS evasion.
In authorized penetration tests and red-team assessments evaluating how resistant an internal network is to man-in-the-middle and traffic-manipulation attacks.
Primarily local-network layer 2 and layer 3 protocols, where attacks exploit implicit trust in protocols like ARP, LLMNR, and DHCP.
Yes — these techniques can intercept or disrupt traffic and must only be used on networks the tester is explicitly permitted to assess.
By enabling dynamic ARP inspection, disabling LLMNR/NBT-NS, using DHCP snooping and segmentation, and tuning IDS/IPS for the evasion methods.
Quick Setup:
.claude/skills/Repository
yaklang/hack-skills