Agent skill

Infrastructure Enumeration

by blacklanternsecurity in blacklanternsecurity/red-run

Enumeration of infrastructure services: DNS, SMTP, SNMP, IPMI, NFS, TFTP, RPC/MSRPC, and HTTP/HTTPS surface detection.

GPL-3.0Auto-check: notesBackend & APIs

Install Infrastructure Enumeration

skills CLI
$ npx skills add blacklanternsecurity/red-run --skill infrastructure-enumeration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install blacklanternsecurity/red-run infrastructure-enumeration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/blacklanternsecurity/red-run.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/network/infrastructure-enumeration .claude/skills/infrastructure-enumeration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
infrastructure-enumeration
GitHub stars
286
Token cost
~2.4k tokens
SKILL.md length
723 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
GPL-3.0

At a glance

Enumeration of infrastructure services: DNS, SMTP, SNMP, IPMI, NFS, TFTP, RPC/MSRPC, and HTTP/HTTPS surface detection.

  • Tasks that involve Transactional email
  • SKILL.md covers Engagement Logging, Scope Boundary, State Management and Prerequisites, plus 12 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Infrastructure Enumeration is an agent skill from blacklanternsecurity/red-run. Enumeration of infrastructure services: DNS, SMTP, SNMP, IPMI, NFS, TFTP, RPC/MSRPC, and HTTP/HTTPS surface detection. Checks zone transfers, open relays, default community strings, cipher zero, NFS exports, and web technology fingerprinting. Use after network-recon identifies infrastructure ports.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Transactional email. The repository describes itself as: Offensive security toolkit for Claude Code. The licence is GPL-3.0.

When your agent uses it

  • Tasks that involve Transactional email

Example prompts

  • “/infrastructure-enumeration”

What it can do on your machine

Read from SKILL.md and the folder at commit 050ac1f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Infrastructure Enumeration loads about 2.4k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 723 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:226
    # Mount and explore (requires sudo — note in return if unavailable)
  • NoteRuns commands with sudoSKILL.md:227
    sudo mount -t nfs TARGET_IP:/share /mnt/nfs -o nolock

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from blacklanternsecurity/red-run at commit 050ac1f, republished under its GPL-3.0 licence (© blacklanternsecurity). 723 words, ~2,445 tokens.

Download SKILL.mdSave it as .claude/skills/infrastructure-enumeration/SKILL.md (or your agent's skills folder).
name
infrastructure-enumeration
description
Enumeration of infrastructure services: DNS, SMTP, SNMP, IPMI, NFS, TFTP, RPC/MSRPC, and HTTP/HTTPS surface detection. Checks zone transfers, open relays, default community strings, cipher zero, NFS exports, and web technology fingerprinting. Use after network-recon identifies infrastructure ports.
keywords
DNS zone transfer, SMTP relay, SNMP community string, IPMI cipher zero, NFS no_root_squash, TFTP, RPC null session, HTTP tech detect, snmpwalk, onesixtyone…
tools
nmap, snmpwalk, onesixtyone, dnsrecon, smtp-user-enum, httpx
opsec
medium

Infrastructure Enumeration

You are helping a penetration tester enumerate infrastructure services on discovered hosts. All testing is under explicit written authorization.

Engagement Logging

Check for ./engagement/ directory. If absent, proceed without logging. When present:

  • Print [infrastructure-enumeration] Activated → <target> on activation.
  • Save significant output to engagement/evidence/ with descriptive filenames (e.g., dns-zone-transfer-10.10.10.5.txt, snmp-walk-10.10.10.20.txt).

Scope Boundary

This skill covers infrastructure service enumeration only — misconfigs, default credentials, and info disclosure on non-web, non-AD services, plus surface-level HTTP/HTTPS tech detection.

Out of scope — route instead:

  • Deep web application testing
  • Kerberos/LDAP/domain enumeration
  • Credential brute force
  • Exploitation of discovered vulns → return to orchestrator

Do not load or execute another skill. Stay in methodology.

State Management

Call get_state_summary() to read current engagement state. Use it to:

  • Skip services already enumerated
  • Leverage existing credentials (e.g., SNMP community strings already found)
  • Check Blocked section for previous failures

State writes — write critical discoveries immediately:

  • SNMP community string → add_credential(username="", secret="<community>", secret_type="other", source="SNMP on <host>")
  • SNMP network interfaces revealing subnets → add_pivot(source="SNMP on <host>", destination="<subnet>", method="SNMP interface enumeration")
  • LDAP signing not required → add_vuln(title="LDAP signing not required on <host>", host="<host>", vuln_type="ldap-signing", severity="medium")
  • LDAP anonymous bind → add_vuln(title="LDAP anonymous bind on <host>", host="<host>", vuln_type="null-session", severity="medium")
  • Domain name from rootDSE/LDAP → add_pivot(source="LDAP rootDSE on <host>", destination="<domain>", method="LDAP enumeration")
  • NFS no_root_squash → add_vuln(title="NFS no_root_squash on <host>:<share>", host="<host>", vuln_type="nfs-misconfig", severity="high")
  • IPMI cipher 0 → add_vuln(title="IPMI cipher zero on <host>", host="<host>", vuln_type="ipmi-cipher-zero", severity="critical")
  • DNS zone transfer → add_vuln(title="DNS zone transfer on <host>", host="<host>", vuln_type="zone-transfer", severity="medium")
  • SMTP open relay → add_vuln(title="SMTP open relay on <host>", host="<host>", vuln_type="open-relay", severity="high")

Report all findings in your return summary.

Prerequisites

  • Network access to target host(s)
  • Port list from orchestrator or network-recon (open TCP/UDP ports)
  • For SNMP/IPMI/TFTP: UDP scan results (UDP-only services)

Only run sections for ports that are actually open. Skip sections entirely if the relevant ports are not open — do not scan for ports yourself.

DNS — Port 53

bash
nmap -sV -p53 --script dns-zone-transfer,dns-cache-snoop,dns-nsid TARGET_IP

# Zone transfer (requires domain name — check state or reverse DNS)
dig axfr @TARGET_IP target.com
host -l target.com TARGET_IP

# Reverse DNS sweep (discover hostnames on the subnet)
dnsrecon -r 10.10.10.0/24 -n TARGET_IP

# Subdomain brute force
dnsenum --dnsserver TARGET_IP --enum target.com \
  -f /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt

Quick wins: Zone transfer (full DNS dump), wildcard records, internal hostnames revealing naming conventions and services.

SMTP — Ports 25/465/587

bash
nmap -sV -p25,465,587 --script smtp-commands,smtp-enum-users,smtp-open-relay,smtp-vuln* TARGET_IP

# User enumeration via VRFY/RCPT/EXPN
smtp-user-enum -M VRFY -U users.txt -t TARGET_IP
smtp-user-enum -M RCPT -U users.txt -t TARGET_IP
smtp-user-enum -M EXPN -U users.txt -t TARGET_IP

Quick wins: Open relay (send mail as anyone), user enumeration (valid accounts), NTLM auth info leak (MAIL FROM:<> AUTH NTLM reveals internal hostname/domain).

RPC/MSRPC — Ports 111/135

bash
# Linux RPC (port 111)
rpcinfo -p TARGET_IP
showmount -e TARGET_IP  # NFS preview

# Windows MSRPC (port 135)
rpcclient -U "" -N TARGET_IP
rpcclient -U "" -N TARGET_IP -c "enumdomusers;enumdomgroups;getdompwinfo"
rpcdump.py TARGET_IP | grep -E "Protocol|Provider"

Quick wins: Null session user enumeration, NFS shares via rpcinfo, MSRPC endpoint map revealing internal services.

LDAP — Ports 389/636/3268

bash
# rootDSE query (always allowed per RFC)
ldapsearch -x -H ldap://TARGET_IP -b "" -s base namingContexts

# Anonymous directory read
ldapsearch -x -H ldap://TARGET_IP -b "DC=domain,DC=local" \
  "(objectClass=user)" sAMAccountName description memberOf

nmap -sV -p389,636,3268 --script ldap-rootdse,ldap-search TARGET_IP

Quick wins: Anonymous bind, password in description, rootDSE domain disclosure, LDAP signing not required.

→ STOP and return with: what was achieved, new findings, context for next steps. domain name from rootDSE, anonymous bind results.

Kerberos — Port 88

DO NOT enumerate. Kerberos enumeration and ticket requests belong to AD skills.

→ STOP and return with: what was achieved, new findings, context for next steps. domain name, any credentials found.

Show full SKILL.md (294 more words)Show less

HTTP/HTTPS — Ports 80/443/8080/8443

bash
# HTTP enumeration
nmap -sV -p80,443,8080,8443 \
  --script http-title,http-headers,http-methods,http-robots.txt,http-enum TARGET_IP

# Tech stack identification
whatweb TARGET_IP
httpx -u TARGET_IP -ports 80,443,8080,8443 \
  -title -tech-detect -status-code -follow-redirects

Quick wins: Default credentials on management interfaces (Tomcat, Jenkins, phpMyAdmin), exposed admin panels, directory listing, .git/.svn exposed, phpinfo(), server-status/server-info.

→ STOP and return with: what was achieved, new findings, context for next steps. URL, tech stack, interesting headers or findings. Do not execute web fuzzing or directory brute force inline.

SNMP — Ports 161/162 (UDP)

bash
# Community string brute force
onesixtyone -c /usr/share/seclists/Discovery/SNMP/snmp.txt TARGET_IP

# Walk with found community string
snmpwalk -v2c -c public TARGET_IP .1
snmpwalk -v2c -c public TARGET_IP NET-SNMP-EXTEND-MIB::nsExtendOutputFull

# Bulk walk for speed
snmpbulkwalk -v2c -c public TARGET_IP .1 > snmp_full_dump.txt

# Specific high-value OIDs
snmpwalk -v2c -c public TARGET_IP 1.3.6.1.4.1.77.1.2.25  # Windows users
snmpwalk -v2c -c public TARGET_IP 1.3.6.1.2.1.25.4.2.1.2  # Running processes
snmpwalk -v2c -c public TARGET_IP 1.3.6.1.2.1.6.13.1.3    # TCP connections
snmpwalk -v2c -c public TARGET_IP 1.3.6.1.2.1.25.6.3.1.2  # Installed software

Quick wins: Default public/private community strings, user enumeration, running process list, installed software, network interfaces revealing new subnets, Net-SNMP Extend RCE (check nsExtendOutputFull).

IPMI — Port 623 (UDP)

bash
nmap -sU -p623 --script ipmi-version,ipmi-cipher-zero TARGET_IP
ipmitool -I lanplus -H TARGET_IP -U "" -P "" user list
# RAKP hash disclosure: msf auxiliary/scanner/ipmi/ipmi_dumphashes

Quick wins: Cipher 0 (auth bypass), default creds (admin/admin, ADMIN/ADMIN), RAKP hash disclosure for offline cracking.

NFS — Port 2049

bash
showmount -e TARGET_IP
nmap -sV -p2049 --script nfs-ls,nfs-showmount,nfs-statfs TARGET_IP

# Mount and explore (requires sudo — note in return if unavailable)
sudo mount -t nfs TARGET_IP:/share /mnt/nfs -o nolock
ls -la /mnt/nfs/

Quick wins: World-readable shares (credential files, configs), writable shares (SUID binary plant), no_root_squash (root file injection for privesc).

TFTP — Port 69 (UDP)

bash
nmap -sU -p69 --script tftp-enum TARGET_IP

# Grab common files
tftp TARGET_IP -c get /etc/passwd
tftp TARGET_IP -c get running-config
tftp TARGET_IP -c get startup-config

Quick wins: Open TFTP with config files (router/switch configs), credential files, firmware images.

Escalate or Pivot

After enumeration, return to the orchestrator with routing recommendations:

  • Web services (pass URLs, tech stack)
  • AD services (LDAP/Kerberos) (pass DC IP, domain, anon bind results)
  • SNMP RCE (Net-SNMP Extend) → note in return for orchestrator
  • NFS no_root_squash → note for privesc chaining if shell access exists
  • IPMI hashes (pass hash type and values)
  • Credentials found → list all for orchestrator to record and test
  • New subnets/hosts → list for orchestrator to add as targets

Troubleshooting

  • SNMP timeouts: UDP — firewalls silently drop. Note "SNMP filtered/no response" rather than "no service."
  • DNS zone transfer denied: Expected on most servers. Proceed to reverse DNS sweep and subdomain brute force.
  • NFS mount denied: Exports may restrict by source IP. Note the export list and restrictions — orchestrator may route from a pivot host.
  • SMTP anti-enumeration: Server returns identical responses for valid and invalid users. Note and move on.
  • rpcclient null session denied: Note as blocked. Try authenticated access if credentials exist in state.

© blacklanternsecurity, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/network/infrastructure-enumeration of blacklanternsecurity/red-run.

Open the folder on GitHubat commit 050ac1f

Compare with similar skills

Infrastructure Enumeration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Infrastructure Enumeration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Infrastructure Enumeration this skillblacklanternsecurity/red-run286—~2.4kAutomated safety check: NotesGPL-3.0
Deliverability Incident Responsegrowthenginenowoslawski/coldoutboundskills740—~3.5kAutomated safety check: PassMIT
Traffic Analysis Pcapyaklang/hack-skills2.4k—~2.8kAutomated safety check: NotesMIT
Stripe Projectsfossasia/eventyay1.7k5 repos~2kAutomated safety check: NotesApache-2.0
WooCommerce Email Editor Developmentwoocommerce/woocommerce11k—~893Automated safety check: PassCustom licence
Email Best Practicesviclafouch/meme-studio1107 repos~787Automated safety check: PassNone

Similar skills

  • Deliverability Incident Response

    growthenginenowoslawski/coldoutboundskills

    Triage playbook for when cold email deliverability breaks. An agent skill from growthenginenowoslawski/coldoutboundskills.

    740 GitHub stars~3.5k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Traffic Analysis Pcap

    yaklang/hack-skills

    Traffic analysis and PCAP forensics playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~2.8k tokensUpdated 24 days ago
    SecurityAuto-check: notes
  • Stripe Projects

    fossasia/eventyay

    A skill your agent uses when the user wants to provision infrastructure or third-party services using Stripe Projects.

    1.7k GitHub starsUsed in 5 repos~2k tokens
    Backend & APIsAuto-check: notes
  • Sets up a local environment for the WooCommerce block email editor, with a watcher, Mailpit email capture and build and test commands for its PHP and JS packages.

    11k GitHub stars~893 tokensUpdated today
    Backend & APIsAuto-check passed
  • Email Best Practices

    viclafouch/meme-studio

    A skill your agent uses when building email features, emails going to spam, high bounce rates, setting up SPF/DKIM/DMARC authentication, implementing email capture, ensuring compliance (CAN-SPAM…

    110 GitHub starsUsed in 7 repos~787 tokens
    Backend & APIsAuto-check passed
  • React Email

    viclafouch/meme-studio

    A skill your agent uses when creating HTML email templates with React components - welcome emails, password resets, notifications, order confirmations, newsletters, or transactional emails.

    110 GitHub starsUsed in 2 repos~3.6k tokens
    Backend & APIsAuto-check passed

More from blacklanternsecurity/red-run

  • Source Code Review

    blacklanternsecurity/red-run

    Security-focused source code review. An agent skill from blacklanternsecurity/red-run.

    286 GitHub stars~1.8k tokensUpdated 9 days ago
    Auto-check: notes
  • Kerberos Roasting

    blacklanternsecurity/red-run

    Extracts and cracks Kerberos service tickets (Kerberoasting) and AS-REP hashes (AS-REP Roasting) for offline password recovery.

    286 GitHub stars~3.5k tokensUpdated 9 days ago
    Auto-check: notes
  • Smb Enumeration

    blacklanternsecurity/red-run

    SMB share enumeration, access testing, password policy extraction, and content searching.

    286 GitHub stars~3k tokensUpdated 9 days ago
    Auto-check passed
  • Trust Attacks

    blacklanternsecurity/red-run

    Enumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation.

    286 GitHub stars~4.5k tokensUpdated 9 days ago
    Auto-check: notes
  • Av Edr Evasion

    blacklanternsecurity/red-run

    Bypass antivirus and EDR detection for payload delivery during exploitation.

    286 GitHub stars~5.4k tokensUpdated 9 days ago
    Auto-check: notes

Questions about Infrastructure Enumeration

What does Infrastructure Enumeration do?

Enumeration of infrastructure services: DNS, SMTP, SNMP, IPMI, NFS, TFTP, RPC/MSRPC, and HTTP/HTTPS surface detection. Infrastructure Enumeration is an agent skill from blacklanternsecurity/red-run. Enumeration of infrastructure services: DNS, SMTP, SNMP, IPMI, NFS, TFTP, RPC/MSRPC, and HTTP/HTTPS surface detection.

When should I use Infrastructure Enumeration?

Infrastructure Enumeration fits situations like: tasks that involve Transactional email.

How do I install Infrastructure Enumeration in Claude Code?

Run `npx skills add blacklanternsecurity/red-run --skill infrastructure-enumeration -a claude-code`. Or copy the skill folder (skills/network/infrastructure-enumeration in blacklanternsecurity/red-run) into .claude/skills/infrastructure-enumeration in your project. Claude Code loads it when a task matches its description.

How do I install Infrastructure Enumeration in Codex?

Run `npx skills add blacklanternsecurity/red-run --skill infrastructure-enumeration -a codex`. Or copy the skill folder (skills/network/infrastructure-enumeration in blacklanternsecurity/red-run) into .agents/skills/infrastructure-enumeration in your project. Codex loads it when a task matches its description.

Can I use Infrastructure Enumeration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add blacklanternsecurity/red-run --skill infrastructure-enumeration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/infrastructure-enumeration, .gemini/skills/infrastructure-enumeration, .github/skills/infrastructure-enumeration and .opencode/skills/infrastructure-enumeration in your project.

What does Infrastructure Enumeration need to run?

SKILL.md names no scripts, command-line tools or credentials: Infrastructure Enumeration is instructions for the agent only.

Does Infrastructure Enumeration access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Infrastructure Enumeration safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Infrastructure Enumeration use?

Infrastructure Enumeration is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Infrastructure Enumeration use?

About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Infrastructure Enumeration?

Skills that share tags, products or a category with Infrastructure Enumeration: Deliverability Incident Response (growthenginenowoslawski/coldoutboundskills, 740 stars), Traffic Analysis Pcap (yaklang/hack-skills, 2.4k stars), Stripe Projects (fossasia/eventyay, 1.7k stars) and WooCommerce Email Editor Development (woocommerce/woocommerce, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Infrastructure Enumeration?

blacklanternsecurity (a GitHub organization) maintains it in blacklanternsecurity/red-run, which has 286 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 28, 2026.

Source: blacklanternsecurity/red-run on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.