> For the complete documentation index, see [llms.txt](https://moharat.gitbook.io/cylabs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://moharat.gitbook.io/cylabs/security-domains/network-security/network-assessment.md).

# Network Assessment

Auditing Network device configuration

Security Assessment:

* Which VPN services used
* What are the historical vulnerabilities
* Which team is responsible for that
* Is multi factor authentication enabled
* Is user ID/Machine ID trackable
* Is certificate based multifactor authentication enforced
* What are gaps observed
* Comments/Notes:

Map the Internal Network

Scan the Network for Live Hosts

Port-scan individual machines

&#x20;

Try to gain access using known vulnerabilities

Attempt to establish null sessions

Enumerate users/identify domains on the network

\[Sniff the network using Wireshark

Sniff POP3/FTP/Telnet Passwords

\[ ] Attempt Replay Attacks

\[ ] Attempt ARP Poisoning

\[ ] Attempt MAC Flooding

\[ ] Conduct Man-In-The-Middle Attacks

\[ ] Attempt DNS Poisoning

\[ ] Try logging in to a console machine

\[ ] Boot the PC Using an Alternate OS and Steal the SAM File

\[ ] Bypass the OS to Obtain Information

\[ ] Attempt to plant a software keylogger to steal passwords.

\[ ] Attempt to plant a hardware keylogger to steal passwords.

\[ ] Attempt to plant spyware on the target machine

\[ ] Attempt to plant a Trojan on the target machine

\[ ] Attempt to bypass antivirus software installed on the target machine

\[ ] Attempt to send a virus using the target machine.

\[ ] Attempt to plant rootkits on the target machine

\[ ] Hide sensitive data on target machine

\[ ] Hide hacking tools and other data on target machines

\[ ] Use various steganography techniques to hide files on target machines.

\[ ] Escalate user privileges

\[ ] Capture POP3 Traffic

\[ ] Capture SMTP Traffic

\[ ] Capture IMAP E-mail traffic

\[ ] Capture the communications between FTP client and FTP Server

\[ ] Capture HTTP Traffic

\[ ] Capture RDP Traffic

\[ ] Capture VoIP Traffic

\[ ] Spoof the MAC Address

\[ ] Attempt Session Hijacking on telnet traffic.

\[ ] Attempt Session Hijacking on FTP

&#x20;traffic.

\[ ] Attempt Session Hijacking on HTTP traffic.

\[ ] Document Everything


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://moharat.gitbook.io/cylabs/security-domains/network-security/network-assessment.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
