LAN Network Protection

I've finished up practicing pen-testing my network but I wanted to know how far I should go to protect myself within my own network. For instance, what are the other possible attacks someone could do once they have penetrated network in my home? I know you can nmap for devices and I remember reading an article about wireshark.

Once inside the network I first scan the LAN in order to find any exploitable vulnerability. If I find nothing interesting I can still try MITM+Eavedropping and whatever-spoofing attacks that are pretty effective if communications are unencrypted (ftp, http...) and may allow me to grab random credential (always good to take :P).

