{"enrichment":{"faq":[{"a":"active-directory-attack is an MIT-licensed toolkit for post-compromise Active Directory exploitation. It orchestrates domain attacks through Kerberos roasting, delegation abuse, NTLM relay chains, ADCS certificate template abuse, ticket forgery, DCSync credential dumping, and BloodHound-guided lateral movement discovery. The skill integrates OPSEC and detection guidance across all attack vectors.","q":"What is active-directory-attack and what does it cover?"},{"a":"active-directory-attack covers both AS-REP roasting (targeting accounts with no preauth enabled) and standard Kerberos roasting (extracting and cracking service principal names). It includes SPN enumeration techniques, ticket extraction workflows, and hash cracking strategies to compromise service accounts and escalate domain privileges.","q":"How does active-directory-attack enable Kerberos roasting attacks?"},{"a":"Yes. active-directory-attack addresses ADCS certificate template abuse including ESC1 and other ESC variants. It covers identifying vulnerable templates, requesting certificates with elevated privileges, and leveraging certificate persistence to achieve domain admin access through the certificate chain.","q":"Can active-directory-attack help with ADCS ESC1 certificate template abuse?"},{"a":"active-directory-attack covers NTLM relay coercion exploit chains, including PetitPotam and other coercion methods paired with relay attacks. It addresses SMB signing bypass scenarios, LDAP relay techniques, and integration of coercion with Kerberos/NTLM reflection for domain escalation and lateral movement.","q":"What coercion and relay techniques does active-directory-attack include?"},{"a":"active-directory-attack integrates BloodHound for domain enumeration and attack path discovery. It helps identify lateral movement routes, privilege escalation chains, and high-value targets within the domain graph, enabling operators to chain multiple exploitation techniques for efficient domain takeover.","q":"How does active-directory-attack use BloodHound for lateral movement?"},{"a":"active-directory-attack covers constrained delegation S4U2 abuse, resource-based constrained delegation (RBCD) takeover, and dMSA BadSuccessor privilege escalation. It includes techniques for identifying misconfigured delegation settings and chaining them with ticket forgery for domain admin compromise.","q":"What delegation abuse attacks are covered by active-directory-attack?"}],"shadow_tags":["kerberos-exploitation","certificate-abuse","relay-attacks","domain-persistence","credential-theft","privilege-escalation-ad","enumeration-mapping","windows-exploitation","post-compromise-ops"],"summary_rewrite":"Orchestrate post-compromise domain exploitation through Kerberos attacks, coercion-relay chains, certificate template abuse, and BloodHound-guided lateral movement. Covers roasting, delegation abuse, NTLM reflection, ADCS ESC variants, ticket forgery, DCSync, and dMSA BadSuccessor attacks with integrated OPSEC and detection guidance."},"files":[{"bytes":9089,"path":"skills/active-directory-attack/SKILL.md","sha256":"4e50cc891aa9edfcf620484edb57c3b1771221e53fb68f75acb42ce0b8507128","url":"https://skillfed.io/files/hypnguyen1209/offensive-claude/active-directory-attack/85182d83/SKILL.md"}],"id":"hypnguyen1209/offensive-claude/active-directory-attack","links":{"html":"https://skillfed.io/hypnguyen1209/offensive-claude/active-directory-attack","md":"https://skillfed.io/hypnguyen1209/offensive-claude/active-directory-attack.md","repo":"https://github.com/hypnguyen1209/offensive-claude"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":58,"language":"Python","last_updated":"2026-07-03","license":"MIT","name":"active-directory-attack","publisher":"hypnguyen1209","stars":326},"relations":{"similar":[{"id":"blacklanternsecurity/red-run/ad-discovery"},{"id":"zebbern/claude-code-guide/active-directory-attacks"},{"id":"blacklanternsecurity/red-run/credential-dumping"},{"id":"blacklanternsecurity/red-run/auth-coercion-relay"},{"id":"blacklanternsecurity/red-run/adcs-access-and-relay"},{"id":"yaklang/hack-skills/active-directory-kerberos-attacks"},{"id":"Unclecheng-li/VulnClaw/intranet-pentest-advanced"},{"id":"yaklang/hack-skills/ntlm-relay-coercion"},{"id":"yaklang/hack-skills/active-directory-certificate-services"},{"id":"blacklanternsecurity/red-run/trust-attacks"}]},"slug":{"owner":"hypnguyen1209","repo":"offensive-claude","skill":"active-directory-attack"},"version":"85182d83"}
