{"enrichment":{"faq":[{"a":"active-directory-attacks covers offensive techniques for compromising AD environments through reconnaissance, credential extraction, and exploitation. The skill teaches BloodHound enumeration, Kerberoasting, AS-REP roasting, pass-the-hash attacks, DCSync exploitation, NTLM relay, and lateral movement tactics. You'll learn to leverage Kerberos vulnerabilities, forge tickets, and exploit AD Certificate Services weaknesses to achieve domain compromise during authorized penetration tests.","q":"How to attack active directory in red team operations?"},{"a":"active-directory-attacks covers multiple Kerberos-based attacks: Kerberoasting extracts service account credentials; AS-REP roasting targets users without pre-authentication; Golden Tickets forge domain admin credentials; Silver Tickets create forged service tickets; and Rubeus automates these attacks. The skill teaches ticket generation, manipulation, and replay techniques for lateral movement and privilege escalation within Windows domains.","q":"What Kerberos attack methods does active-directory-attacks include?"},{"a":"active-directory-attacks details DCSync attacks that impersonate domain controllers to extract password hashes directly from AD, and NTLM relay techniques that intercept and forward authentication requests to compromise systems. Both methods enable credential harvesting and lateral movement. The skill covers exploitation prerequisites, detection evasion, and practical implementation using tools like Mimikatz and Responder for domain controller compromise.","q":"How does active-directory-attacks explain DCSync and NTLM relay?"},{"a":"active-directory-attacks teaches credential extraction via Kerberoasting, AS-REP roasting, pass-the-hash attacks, and Mimikatz-based harvesting. It includes LLMNR poisoning with Responder, DCSync exploitation, and NTLM relay interception. The skill demonstrates how to capture, extract, and reuse credentials for lateral movement and privilege escalation across Windows domain environments during authorized red team operations.","q":"What credential harvesting techniques are covered?"},{"a":"active-directory-attacks teaches enumeration and exploitation pathways to domain administrator access through credential extraction, ticket forgery, and lateral movement. Techniques include Kerberoasting service accounts, exploiting AD Certificate Services, DCSync attacks, and pass-the-hash methods. The skill emphasizes reconnaissance with BloodHound to identify privilege escalation paths and vulnerable accounts for authorized penetration testing scenarios.","q":"Can active-directory-attacks help with domain administrator access?"},{"a":"active-directory-attacks covers tools including BloodHound for enumeration, Mimikatz for credential extraction, Rubeus for Kerberos attacks, CrackMapExec for domain exploitation, and Responder for LLMNR poisoning. It addresses critical vulnerabilities like Zerologon (CVE-2020-1472) and AD Certificate Services exploits. The skill provides practical guidance on leveraging these tools and CVEs for authorized red team operations against Windows domains.","q":"What tools and CVEs does active-directory-attacks reference?"}],"shadow_tags":["red-team-ops","windows-domain-security","credential-theft","kerberos-exploitation","lateral-movement","privilege-escalation","network-penetration","hash-cracking","ticket-forging","cve-exploitation"],"summary_rewrite":"This skill covers offensive techniques for compromising Active Directory environments, including reconnaissance with BloodHound, credential extraction via Kerberoasting and AS-REP roasting, ticket forgery, and lateral movement. Learn pass-the-hash, DCSync, NTLM relay, and exploitation of AD Certificate Services vulnerabilities alongside critical CVE tactics."},"files":[{"bytes":9504,"path":"skills/active-directory-attacks/SKILL.md","sha256":"a086e99cb5f9a45f9499a465800189739acd65c555559960af52cdd2c3fcc61e","url":"https://skillfed.io/files/zebbern/claude-code-guide/active-directory-attacks/f1b25e68/SKILL.md"}],"id":"zebbern/claude-code-guide/active-directory-attacks","links":{"html":"https://skillfed.io/zebbern/claude-code-guide/active-directory-attacks","md":"https://skillfed.io/zebbern/claude-code-guide/active-directory-attacks.md","repo":"https://github.com/zebbern/claude-code-guide"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":447,"language":"Python","last_updated":"2026-07-26","license":"MIT","name":"active-directory-attacks","publisher":"zebbern","stars":4440},"relations":{"similar":[{"id":"yaklang/hack-skills/active-directory-kerberos-attacks"},{"id":"zebbern/claude-code-guide/privilege-escalation-methods"},{"id":"hypnguyen1209/offensive-claude/active-directory-attack"},{"id":"blacklanternsecurity/red-run/acl-abuse"},{"id":"yaklang/hack-skills/active-directory-acl-abuse"},{"id":"blacklanternsecurity/red-run/kerberos-ticket-forging"},{"id":"blacklanternsecurity/red-run/adcs-access-and-relay"},{"id":"blacklanternsecurity/red-run/trust-attacks"},{"id":"blacklanternsecurity/red-run/kerberos-roasting"},{"id":"blacklanternsecurity/red-run/pass-the-hash"}]},"slug":{"owner":"zebbern","repo":"claude-code-guide","skill":"active-directory-attacks"},"version":"f1b25e68"}
