Skip to main content

ad-overview

Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction.

Jump to install

Source facts

Repository
BitterSecurity/Decepticon
Last source activity
August 17, 2026 at 22:24
Detected SKILL.md language
English
Stars
5,522
Forks
1,048

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.

File Explorer
12 files

Showing SKILL.md

SKILL.md
Source instructions · Read-only preview
name
ad-overview
description
Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction.
metadata
{"subdomain":"active-directory","when_to_use":"active directory ad attack lane overview routing bloodhound kerberoast adcs dcsync laps domain compromise","mitre_attack":["T1078.002","T1558.003","T1558.004","T1003.006","T1649","T1555"],"capability_contract":{"lane":"active-directory","scope":"isolated-lab","environment":["resettable-ad-lab","isolated-network"],"required_tools":["bloodhound-ce","certipy","netexec"],"evidence":["attack-path-query","lab-replay","remediation-check"],"verification":"replay the exact path in a freshly reset authorized lab","negative_control":"confirm the path fails after the remediated control is applied","scorecard":["verified-path-rate","noisy-action-rate","remediation-correctness"],"benchmark":"dreadgoad"}}
# AD Operator Skill Catalog ## Playbooks | Skill | Use for | |---|---| | `/skills/standard/ad/bloodhound-query/SKILL.md` | Ingest + common Cypher queries | | `/skills/standard/ad/kerberoasting/SKILL.md` | Roast SPN users, crack with hashcat | | `/skills/standard/ad/asrep-roasting/SKILL.md` | dontreqpreauth users | | `/skills/standard/ad/adcs-esc1/SKILL.md` | ESC1 template abuse → domain admin | | `/skills/standard/ad/dcsync/SKILL.md` | Replication rights → krbtgt dump | | `/skills/standard/ad/laps/SKILL.md` | LAPS local admin password extraction | | `/skills/standard/ad/netexec/SKILL.md` | NetExec (formerly CrackMapExec) cheatsheet — SMB/WinRM/LDAP/MSSQL modules | ## Workflow 1. Collect: `bash("bloodhound-python -u user -p pass -d DOMAIN -c all --zip")` 2. `bh_ingest_zip("/workspace/bh.zip")` 3. `dcsync_check` — if any principal, that's instant domain compromise 4. `kg_query(kind="user")` and filter for `hasspn=true` → Kerberoast queue 5. `kg_query(kind="user")` and filter for `dontreqpreauth=true` → AS-REP roast 6. ADCS: `bash("certipy find -u user -p pass -dc-ip X -json")` then `adcs_audit` 7. `plan_attack_chains` to see graph-computed domain compromise paths ## Crown jewels to add ``` kg_add_node(kind="crown_jewel", label="Domain Admins group") kg_add_node(kind="crown_jewel", label="krbtgt account") kg_add_node(kind="crown_jewel", label="DC: DC01.corp.local") ```
View on GitHub