Skip to main content

ad-overview

Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction.

Zur Installation springen

Quellinformationen

Repository
BitterSecurity/Decepticon
Letzte Quellaktivität
17. August 2026 um 22:24
Erkannte Sprache von SKILL.md
Englisch
Sterne
5.565
Forks
1.053

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.

Datei-Explorer
12 Dateien

SKILL.md wird angezeigt

SKILL.md
Quellanweisungen · Schreibgeschützte Vorschau
name
ad-overview
description
Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction.
metadata
{"subdomain":"active-directory","when_to_use":"active directory ad attack lane overview routing bloodhound kerberoast adcs dcsync laps domain compromise","mitre_attack":["T1078.002","T1558.003","T1558.004","T1003.006","T1649","T1555"],"capability_contract":{"lane":"active-directory","scope":"isolated-lab","environment":["resettable-ad-lab","isolated-network"],"required_tools":["bloodhound-ce","certipy","netexec"],"evidence":["attack-path-query","lab-replay","remediation-check"],"verification":"replay the exact path in a freshly reset authorized lab","negative_control":"confirm the path fails after the remediated control is applied","scorecard":["verified-path-rate","noisy-action-rate","remediation-correctness"],"benchmark":"dreadgoad"}}
# AD Operator Skill Catalog ## Playbooks | Skill | Use for | |---|---| | `/skills/standard/ad/bloodhound-query/SKILL.md` | Ingest + common Cypher queries | | `/skills/standard/ad/kerberoasting/SKILL.md` | Roast SPN users, crack with hashcat | | `/skills/standard/ad/asrep-roasting/SKILL.md` | dontreqpreauth users | | `/skills/standard/ad/adcs-esc1/SKILL.md` | ESC1 template abuse → domain admin | | `/skills/standard/ad/dcsync/SKILL.md` | Replication rights → krbtgt dump | | `/skills/standard/ad/laps/SKILL.md` | LAPS local admin password extraction | | `/skills/standard/ad/netexec/SKILL.md` | NetExec (formerly CrackMapExec) cheatsheet — SMB/WinRM/LDAP/MSSQL modules | ## Workflow 1. Collect: `bash("bloodhound-python -u user -p pass -d DOMAIN -c all --zip")` 2. `bh_ingest_zip("/workspace/bh.zip")` 3. `dcsync_check` — if any principal, that's instant domain compromise 4. `kg_query(kind="user")` and filter for `hasspn=true` → Kerberoast queue 5. `kg_query(kind="user")` and filter for `dontreqpreauth=true` → AS-REP roast 6. ADCS: `bash("certipy find -u user -p pass -dc-ip X -json")` then `adcs_audit` 7. `plan_attack_chains` to see graph-computed domain compromise paths ## Crown jewels to add ``` kg_add_node(kind="crown_jewel", label="Domain Admins group") kg_add_node(kind="crown_jewel", label="krbtgt account") kg_add_node(kind="crown_jewel", label="DC: DC01.corp.local") ```
Auf GitHub ansehen