Skip to main content

Skills dans ce dépôt

abelrguezr/hacktricks-skills - Page 21

SkillsMP a collecté 908 skills depuis abelrguezr/hacktricks-skills. Ouvrez un skill pour examiner sa source et ses détails.

abelrguezr/hacktricks-skills

Affichage de 40 skills collectés sur 908.

métier
Analystes en sécurité de l'information
description

Detect and analyze steganographic payloads in files, especially malware hiding data in images, metadata, and trailing bytes. Use this skill whenever the user needs to investigate suspicious files, analyze potential steganography, hunt for hidden payloads, or…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Steganography analysis and hidden data extraction. Use this skill whenever the user needs to find or extract hidden data from files (images, audio, video, documents, archives) or text-based steganography. Trigger on requests involving: hidden messages,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Detect and decode hidden data in text using Unicode steganography techniques. Use this skill whenever you need to analyze suspicious text files, CTF challenges with hidden messages, or any text that might contain covert data through homoglyphs, zero-width…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Steganography analysis workflow for CTF challenges and security investigations. Use this skill whenever the user mentions steganography, hidden data, stego files, image analysis, audio forensics, file carving, or needs to find hidden payloads in files.…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to enumerate and abuse Microsoft SQL Server in Active Directory environments. Use this skill whenever the user mentions MSSQL, SQL Server, database enumeration, trusted links, SQL injection, xp_cmdshell, or wants to perform MSSQL-based attacks in AD…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Active Directory ACL/ACE abuse techniques for privilege escalation. Use this skill whenever the user needs to enumerate or exploit misconfigured Active Directory permissions, including GenericAll, GenericWrite, WriteProperty, WriteOwner, ForceChangePassword,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Guide for testing the BadSuccessor vulnerability in Active Directory Delegated Managed Service Accounts (dMSAs). Use this skill when assessing Windows Server 2025 environments for dMSA privilege escalation risks, when you need to understand the…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to abuse Active Directory Key Trust and msDS-KeyCredentialLink to extract NT hashes and create silver tickets. Use this skill whenever the user mentions Active Directory attacks, msDS-KeyCredentialLink, Key Trust abuse, NT hash extraction, TGT…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Use this skill whenever you need to enumerate, attack, or escalate privileges in an Active Directory environment. Trigger on any AD-related tasks including reconnaissance, credential attacks, Kerberos abuse, trust exploitation, privilege escalation, or…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Active Directory Certificate Services (AD CS) persistence techniques for security assessments. Use this skill whenever analyzing AD CS configurations, planning certificate-based persistence, understanding PKINIT attacks, working with certificate templates in…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Active Directory Certificate Services (AD CS) enumeration and vulnerability assessment. Use this skill whenever the user mentions AD certificates, PKI, certificate templates, AD CS, certificate authorities, or wants to enumerate/assess certificate…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to steal and abuse Active Directory Certificate Services (AD CS) certificates. Use this skill whenever you need to extract, decrypt, or abuse certificates in a Windows/AD environment, including user certificates, machine certificates, certificate files,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Active Directory Certificate Services (AD CS) domain escalation techniques. Use this skill whenever the user mentions AD CS, certificate templates, ESC vulnerabilities, PKI misconfigurations, certificate-based authentication attacks, or wants to…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Active Directory Certificate Services (AD CS) domain persistence techniques for authorized security testing. Use this skill whenever the user needs to maintain long-term access to a compromised Active Directory environment through certificate-based methods.…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Active Directory Certificate Services (AD CS) security assessment and hardening. Use this skill whenever the user mentions AD certificates, certificate authorities, PKI, ESC vulnerabilities, certificate enumeration, or needs to assess/harden AD CS…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Active Directory DNS enumeration, manipulation, and hardening. Use this skill whenever the user mentions AD DNS, DNS records, zone transfers, adidnsdump, DNS spoofing, WPAD, dynamic DNS updates, or any Active Directory DNS-related reconnaissance or security…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Use this skill whenever you need to perform Active Directory operations that require stealth, anti-forensics, or evidence elimination. Trigger this for any AD assessment involving computer account creation, group membership manipulation, GPO modifications,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to harvest Active Directory credentials from printers configured with LDAP authentication. Use this skill whenever you're doing AD penetration testing, security assessments, or need to test printer security. Trigger this when the user mentions printers,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Active Directory Web Services (ADWS) enumeration and stealth collection over TCP 9389. Use this skill whenever the user needs to enumerate Active Directory, collect domain objects, perform LDAP-style queries, or gather BloodHound data in a stealthy manner.…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to perform AS-REP Roasting attacks against Active Directory users without Kerberos pre-authentication. Use this skill whenever the user mentions AS-REP, ASREPRoast, Kerberos pre-authentication, AD security testing, or wants to enumerate/crack users…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Active Directory security assessment skill for the BadSuccessor privilege escalation technique. Use this skill when users are conducting authorized AD penetration testing, security assessments, or want to understand the dMSA migration abuse vulnerability.…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Active Directory enumeration and visualization using BloodHound, ADRecon, and related tools. Use this skill whenever the user needs to map AD relationships, find privilege escalation paths, enumerate GPOs, or visualize attack paths in Windows domains. Trigger…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to enumerate and exploit Kerberos Constrained Delegation in Active Directory for privilege escalation. Use this skill whenever the user mentions constrained delegation, S4U2self, S4U2proxy, msDS-AllowedToDelegateTo, TrustedToAuthForDelegation, Kerberos…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to capture Windows credentials in clear text using a custom Security Support Provider (SSP) with Mimikatz. Use this skill whenever you need to extract credentials from a Windows system during authorized penetration testing, red teaming, or security…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Execute DCShadow attacks in Active Directory to push attribute changes without logging. Use this skill whenever the user mentions DCShadow, rogue domain controllers, AD attribute modification, primaryGroupID manipulation, SIDHistory backdoors, mimikatz…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Active Directory DCSync attack methodology for security assessments. Use this skill when testing AD environments for DCSync vulnerabilities, analyzing replication permissions, or documenting DCSync attack paths. Trigger when users mention DCSync, AD…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Security research skill for understanding Diamond Ticket Kerberos attacks. Use this skill whenever the user asks about Kerberos ticket manipulation, diamond tickets, golden tickets, sapphire tickets, TGT forgery, PAC modification, Rubeus diamond commands,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to access and leverage Directory Services Restore Mode (DSRM) credentials on Active Directory Domain Controllers. Use this skill whenever the user mentions DSRM, domain controller local administrator access, Active Directory credential extraction, DC…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Active Directory external forest trust enumeration and testing. Use this skill when analyzing outbound trust relationships between domains, investigating trust account vulnerabilities, or performing authorized security assessments of AD trust configurations.…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Active Directory external forest trust exploitation methodology. Use this skill whenever the user mentions forest trusts, cross-domain access, AD trust enumeration, SID history abuse, RBCD across forests, inter-realm TGT/TGS, or any scenario involving…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Execute Golden gMSA/dMSA attacks to derive managed service account passwords offline. Use this skill whenever the user mentions gMSA, dMSA, managed service accounts, KDS root key extraction, or wants to compute service account passwords from Active Directory.…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to create and use Golden Ticket attacks in Active Directory environments. Use this skill whenever the user mentions Golden Tickets, TGT forgery, krbtgt hash, Kerberos ticket attacks, or needs to understand how to forge TGTs for authorized penetration…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Kerberoasting attack methodology for Active Directory penetration testing. Use this skill whenever the user mentions kerberoasting, TGS ticket extraction, SPN enumeration, service account attacks, or wants to extract and crack Kerberos service tickets from…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Kerberos authentication analysis and attack methodology for Active Directory environments. Use this skill whenever the user mentions Kerberos, AD authentication, ticket-based auth, Kerberoasting, AS-REP roasting, delegation abuse, golden tickets, or any…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to understand and work around the Kerberos double hop authentication problem in Windows environments. Use this skill whenever you need to authenticate across multiple hops in Active Directory, troubleshoot Kerberos authentication failures between servers,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Security assessment skill for Lansweeper IT asset management platforms. Use this skill whenever the user needs to assess Lansweeper deployments, harvest scanning credentials, decrypt stored secrets, abuse AD ACLs related to Lansweeper groups, or execute…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Use this skill whenever you need to enumerate, read, or exploit LAPS (Local Administrator Password Solution) in Active Directory environments. Trigger when the user mentions LAPS, local admin passwords, AD computer objects, ms-mcs-AdmPwd, LAPS password…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to harden Active Directory against LDAP relay attacks using LDAP signing and channel binding. Use this skill whenever the user mentions LDAP security, AD hardening, LDAP signing, channel binding, LDAP relay prevention, Active Directory security, or wants…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Execute Overpass The Hash/Pass The Key (PTK) attacks in Active Directory environments where NTLM is restricted and Kerberos authentication is required. Use this skill whenever the user mentions Kerberos attacks, NTLM hashes, TGT tickets, pass-the-hash…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to execute Pass the Ticket (PTT) attacks in Active Directory environments. Use this skill whenever the user mentions Kerberos tickets, authentication bypass, ticket theft, PTT attacks, or needs to impersonate users using stolen tickets. Also trigger for…

Langue du texte source : anglais

mis à jour
Affichage de 40 skills collectés sur 908.