Skip to main content
Exécutez n'importe quel Skill dans Manus
en un clic

ad-kerberos-hunter

Étoiles15
Forks7
Mis à jour28 juin 2026 à 16:46

Tests an authorized Active Directory domain for Kerberos-abuse paths: Kerberoasting (TGS for SPN accounts → offline crack), AS-REP roasting (accounts without pre-auth), and enumeration/proof of unconstrained, constrained (S4U), and resource-based constrained delegation (RBCD) plus shadow-credentials (msDS-KeyCredentialLink) candidates. Consumes ad-recon-hunter's ad-quickwins.md. Use after ad-recon-hunter once internal_pentest is approved and domain credentials are available. Cracking and any impersonation proof are gated. Maps findings to CWE-287/CWE-522/CWE-284 and MITRE T1558. Internal pentest only - requires .claude/security-scope.yaml internal_pentest: approved and credentials from ad_credentials_vault_path. Grounded in redteam-ad-ops.

Installation

Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.

SKILL.md
readonly