Skip to main content

Skills neste repositório

abelrguezr/hacktricks-skills - Página 21

O SkillsMP coletou 908 skills de abelrguezr/hacktricks-skills. Abra uma skill para revisar a origem e os detalhes.

abelrguezr/hacktricks-skills

Mostrando 40 de 908 skills coletadas.

ocupação
Analistas de segurança da informação
descrição

Detect and analyze steganographic payloads in files, especially malware hiding data in images, metadata, and trailing bytes. Use this skill whenever the user needs to investigate suspicious files, analyze potential steganography, hunt for hidden payloads, or…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Steganography analysis and hidden data extraction. Use this skill whenever the user needs to find or extract hidden data from files (images, audio, video, documents, archives) or text-based steganography. Trigger on requests involving: hidden messages,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect and decode hidden data in text using Unicode steganography techniques. Use this skill whenever you need to analyze suspicious text files, CTF challenges with hidden messages, or any text that might contain covert data through homoglyphs, zero-width…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Steganography analysis workflow for CTF challenges and security investigations. Use this skill whenever the user mentions steganography, hidden data, stego files, image analysis, audio forensics, file carving, or needs to find hidden payloads in files.…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to enumerate and abuse Microsoft SQL Server in Active Directory environments. Use this skill whenever the user mentions MSSQL, SQL Server, database enumeration, trusted links, SQL injection, xp_cmdshell, or wants to perform MSSQL-based attacks in AD…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Active Directory ACL/ACE abuse techniques for privilege escalation. Use this skill whenever the user needs to enumerate or exploit misconfigured Active Directory permissions, including GenericAll, GenericWrite, WriteProperty, WriteOwner, ForceChangePassword,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Guide for testing the BadSuccessor vulnerability in Active Directory Delegated Managed Service Accounts (dMSAs). Use this skill when assessing Windows Server 2025 environments for dMSA privilege escalation risks, when you need to understand the…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to abuse Active Directory Key Trust and msDS-KeyCredentialLink to extract NT hashes and create silver tickets. Use this skill whenever the user mentions Active Directory attacks, msDS-KeyCredentialLink, Key Trust abuse, NT hash extraction, TGT…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use this skill whenever you need to enumerate, attack, or escalate privileges in an Active Directory environment. Trigger on any AD-related tasks including reconnaissance, credential attacks, Kerberos abuse, trust exploitation, privilege escalation, or…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Active Directory Certificate Services (AD CS) persistence techniques for security assessments. Use this skill whenever analyzing AD CS configurations, planning certificate-based persistence, understanding PKINIT attacks, working with certificate templates in…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Active Directory Certificate Services (AD CS) enumeration and vulnerability assessment. Use this skill whenever the user mentions AD certificates, PKI, certificate templates, AD CS, certificate authorities, or wants to enumerate/assess certificate…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to steal and abuse Active Directory Certificate Services (AD CS) certificates. Use this skill whenever you need to extract, decrypt, or abuse certificates in a Windows/AD environment, including user certificates, machine certificates, certificate files,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Active Directory Certificate Services (AD CS) domain escalation techniques. Use this skill whenever the user mentions AD CS, certificate templates, ESC vulnerabilities, PKI misconfigurations, certificate-based authentication attacks, or wants to…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Active Directory Certificate Services (AD CS) domain persistence techniques for authorized security testing. Use this skill whenever the user needs to maintain long-term access to a compromised Active Directory environment through certificate-based methods.…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Active Directory Certificate Services (AD CS) security assessment and hardening. Use this skill whenever the user mentions AD certificates, certificate authorities, PKI, ESC vulnerabilities, certificate enumeration, or needs to assess/harden AD CS…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Active Directory DNS enumeration, manipulation, and hardening. Use this skill whenever the user mentions AD DNS, DNS records, zone transfers, adidnsdump, DNS spoofing, WPAD, dynamic DNS updates, or any Active Directory DNS-related reconnaissance or security…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use this skill whenever you need to perform Active Directory operations that require stealth, anti-forensics, or evidence elimination. Trigger this for any AD assessment involving computer account creation, group membership manipulation, GPO modifications,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to harvest Active Directory credentials from printers configured with LDAP authentication. Use this skill whenever you're doing AD penetration testing, security assessments, or need to test printer security. Trigger this when the user mentions printers,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Active Directory Web Services (ADWS) enumeration and stealth collection over TCP 9389. Use this skill whenever the user needs to enumerate Active Directory, collect domain objects, perform LDAP-style queries, or gather BloodHound data in a stealthy manner.…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to perform AS-REP Roasting attacks against Active Directory users without Kerberos pre-authentication. Use this skill whenever the user mentions AS-REP, ASREPRoast, Kerberos pre-authentication, AD security testing, or wants to enumerate/crack users…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Active Directory security assessment skill for the BadSuccessor privilege escalation technique. Use this skill when users are conducting authorized AD penetration testing, security assessments, or want to understand the dMSA migration abuse vulnerability.…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Active Directory enumeration and visualization using BloodHound, ADRecon, and related tools. Use this skill whenever the user needs to map AD relationships, find privilege escalation paths, enumerate GPOs, or visualize attack paths in Windows domains. Trigger…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to enumerate and exploit Kerberos Constrained Delegation in Active Directory for privilege escalation. Use this skill whenever the user mentions constrained delegation, S4U2self, S4U2proxy, msDS-AllowedToDelegateTo, TrustedToAuthForDelegation, Kerberos…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to capture Windows credentials in clear text using a custom Security Support Provider (SSP) with Mimikatz. Use this skill whenever you need to extract credentials from a Windows system during authorized penetration testing, red teaming, or security…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Execute DCShadow attacks in Active Directory to push attribute changes without logging. Use this skill whenever the user mentions DCShadow, rogue domain controllers, AD attribute modification, primaryGroupID manipulation, SIDHistory backdoors, mimikatz…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Active Directory DCSync attack methodology for security assessments. Use this skill when testing AD environments for DCSync vulnerabilities, analyzing replication permissions, or documenting DCSync attack paths. Trigger when users mention DCSync, AD…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Security research skill for understanding Diamond Ticket Kerberos attacks. Use this skill whenever the user asks about Kerberos ticket manipulation, diamond tickets, golden tickets, sapphire tickets, TGT forgery, PAC modification, Rubeus diamond commands,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to access and leverage Directory Services Restore Mode (DSRM) credentials on Active Directory Domain Controllers. Use this skill whenever the user mentions DSRM, domain controller local administrator access, Active Directory credential extraction, DC…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Active Directory external forest trust enumeration and testing. Use this skill when analyzing outbound trust relationships between domains, investigating trust account vulnerabilities, or performing authorized security assessments of AD trust configurations.…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Active Directory external forest trust exploitation methodology. Use this skill whenever the user mentions forest trusts, cross-domain access, AD trust enumeration, SID history abuse, RBCD across forests, inter-realm TGT/TGS, or any scenario involving…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Execute Golden gMSA/dMSA attacks to derive managed service account passwords offline. Use this skill whenever the user mentions gMSA, dMSA, managed service accounts, KDS root key extraction, or wants to compute service account passwords from Active Directory.…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to create and use Golden Ticket attacks in Active Directory environments. Use this skill whenever the user mentions Golden Tickets, TGT forgery, krbtgt hash, Kerberos ticket attacks, or needs to understand how to forge TGTs for authorized penetration…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Kerberoasting attack methodology for Active Directory penetration testing. Use this skill whenever the user mentions kerberoasting, TGS ticket extraction, SPN enumeration, service account attacks, or wants to extract and crack Kerberos service tickets from…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Kerberos authentication analysis and attack methodology for Active Directory environments. Use this skill whenever the user mentions Kerberos, AD authentication, ticket-based auth, Kerberoasting, AS-REP roasting, delegation abuse, golden tickets, or any…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to understand and work around the Kerberos double hop authentication problem in Windows environments. Use this skill whenever you need to authenticate across multiple hops in Active Directory, troubleshoot Kerberos authentication failures between servers,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Security assessment skill for Lansweeper IT asset management platforms. Use this skill whenever the user needs to assess Lansweeper deployments, harvest scanning credentials, decrypt stored secrets, abuse AD ACLs related to Lansweeper groups, or execute…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use this skill whenever you need to enumerate, read, or exploit LAPS (Local Administrator Password Solution) in Active Directory environments. Trigger when the user mentions LAPS, local admin passwords, AD computer objects, ms-mcs-AdmPwd, LAPS password…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to harden Active Directory against LDAP relay attacks using LDAP signing and channel binding. Use this skill whenever the user mentions LDAP security, AD hardening, LDAP signing, channel binding, LDAP relay prevention, Active Directory security, or wants…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Execute Overpass The Hash/Pass The Key (PTK) attacks in Active Directory environments where NTLM is restricted and Kerberos authentication is required. Use this skill whenever the user mentions Kerberos attacks, NTLM hashes, TGT tickets, pass-the-hash…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to execute Pass the Ticket (PTT) attacks in Active Directory environments. Use this skill whenever the user mentions Kerberos tickets, authentication bypass, ticket theft, PTT attacks, or needs to impersonate users using stolen tickets. Also trigger for…

Idioma do texto original: inglês

atualizado
Mostrando 40 de 908 skills coletadas.