Skip to main content

这个仓库中的 skills

abelrguezr/hacktricks-skills - 第 21 页

SkillsMP 已收集 abelrguezr/hacktricks-skills 中的 908 个 Skill。打开任一 Skill 可查看来源和详情。

abelrguezr/hacktricks-skills

已展示 40 / 908 个已收集 Skill。

职业分类
信息安全分析师
描述

Detect and analyze steganographic payloads in files, especially malware hiding data in images, metadata, and trailing bytes. Use this skill whenever the user needs to investigate suspicious files, analyze potential steganography, hunt for hidden payloads, or…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Steganography analysis and hidden data extraction. Use this skill whenever the user needs to find or extract hidden data from files (images, audio, video, documents, archives) or text-based steganography. Trigger on requests involving: hidden messages,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Detect and decode hidden data in text using Unicode steganography techniques. Use this skill whenever you need to analyze suspicious text files, CTF challenges with hidden messages, or any text that might contain covert data through homoglyphs, zero-width…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Steganography analysis workflow for CTF challenges and security investigations. Use this skill whenever the user mentions steganography, hidden data, stego files, image analysis, audio forensics, file carving, or needs to find hidden payloads in files.…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to enumerate and abuse Microsoft SQL Server in Active Directory environments. Use this skill whenever the user mentions MSSQL, SQL Server, database enumeration, trusted links, SQL injection, xp_cmdshell, or wants to perform MSSQL-based attacks in AD…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Active Directory ACL/ACE abuse techniques for privilege escalation. Use this skill whenever the user needs to enumerate or exploit misconfigured Active Directory permissions, including GenericAll, GenericWrite, WriteProperty, WriteOwner, ForceChangePassword,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Guide for testing the BadSuccessor vulnerability in Active Directory Delegated Managed Service Accounts (dMSAs). Use this skill when assessing Windows Server 2025 environments for dMSA privilege escalation risks, when you need to understand the…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to abuse Active Directory Key Trust and msDS-KeyCredentialLink to extract NT hashes and create silver tickets. Use this skill whenever the user mentions Active Directory attacks, msDS-KeyCredentialLink, Key Trust abuse, NT hash extraction, TGT…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use this skill whenever you need to enumerate, attack, or escalate privileges in an Active Directory environment. Trigger on any AD-related tasks including reconnaissance, credential attacks, Kerberos abuse, trust exploitation, privilege escalation, or…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Active Directory Certificate Services (AD CS) persistence techniques for security assessments. Use this skill whenever analyzing AD CS configurations, planning certificate-based persistence, understanding PKINIT attacks, working with certificate templates in…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Active Directory Certificate Services (AD CS) enumeration and vulnerability assessment. Use this skill whenever the user mentions AD certificates, PKI, certificate templates, AD CS, certificate authorities, or wants to enumerate/assess certificate…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to steal and abuse Active Directory Certificate Services (AD CS) certificates. Use this skill whenever you need to extract, decrypt, or abuse certificates in a Windows/AD environment, including user certificates, machine certificates, certificate files,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Active Directory Certificate Services (AD CS) domain escalation techniques. Use this skill whenever the user mentions AD CS, certificate templates, ESC vulnerabilities, PKI misconfigurations, certificate-based authentication attacks, or wants to…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Active Directory Certificate Services (AD CS) domain persistence techniques for authorized security testing. Use this skill whenever the user needs to maintain long-term access to a compromised Active Directory environment through certificate-based methods.…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Active Directory Certificate Services (AD CS) security assessment and hardening. Use this skill whenever the user mentions AD certificates, certificate authorities, PKI, ESC vulnerabilities, certificate enumeration, or needs to assess/harden AD CS…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Active Directory DNS enumeration, manipulation, and hardening. Use this skill whenever the user mentions AD DNS, DNS records, zone transfers, adidnsdump, DNS spoofing, WPAD, dynamic DNS updates, or any Active Directory DNS-related reconnaissance or security…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use this skill whenever you need to perform Active Directory operations that require stealth, anti-forensics, or evidence elimination. Trigger this for any AD assessment involving computer account creation, group membership manipulation, GPO modifications,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to harvest Active Directory credentials from printers configured with LDAP authentication. Use this skill whenever you're doing AD penetration testing, security assessments, or need to test printer security. Trigger this when the user mentions printers,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Active Directory Web Services (ADWS) enumeration and stealth collection over TCP 9389. Use this skill whenever the user needs to enumerate Active Directory, collect domain objects, perform LDAP-style queries, or gather BloodHound data in a stealthy manner.…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to perform AS-REP Roasting attacks against Active Directory users without Kerberos pre-authentication. Use this skill whenever the user mentions AS-REP, ASREPRoast, Kerberos pre-authentication, AD security testing, or wants to enumerate/crack users…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Active Directory security assessment skill for the BadSuccessor privilege escalation technique. Use this skill when users are conducting authorized AD penetration testing, security assessments, or want to understand the dMSA migration abuse vulnerability.…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Active Directory enumeration and visualization using BloodHound, ADRecon, and related tools. Use this skill whenever the user needs to map AD relationships, find privilege escalation paths, enumerate GPOs, or visualize attack paths in Windows domains. Trigger…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to enumerate and exploit Kerberos Constrained Delegation in Active Directory for privilege escalation. Use this skill whenever the user mentions constrained delegation, S4U2self, S4U2proxy, msDS-AllowedToDelegateTo, TrustedToAuthForDelegation, Kerberos…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to capture Windows credentials in clear text using a custom Security Support Provider (SSP) with Mimikatz. Use this skill whenever you need to extract credentials from a Windows system during authorized penetration testing, red teaming, or security…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Execute DCShadow attacks in Active Directory to push attribute changes without logging. Use this skill whenever the user mentions DCShadow, rogue domain controllers, AD attribute modification, primaryGroupID manipulation, SIDHistory backdoors, mimikatz…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Active Directory DCSync attack methodology for security assessments. Use this skill when testing AD environments for DCSync vulnerabilities, analyzing replication permissions, or documenting DCSync attack paths. Trigger when users mention DCSync, AD…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Security research skill for understanding Diamond Ticket Kerberos attacks. Use this skill whenever the user asks about Kerberos ticket manipulation, diamond tickets, golden tickets, sapphire tickets, TGT forgery, PAC modification, Rubeus diamond commands,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to access and leverage Directory Services Restore Mode (DSRM) credentials on Active Directory Domain Controllers. Use this skill whenever the user mentions DSRM, domain controller local administrator access, Active Directory credential extraction, DC…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Active Directory external forest trust enumeration and testing. Use this skill when analyzing outbound trust relationships between domains, investigating trust account vulnerabilities, or performing authorized security assessments of AD trust configurations.…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Active Directory external forest trust exploitation methodology. Use this skill whenever the user mentions forest trusts, cross-domain access, AD trust enumeration, SID history abuse, RBCD across forests, inter-realm TGT/TGS, or any scenario involving…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Execute Golden gMSA/dMSA attacks to derive managed service account passwords offline. Use this skill whenever the user mentions gMSA, dMSA, managed service accounts, KDS root key extraction, or wants to compute service account passwords from Active Directory.…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to create and use Golden Ticket attacks in Active Directory environments. Use this skill whenever the user mentions Golden Tickets, TGT forgery, krbtgt hash, Kerberos ticket attacks, or needs to understand how to forge TGTs for authorized penetration…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Kerberoasting attack methodology for Active Directory penetration testing. Use this skill whenever the user mentions kerberoasting, TGS ticket extraction, SPN enumeration, service account attacks, or wants to extract and crack Kerberos service tickets from…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Kerberos authentication analysis and attack methodology for Active Directory environments. Use this skill whenever the user mentions Kerberos, AD authentication, ticket-based auth, Kerberoasting, AS-REP roasting, delegation abuse, golden tickets, or any…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to understand and work around the Kerberos double hop authentication problem in Windows environments. Use this skill whenever you need to authenticate across multiple hops in Active Directory, troubleshoot Kerberos authentication failures between servers,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Security assessment skill for Lansweeper IT asset management platforms. Use this skill whenever the user needs to assess Lansweeper deployments, harvest scanning credentials, decrypt stored secrets, abuse AD ACLs related to Lansweeper groups, or execute…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use this skill whenever you need to enumerate, read, or exploit LAPS (Local Administrator Password Solution) in Active Directory environments. Trigger when the user mentions LAPS, local admin passwords, AD computer objects, ms-mcs-AdmPwd, LAPS password…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to harden Active Directory against LDAP relay attacks using LDAP signing and channel binding. Use this skill whenever the user mentions LDAP security, AD hardening, LDAP signing, channel binding, LDAP relay prevention, Active Directory security, or wants…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Execute Overpass The Hash/Pass The Key (PTK) attacks in Active Directory environments where NTLM is restricted and Kerberos authentication is required. Use this skill whenever the user mentions Kerberos attacks, NTLM hashes, TGT tickets, pass-the-hash…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to execute Pass the Ticket (PTT) attacks in Active Directory environments. Use this skill whenever the user mentions Kerberos tickets, authentication bypass, ticket theft, PTT attacks, or needs to impersonate users using stolen tickets. Also trigger for…

原文语言:英语

更新
已展示 40 / 908 个已收集 Skill。