active-directory-technique
Installation
SKILL.md
Active Directory Technique
Goal: move from domain foothold or low-privilege credential to domain dominance via the shortest confirmed path.
When this technique applies
- Shell or credential on a domain-joined host (from post-exploit-technique).
- Valid domain user credential (from phishing, spray, NTLM relay, or credential harvest).
- Network access to DC ports (88/Kerberos, 389/LDAP, 445/SMB, 636/LDAPS).
- Red team / pentest requiring AD attack path documentation.
- Need to validate ACL-based privilege paths such as
GenericAll,WriteDacl,WriteOwner, orGenericWrite.
Boundary with other skills
- Input from
post-exploit-technique: shell on domain host, harvested NTLM hash or plaintext. - Input from
network-technique§Case E: NTLM relay setup (Responder + ntlmrelayx). - Recon phase: use
recon-techniquefor initial attack surface mapping; this skill assumes you are inside the domain. - Cracking: NTLM/Kerberos hashes from this skill →
cracking-techniquefor offline cracking. - Lateral movement tooling:
network-technique§Case D/H for proxychains, crackmapexec basics.