active-directory-technique

Installation
SKILL.md

Active Directory Technique

Goal: move from domain foothold or low-privilege credential to domain dominance via the shortest confirmed path.

When this technique applies

  • Shell or credential on a domain-joined host (from post-exploit-technique).
  • Valid domain user credential (from phishing, spray, NTLM relay, or credential harvest).
  • Network access to DC ports (88/Kerberos, 389/LDAP, 445/SMB, 636/LDAPS).
  • Red team / pentest requiring AD attack path documentation.
  • Need to validate ACL-based privilege paths such as GenericAll, WriteDacl, WriteOwner, or GenericWrite.

Boundary with other skills

  • Input from post-exploit-technique: shell on domain host, harvested NTLM hash or plaintext.
  • Input from network-technique §Case E: NTLM relay setup (Responder + ntlmrelayx).
  • Recon phase: use recon-technique for initial attack surface mapping; this skill assumes you are inside the domain.
  • Cracking: NTLM/Kerberos hashes from this skill → cracking-technique for offline cracking.
  • Lateral movement tooling: network-technique §Case D/H for proxychains, crackmapexec basics.
Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
active-directory-technique — aeondave/malskill