active-directory-technique

Warn

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONPERSISTENCEDATA_EXFILTRATIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill provides instructions for accessing and extracting highly sensitive information including AWS credentials, SSH private keys, and critical Windows registry hives (SAM, SYSTEM, SECURITY). It also targets the Active Directory database (ntds.dit) and lsass.exe memory dumps for credential harvesting.
  • [PRIVILEGE_ESCALATION]: The skill implements numerous techniques for gaining administrative control, such as using sudo, registry modification for persistence, and tools for LSASS debugging and token elevation. It also provides detailed workflows for abusing Active Directory Access Control Lists (ACLs) to escalate privileges.
  • [PERSISTENCE]: The skill includes instructions for establishing long-term persistence within an environment, covering methods like AdminSDHolder abuse, Skeleton Key injection, Security Support Provider (SSP) backdoors, and the creation of Golden Certificates.
  • [COMMAND_EXECUTION]: The instructions rely on the execution of multiple administrative and offensive security tools including the impacket suite, mimikatz, bloodhound, responder, crackmapexec, and certipy.
  • [DYNAMIC_EXECUTION]: The skill provides embedded Python and PowerShell code blocks intended for execution at runtime to perform specific tasks such as AD-Integrated DNS (ADIDNS) record injection and certificate signing request (CSR) generation.
  • [EXTERNAL_DOWNLOADS]: The skill fetches administrative tools from external sources, specifically downloading PsExec64.exe from the official Microsoft Sysinternals repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection by processing untrusted directory data while having extensive system capabilities.
  • Ingestion points: Directory data retrieved via ldapsearch, PowerView, and BloodHound.
  • Boundary markers: Absent; the skill does not implement delimiters to isolate directory content.
  • Capability inventory: High-privilege command execution, file system writes, and network operations across all referenced scripts.
  • Sanitization: Absent; metadata retrieved from the directory is interpolated directly into command strings.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — active-directory-technique