active-directory-technique

Fail

Audited by Socket on Sep 5, 2026

12 alerts found:

Securityx2Malwarex10
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an Active Directory offensive technique guide, but its purpose is to equip an AI agent to perform high-impact attack operations, including credential theft, relay, persistence, and domain compromise. No confirmed hidden malware is shown, yet the offensive scope, autonomous exploit guidance, and external tool installation make it high security risk.

Confidence: 95%Severity: 94%
MalwareHIGH
references/kerberos-attacks.md

High likelihood of malicious use. The fragment provides explicit, actionable instructions for Active Directory compromise through Kerberos delegation and ticket attacks (SPN/RBCD manipulation), including pass-the-ticket/overpass-the-hash workflows and remote execution and secrets dumping. This aligns strongly with credential theft and privilege escalation/sabotage rather than legitimate software functionality.

Confidence: 93%Severity: 98%
MalwareHIGH
references/certificate-abuse.md

The provided fragment is a high-confidence malicious exploitation/weaponization write-up for abusing Microsoft AD CS. It describes (1) backing up a CA private key and forging arbitrary certificates for certificate-based authentication, and/or (2) abusing misconfigured AD CS templates to obtain server-auth TLS certificates for attacker-controlled service impersonation, including follow-on operational steps (DNS poisoning and rogue HTTPS) targeting high-impact enterprise services. This content would be a severe supply-chain threat if shipped in any dependency, as it directly enables unauthorized access and enterprise service compromise.

Confidence: 82%Severity: 100%
MalwareHIGH
references/domain-trust-attacks.md

This fragment is highly indicative of malicious intent and directly enables Active Directory compromise techniques: forging/modifying Kerberos tickets with ExtraSID/PAC injection, abusing trust keys and SIDHistory for cross-domain privilege escalation, performing Kerberoasting for credential recovery, and reading highly sensitive DC/system artifacts over SMB using backup-intent access with forged Kerberos tickets. If present in a software dependency, it represents an extreme supply-chain security risk rather than legitimate functionality.

Confidence: 85%Severity: 100%
MalwareHIGH
references/ad-enumeration.md

This fragment is highly indicative of malicious credential-harvesting intent. It provides actionable, command-level guidance to retrieve and decode sensitive AD-stored secrets for both LAPS (local administrator passwords) and gMSA (managed passwords/NT hashes), including permission discovery (BloodHound) and an NTLM relay abuse path. If this content appears in a package repository, build artifact, or dependency, it represents a serious security risk and should be treated as hostile or at minimum as unacceptable behavior for a legitimate software supply chain.

Confidence: 80%Severity: 95%
MalwareHIGH
references/ad-services-abuse.md

This fragment is overwhelmingly indicative of malicious, offensive behavior. It provides an end-to-end enterprise intrusion workflow: use LDAP writes to inject AD-integrated DNS records (ADIDNS poisoning) to redirect WSUS hostname resolution to an attacker-controlled WSUS server, then serve an Authenticode-suitable executable for download during WSUS synchronization, with the intended result of executing the payload as NT AUTHORITY\SYSTEM on victim hosts. There is no legitimate software supply-chain functionality observable in the provided content; it is exploit wiring and operational attack guidance.

Confidence: 78%Severity: 100%
MalwareHIGH
references/rodc-attacks.md

This fragment is a highly actionable offensive Kerberos/AD abuse playbook. It instructs extracting krbtgt AES keys from a compromised RODC LSASS, forging authentication tickets accepted by a writable DC, and using KERB-KEY-LIST-REQ (via KeyList) to disclose long-term keys under PRP—followed by Kerberos-authenticated lateral movement. This is strongly consistent with malicious intent (credential theft/impersonation/key disclosure) and represents extreme security risk if distributed as part of a software supply chain.

Confidence: 92%Severity: 99%
SecurityMEDIUM
references/domain-persistence.md

This fragment is not a benign code artifact; it is an attacker-style playbook detailing multiple high-impact Active Directory/domain controller persistence and credential-compromise techniques, including security-critical tampering (LSASS/SSP/LSA registry), replication abuse (DCShadow), DSRM exploitation, and long-term PKI forgery (Golden Certificate). No actual dependency implementation is provided, so execution cannot be verified, but the content is strongly suggestive of malicious intent and would represent a severe security concern if present in a software supply-chain context.

Confidence: 70%Severity: 78%
MalwareHIGH
references/ntlm-relay.md

This is high-confidence malicious offensive content rather than legitimate software dependency code. It provides an end-to-end AD compromise chain: coercing NTLM authentication from a target machine, relaying that authentication to the DC over LDAP to modify RBCD delegation rights, using S4U2Proxy to impersonate an administrator, and executing commands remotely via WMI; it also references cleanup of an added account. The presence of privilege-escalation and remote-execution steps indicates a serious security risk if included in a package.

Confidence: 90%Severity: 98%
MalwareHIGH
references/kerberos-only-and-badsuccessor.md

This fragment is strongly indicative of malicious offensive guidance focused on Active Directory/Kerberos credential extraction. It describes manipulating sensitive msDS-* directory attributes, using dMSA/badSuccessor and S4U2self authenticated via Kerberos ccache, and obtaining the target account’s RC4/NT hash for subsequent credential abuse. Obfuscation is absent, but the content itself is directly actionable for compromise and should be treated as a high-risk malicious indicator if present in any software distribution artifact.

Confidence: 66%Severity: 93%
MalwareHIGH
references/lateral-movement-ad.md

This fragment is an explicit Active Directory lateral-movement and remote execution operational playbook that leverages credential abuse (pass-the-hash/pass-the-ticket), multiple remote management protocols (SMB/WinRM/WMI/DCOM/RDP), and includes explicit evasion/cleanup steps (PowerShell history deletion and Windows event log clearing). There is no benign software functionality present; it would meaningfully enable intrusion and reduce forensic visibility if distributed in a software supply chain.

Confidence: 90%Severity: 100%
MalwareHIGH
references/ad-acl-abuse.md

This fragment is strongly indicative of malicious intent: it provides explicit, actionable instructions (including LDAP/security-descriptor manipulation, gMSA secret extraction, SPN jacking for Kerberos abuse, and ForceChangePassword credential takeover). If included in a published software dependency/artifact, it would materially increase the capability to compromise Active Directory and exfiltrate credential material. No evidence of code obfuscation is present, but the content itself is highly sensitive and exploit-oriented.

Confidence: 62%Severity: 93%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:47 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Factive-directory-technique%2F@2dd7c9b9a544a6346ad761b533c8e887cc5dfd68ec5b6d3080f7258b5c380cf8
Security Audit — socket — active-directory-technique