bloodyad

Installation
SKILL.md

bloodyad

Goal: Exploit Active Directory Access Control List (ACL) vulnerabilities and manipulate AD objects without relying on WinRM or native Windows RSAT tools.

Cognitive Stance

bloodyAD is an offensive LDAP/SAMR framework. It acts as the direct execution layer for attack paths identified by BloodHound (GenericAll, WriteDACL, ForceChangePassword, etc). It operates cross-platform and fully supports proxying (SOCKS).

Core Authentication Patterns

Authentication follows standard Impacket-style formats but with specific arguments. The executable is typically invoked as bloodyAD.

# Cleartext
bloodyAD --host <DC_IP> -d <domain> -u <username> -p <password> <command>

# Pass-The-Hash (NTLM)
bloodyAD --host <DC_IP> -d <domain> -u <username> -p aad3b435b51404eeaad3b435b51404ee:<NTHash> <command>
Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
bloodyad — aeondave/malskill