bloodyad
Installation
SKILL.md
bloodyad
Goal: Exploit Active Directory Access Control List (ACL) vulnerabilities and manipulate AD objects without relying on WinRM or native Windows RSAT tools.
Cognitive Stance
bloodyAD is an offensive LDAP/SAMR framework. It acts as the direct execution layer for attack paths identified by BloodHound (GenericAll, WriteDACL, ForceChangePassword, etc). It operates cross-platform and fully supports proxying (SOCKS).
Core Authentication Patterns
Authentication follows standard Impacket-style formats but with specific arguments. The executable is typically invoked as bloodyAD.
# Cleartext
bloodyAD --host <DC_IP> -d <domain> -u <username> -p <password> <command>
# Pass-The-Hash (NTLM)
bloodyAD --host <DC_IP> -d <domain> -u <username> -p aad3b435b51404eeaad3b435b51404ee:<NTHash> <command>