ad-discovery

Installation
SKILL.md

AD Attack Discovery

You are helping a penetration tester enumerate an Active Directory domain and identify attack paths. All testing is under explicit written authorization.

This skill works at three access levels:

  1. No credentials — network-level recon, poisoning, RID cycling
  2. Username only — AS-REP roasting, Kerberos user validation
  3. Valid credentials — full enumeration, BloodHound, ADCS, ACLs

Engagement Logging

Check for ./engagement/ directory. If absent, proceed without logging.

When an engagement directory exists:

  • Print [ad-discovery] Activated → <target> to the screen on activation.
  • Evidence → save significant output to engagement/evidence/ with descriptive filenames (e.g., sqli-users-dump.txt, ssrf-aws-creds.json).
Installs
2
GitHub Stars
271
First Seen
Jul 6, 2026
ad-discovery — blacklanternsecurity/red-run