kerberos-delegation
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous command-line examples for various security tools to automate Kerberos enumeration and exploitation techniques.
- Evidence: Usage of tools such as
nxc(NetExec),bloodyAD,getTGT.py,getST.py,rbcd.py, andRubeus.exethroughoutSKILL.mdto interact with Active Directory services. - [DATA_EXFILTRATION]: The skill describes methods for harvesting sensitive authentication artifacts, including Kerberos TGTs and service tickets, for lateral movement within the target domain.
- Evidence: Procedures in Step 2c and Step 3 for extracting tickets from LSASS or capturing them over the network using
Rubeus,Mimikatz, andkrbrelayx.py. - [SAFE]: The skill is authored by a known security vendor (blacklanternsecurity), utilizes credential placeholders, and provides specific remediation instructions for configuration changes.
- Evidence: Step 4d in
SKILL.mdcontains a "Cleanup (Critical)" section with commands to remove Resource-Based Constrained Delegation (RBCD) attributes usingrbcd.pyorbloodyAD. All command examples use placeholders likeNTHASH,AES256KEY, andP@ssw0rd123!.
Audit Metadata