kerberos-delegation

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous command-line examples for various security tools to automate Kerberos enumeration and exploitation techniques.
  • Evidence: Usage of tools such as nxc (NetExec), bloodyAD, getTGT.py, getST.py, rbcd.py, and Rubeus.exe throughout SKILL.md to interact with Active Directory services.
  • [DATA_EXFILTRATION]: The skill describes methods for harvesting sensitive authentication artifacts, including Kerberos TGTs and service tickets, for lateral movement within the target domain.
  • Evidence: Procedures in Step 2c and Step 3 for extracting tickets from LSASS or capturing them over the network using Rubeus, Mimikatz, and krbrelayx.py.
  • [SAFE]: The skill is authored by a known security vendor (blacklanternsecurity), utilizes credential placeholders, and provides specific remediation instructions for configuration changes.
  • Evidence: Step 4d in SKILL.md contains a "Cleanup (Critical)" section with commands to remove Resource-Based Constrained Delegation (RBCD) attributes using rbcd.py or bloodyAD. All command examples use placeholders like NTHASH, AES256KEY, and P@ssw0rd123!.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 09:15 AM
Security Audit — agent-trust-hub — kerberos-delegation