Active Directory Attacks

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PERSISTENCE]: The skill explicitly defines the creation of persistent access mechanisms as a primary objective.
  • Evidence: SKILL.md lists "Persistent access mechanisms" in the Outputs/Deliverables section.
  • Evidence: references/advanced-attacks.md provides specific commands to create backdoor user accounts via Group Policy Objects (GPOs) and WSUS updates using instructions like net user backdoor Password123! /add.
  • [PRIVILEGE_ESCALATION]: The core functionality of the skill is to guide the user from low-privileged access to full Domain Administrator control.
  • Evidence: SKILL.md details DCSync attacks using secretsdump.py and forging Golden Tickets with kerberos::golden to gain high-level privileges.
  • Evidence: references/advanced-attacks.md explains how to abuse GPOs to grant local administrator rights using SharpGPOAbuse.exe --AddLocalAdmin and how to exploit unconstrained delegation.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a wide variety of shell commands and scripts, including exploits for critical system vulnerabilities.
  • Evidence: SKILL.md provides commands for executing python3 cve-2020-1472-exploit.py (ZeroLogon) and python3 CVE-2021-1675.py (PrintNightmare).
  • [CREDENTIALS_UNSAFE]: The skill is focused on the unauthorized harvesting and reuse of authentication secrets.
  • Evidence: Provides comprehensive workflows for Kerberoasting, AS-REP Roasting, and Pass-the-Hash/Ticket attacks to extract hashes, TGS tickets, and TGTs from domain controllers and memory.
  • [EXTERNAL_DOWNLOADS]: The skill advocates for downloading and running numerous third-party offensive binaries and remote files from non-trusted sources.
  • Evidence: References binary tools such as SharpHound.exe, Mimikatz.exe, Rubeus.exe, SharpWSUS.exe, and MalSCCM.exe.
  • Evidence: SKILL.md contains an instruction to execute code from a remote network share: \\attacker\share\evil.dll.
  • [DATA_EXFILTRATION]: Provides techniques to harvest and export sensitive organizational data from Active Directory.
  • Evidence: Enumeration of users, domain controllers, and service principal names (SPNs) via tools like BloodHound, PowerView, and GetUserSPNs.py.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface where it ingests untrusted data from an Active Directory environment that could be manipulated to influence agent behavior.
  • Ingestion points: Processes user properties, group memberships, and SPN data via bloodhound-python and PowerView (SKILL.md).
  • Boundary markers: None identified.
  • Capability inventory: Extensive command execution via shell and file system access across all skill files.
  • Sanitization: None identified.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — Active Directory Attacks