active-directory-attack
Installation
SKILL.md
Active Directory Attacks
When to Activate
- Attacking Windows domain environments after gaining any domain foothold (creds, hash, or unauth network position)
- Kerberos exploitation: Kerberoasting, AS-REP roasting, delegation (RBCD/constrained/unconstrained), ticket forgery
- Coercion + NTLM/Kerberos relay chains (PetitPotam/DFSCoerce → LDAP/ADCS, NTLM reflection CVE-2025-33073)
- ADCS certificate-template abuse (ESC1-ESC16) and certificate-based domain takeover
- dMSA / BadSuccessor privilege escalation on Windows Server 2025 domains
- BloodHound CE attack-path discovery, lateral movement, DCSync, and domain-dominance persistence