active-directory-attack

Warn

Audited by Gen Agent Trust Hub on May 26, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: Provides a wide range of commands for exploiting Windows domain environments, including Kerberos attacks (Kerberoasting, AS-REP Roasting, and ticket forgery), NTLM relaying, and lateral movement.
  • [COMMAND_EXECUTION]: Includes detailed instructions for establishing persistence within a target domain using advanced techniques such as Skeleton Key patching, AdminSDHolder manipulation, and DCShadow.
  • [DATA_EXFILTRATION]: Documents methods for extracting sensitive domain credentials and hashes from domain controllers and memory, specifically utilizing DCSync (via Impacket or Mimikatz) and secrets dumping.
  • [COMMAND_EXECUTION]: Provides commands to modify system time settings or use time-faking utilities to bypass Kerberos synchronization requirements during authentication attacks.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 26, 2026, 08:57 AM
Security Audit — agent-trust-hub — active-directory-attack