Active Directory Attacks
Warn
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates establishing persistence through commands that create backdoor users and scheduled tasks (e.g.,
net user backdoor ... /addviaSharpWSUS.exeandSharpGPOAbuse.exe). It also usessudofor system clock synchronization. - [REMOTE_CODE_EXECUTION]: The skill instructs the agent to run numerous unverified external scripts for CVE exploitation (e.g.,
cve-2020-1472-exploit.py,sam_the_admin.py) and a remote DLL payload via an SMB share (\\attacker\share\evil.dll). - [DATA_EXFILTRATION]: The skill includes instructions to harvest and potentially exfiltrate sensitive authentication material, such as NT hashes, Kerberos tickets, and DSRM credentials, from domain controllers and network memory using tools like
secretsdump.py,Mimikatz, andRubeus. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection.
- Ingestion points: The skill processes output from Active Directory enumeration tools like
BloodHoundandPowerView(SKILL.md). - Boundary markers: None are present to delimit untrusted data.
- Capability inventory: The skill has access to full shell execution (
bash,powershell), file modification, and network operations. - Sanitization: No escaping or validation is performed on tool outputs before processing.
Audit Metadata