Active Directory Attacks

Warn

Audited by Gen Agent Trust Hub on May 27, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a comprehensive list of commands for exploiting Active Directory infrastructure.
  • Evidence: Commands for Kerberoasting (GetUserSPNs.py), DCSync (secretsdump.py), and Pass-the-Hash (psexec.py).
  • Evidence: Instructions for exploiting specific CVEs like ZeroLogon and PrintNightmare.
  • [COMMAND_EXECUTION]: Instructs the agent to perform operations requiring elevated privileges on the local system.
  • Evidence: sudo date -s "14 APR 2024 18:25:16" in SKILL.md to fix clock skew.
  • [REMOTE_CODE_EXECUTION]: References external scripts and tools without providing verified sources, creating a risk of executing untrusted code.
  • Evidence: Mentions multiple scripts like cve-2020-1472-exploit.py, sam_the_admin.py, ADFSpoof.py, and modifyCertTemplate.py.
  • Evidence: Lists Windows binaries such as SharpHound.exe, Rubeus.exe, and Mimikatz.exe for execution.
  • [CREDENTIALS_UNSAFE]: Provides templates for command execution that include hardcoded passwords.
  • Evidence: net user backdoor Password123! /add in references/advanced-attacks.md.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 27, 2026, 10:15 PM
Security Audit — agent-trust-hub — Active Directory Attacks