Active Directory Attacks
Warn
Audited by Gen Agent Trust Hub on May 27, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a comprehensive list of commands for exploiting Active Directory infrastructure.
- Evidence: Commands for Kerberoasting (GetUserSPNs.py), DCSync (secretsdump.py), and Pass-the-Hash (psexec.py).
- Evidence: Instructions for exploiting specific CVEs like ZeroLogon and PrintNightmare.
- [COMMAND_EXECUTION]: Instructs the agent to perform operations requiring elevated privileges on the local system.
- Evidence:
sudo date -s "14 APR 2024 18:25:16"in SKILL.md to fix clock skew. - [REMOTE_CODE_EXECUTION]: References external scripts and tools without providing verified sources, creating a risk of executing untrusted code.
- Evidence: Mentions multiple scripts like cve-2020-1472-exploit.py, sam_the_admin.py, ADFSpoof.py, and modifyCertTemplate.py.
- Evidence: Lists Windows binaries such as SharpHound.exe, Rubeus.exe, and Mimikatz.exe for execution.
- [CREDENTIALS_UNSAFE]: Provides templates for command execution that include hardcoded passwords.
- Evidence:
net user backdoor Password123! /addin references/advanced-attacks.md.
Audit Metadata