conducting-domain-persistence-with-dcsync

Fail

Audited by Socket on Apr 10, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

HIGH RISK. The skill’s purpose and capabilities are internally aligned, but that purpose is to perform offensive credential theft and persistence in Active Directory. It provides actionable instructions to dump domain secrets, forge Kerberos tickets, and backdoor replication rights, so it should be classified as a dangerous offensive security skill rather than benign automation. No obfuscation or deceptive third-party routing is shown, but the operational impact is severe.

Confidence: 97%Severity: 96%
MalwareHIGH
references/workflows.md

The content presents a high-risk, attacker-oriented blueprint for DCSync and Golden Ticket techniques. It is valuable for defensive threat modeling but inappropriate for public distribution in its current form. Recommend removing or redacting actionable details from public-facing materials, while preserving high-level awareness, and pairing with concrete defenses (monitoring, least privilege, privileged access management, and robust ticket lifecycle controls).

Confidence: 66%Severity: 95%
Audit Metadata
Analyzed At
Apr 10, 2026, 08:32 AM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fconducting-domain-persistence-with-dcsync%2F@70e706dda590736160ee3e7e93c1a63b88063f8a
Security Audit — socket — conducting-domain-persistence-with-dcsync