exploiting-zerologon-vulnerability-cve-2020-1472

Fail

Audited by Socket on Apr 10, 2026

1 alert found:

Malware
MalwareHIGH
references/workflows.md

This document is a high-risk exploitation playbook for CVE-2020-1472 (Zerologon) that provides actionable steps to reset a DC machine account password to empty, perform DCSync to extract all domain credential hashes (including krbtgt), and obtain full domain compromise via Pass-the-Hash and Golden Ticket techniques. It should be treated as offensive material: if present where not explicitly authorized, consider it a security incident, remove sensitive content, and investigate authorship and intent. If used for authorized testing, enforce strict approvals, monitoring, and immediate restoration procedures.

Confidence: 85%Severity: 95%
Audit Metadata
Analyzed At
Apr 10, 2026, 08:31 AM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fexploiting-zerologon-vulnerability-cve-2020-1472%2F@bb159565a390a16176a498d442d9dfe6658a7327
Security Audit — socket — exploiting-zerologon-vulnerability-cve-2020-1472