active-directory-acl-abuse
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill serves as a technical reference for Active Directory security auditing. The techniques described—including DCSync, GPO abuse, and Shadow Credentials—are standard methodologies in authorized penetration testing and correctly align with the skill's primary stated purpose.
- [COMMAND_EXECUTION]: The skill provides numerous command-line examples for administrative and security tools such as
net user,SharpGPOAbuse.exe, and various Impacket modules. These are intended for the agent to use under user direction within a target environment. - [DATA_EXFILTRATION]: Instructions are provided for extracting sensitive identity data, such as password hashes and LAPS credentials, from Active Directory environments. This is a core component of the documented security audit workflow and does not involve unauthorized exfiltration to external third-party domains.
- [EXTERNAL_DOWNLOADS]: The skill references and provides usage for several established third-party security tools (e.g., BloodHound, Whisker, SharpGPOAbuse). These tools are necessary for the documented attack paths and are standard references in the security community.
Audit Metadata