active-directory-acl-abuse
Audited by Socket on Jul 21, 2026
2 alerts found:
Securityx2High-risk offensive security skill. Its capabilities are internally consistent with its stated purpose, but that purpose is to help an AI agent conduct AD exploitation, credential compromise, and privilege escalation, including chaining into additional offensive skills. No strong malware or exfiltration indicators are present, but the operational security risk is very high.
This fragment is not a benign library module; it is an offensively oriented BloodHound/BloodHound CE workflow that combines credentialed AD data collection and authenticated API retrieval with Cypher queries that return actionable privilege-escalation and lateral-movement paths (Domain Admin reachability, DCSync/Kerberoasting/AS-REP roast chains, GPO abuse, unconstrained delegation, LAPS readers). No obfuscated payloads or in-process malware are present in the snippet itself, but its misuse potential is extremely high and it should be treated as high risk in any software supply-chain context.