active-directory-kerberos-attacks
Audited by Socket on Jul 21, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS. The skill is an explicit offensive-security playbook for Kerberos attacks in Active Directory, including credential theft, ticket forgery, persistence, and lateral movement, and it further chains into other attack skills. There is no obvious hidden exfiltration or deceptive installer, so this is not confirmed malware, but it is a high-risk AI agent capability that does not belong in a benign general-purpose skill ecosystem.
This fragment is not benign software logic; it is an attacker playbook that provides explicit, actionable instructions for Kerberos/Active Directory privilege escalation and credential theft, including ticket forging/injection, AD object manipulation (delegation/RBCD/shadow credentials/SPNs), DC credential dumping and DCSync replication abuse, and lateral movement via Kerberos-authenticated remote execution. As a distributed artifact in a software supply chain, it represents a high malicious-use facilitation risk. No obfuscation is present, but the operational content is inherently weaponized.