attacking-active-directory
Fail
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPRIVILEGE_ESCALATIONPERSISTENCE
Full Analysis
- [COMMAND_EXECUTION]: The skill documentation contains numerous command-line examples for using security tools such as Rubeus, Impacket, and NetExec. These snippets are provided as educational instructions for the agent to suggest or use during an Active Directory security engagement.
- [EXTERNAL_DOWNLOADS]: References official GitHub repositories for established security projects, including Impacket (maintained by Fortra), Rubeus (by GhostPack), and BloodHound. It also links to HackTricks, which is a well-known documentation service for security professionals and researchers.
- [DATA_EXFILTRATION]: Outlines standard techniques for harvesting credentials from target Windows environments, such as dumping LSASS memory using procdump or comsvcs.dll, and dumping the SAM and SYSTEM registry hives.
- [PRIVILEGE_ESCALATION]: Describes common domain escalation vectors, including Kerberoasting, ASREPRoasting, and the use of DCSync rights to replicate sensitive account data from a Domain Controller.
- [PERSISTENCE]: Explains methods for maintaining access within a domain environment, such as the generation and use of Golden Tickets (TGTs).
Recommendations
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata