ldap-pentesting
Audited by Socket on Aug 12, 2026
2 alerts found:
Securityx2该 Skill 与其“LDAP 渗透测试”目的基本一致,但其能力本身是高风险的进攻性安全自动化:包含凭据攻击、MITM、注入、目录写入、本地敏感配置/数据库读取和后渗透步骤。未见明确隐蔽外传或伪装分发,因此更像高风险攻击技能而非确认恶意软件。
This fragment is an offensive AD/LDAP attack playbook. It provides explicit instructions and payloads for LDAP injection, Kerberos credential attacks (Kerberoasting/AS-REP roasting), reconnaissance (including BloodHound), and local extraction/cracking workflows using sensitive materials (keytab and LDAP backend files). While it does not demonstrate covert supply-chain malware mechanics (e.g., hidden exfiltration/persistence/obfuscation) because it is not actual dependency code, including such content in a distributed package or automation would constitute a high security risk because it substantially facilitates unauthorized access and credential theft.