active-directory-kerberos-attacks

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Provides numerous command-line examples for industry-standard tools including Impacket, Rubeus, Mimikatz, and PowerView for domain environment interaction.- [PRIVILEGE_ESCALATION]: Outlines comprehensive techniques for domain-level privilege escalation, including Kerberos ticket forging (Golden, Silver, Diamond, Sapphire) and delegation abuse (Unconstrained, Constrained, RBCD).- [DATA_EXFILTRATION]: Documents methodologies for extracting sensitive authentication material, such as domain-wide NTLM hashes via DCSync and Kerberos tickets.- [INDIRECT_PROMPT_INJECTION]: The skill contains a vulnerability surface where untrusted user input is interpolated into high-privilege commands. Ingestion points: Target hostnames, IPs, and credentials in SKILL.md and KERBEROS_ATTACK_CHAINS.md. Boundary markers: Absent. Capability inventory: Remote command execution and domain-wide credential dumping. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:13 PM
Security Audit — agent-trust-hub — active-directory-kerberos-attacks