active-directory-kerberos-attacks

Fail

Audited by Socket on Sep 15, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

High-risk offensive security skill. Its stated purpose and capabilities are internally consistent, but that purpose is to help an AI agent conduct Kerberos-based attacks, credential abuse, privilege escalation, and domain compromise; this makes it unsuitable for general deployment despite no clear evidence of hidden exfiltration or obfuscation.

Confidence: 95%Severity: 90%
MalwareHIGH
KERBEROS_ATTACK_CHAINS.md

This fragment is not benign software logic; it is an attacker playbook that provides explicit, actionable instructions for Kerberos/Active Directory privilege escalation and credential theft, including ticket forging/injection, AD object manipulation (delegation/RBCD/shadow credentials/SPNs), DC credential dumping and DCSync replication abuse, and lateral movement via Kerberos-authenticated remote execution. As a distributed artifact in a software supply chain, it represents a high malicious-use facilitation risk. No obfuscation is present, but the operational content is inherently weaponized.

Confidence: 92%Severity: 98%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:17 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Factive-directory-kerberos-attacks%2F@1e26e74bfde751347fb025e8c9945f056f174eca75bf07d6d6fcf356793ea0b3
Security Audit — socket — active-directory-kerberos-attacks