active-directory-kerberos-attacks
Audited by Socket on Sep 15, 2026
2 alerts found:
SecurityMalwareHigh-risk offensive security skill. Its stated purpose and capabilities are internally consistent, but that purpose is to help an AI agent conduct Kerberos-based attacks, credential abuse, privilege escalation, and domain compromise; this makes it unsuitable for general deployment despite no clear evidence of hidden exfiltration or obfuscation.
This fragment is not benign software logic; it is an attacker playbook that provides explicit, actionable instructions for Kerberos/Active Directory privilege escalation and credential theft, including ticket forging/injection, AD object manipulation (delegation/RBCD/shadow credentials/SPNs), DC credential dumping and DCSync replication abuse, and lateral movement via Kerberos-authenticated remote execution. As a distributed artifact in a software supply chain, it represents a high malicious-use facilitation risk. No obfuscation is present, but the operational content is inherently weaponized.