windows-ad
Installation
SKILL.md
Windows / Active Directory Security
ACTION REQUIRED(读完后立刻执行)
NOW: 读取../field-journal/precedent-pentest.mdNOW: 域/AD 测试必须明确授权范围(含 DC、是否允许投毒/中继)NOW: case-init;network_profile 与禁止动作写清NEXT: tool-index(impacket/certipy/bloodhound 等常手动)ACT: 从身份枚举与 BloodHound 图开始,不先上破坏性利用
适用场景
- 域渗透、Kerberoasting、AS-REP、委派
- AD CS(ESC1–ESC8 等)证书攻击
- BloodHound / SharpHound 攻击路径
- NTLM Relay / Coercer 强制认证
- 本地提权到域路径(Potato 等作为跳板)