Login
Download
Skill UI
Browse and discover
10192+
curated skills
All
Development
Artificial Intelligence
Design & Creative
Product & Business
Data Science
Marketing
Soft Skills
Productivity
Engineering
Languages
Search
Active Directory
, found
37
results
Default
Newest
Most Downloaded
Exploiting AD CS For Privilege Escalation
exploiting-active-directory-certificate-services-esc1
mukul975/Anthropic-Cybersecurity-Skills
115
This guide details the exploitation of the Active Directory Certificate Services (AD CS) ESC1 vulnerability. By leveraging misconfigurations, an attacker can request certificates impersonating high-privileged users (e.g., Domain Admins). The workflow covers AD enumeration, forging certificates with arbitrary Subject Alternative Names (SANs), authenticating via PKINIT, and ultimately escalating domain privileges using tools like mimikatz. Essential for authorized red team and penetration testing.
View Details
Exploiting Active Directory With BloodHound
exploiting-active-directory-with-bloodhound
mukul975/Anthropic-Cybersecurity-Skills
390
BloodHound is a powerful, graph-based reconnaissance tool specifically designed for Active Directory environments. It utilizes graph theory to map deep, hidden relationships and potential attack paths—such as privilege escalation chains—from compromised low-value accounts to high-value targets like Domain Admins. This tool is essential for authorized red team exercises and penetration testing engagements.
View Details
Exploiting Constrained Delegation Abuse
exploiting-constrained-delegation-abuse
mukul975/Anthropic-Cybersecurity-Skills
179
This technique details how to exploit misconfigurations within Kerberos Constrained Delegation (KCD) in Active Directory. By leveraging S4U2self and S4U2proxy extensions, attackers can impersonate highly privileged users (e.g., Domain Admins) to request service tickets, enabling lateral movement and full domain compromise during authorized red teaming or penetration testing.
View Details
Kerberoasting Attacks with Impacket Tool
exploiting-kerberoasting-with-impacket
mukul975/Anthropic-Cybersecurity-Skills
393
A comprehensive guide detailing the Kerberoasting technique (T1558.003) used in Active Directory environments. This method exploits service accounts by requesting and subsequently cracking Kerberos TGS tickets offline, allowing attackers to compromise credentials. Instructions cover enumeration, ticket request, cracking with tools like Hashcat/John the Ripper, and credential validation, for authorized red team and penetration testing purposes.
View Details
Exploiting noPac for Domain Admin Escalation
exploiting-nopac-cve-2021-42278-42287
mukul975/Anthropic-Cybersecurity-Skills
216
This skill details exploiting the noPac vulnerability chain, combining CVE-2021-42278 (sAMAccountName spoofing) and CVE-2021-42287 (KDC PAC confusion). It allows an authenticated standard domain user to escalate privileges to Domain Admin, potentially compromising the entire domain. It is designed for authorized red team exercises and penetration testing against vulnerable Active Directory environments.
View Details
Exploiting Zerologon Vulnerability in Domain Controllers
exploiting-zerologon-vulnerability-cve-2020-1472
mukul975/Anthropic-Cybersecurity-Skills
450
This skill details the exploitation of the critical Zerologon vulnerability (CVE-2020-1472) found in the Microsoft Netlogon Remote Protocol. It allows an unauthenticated attacker to compromise a domain controller by resetting its machine account password. The guide covers the complete attack chain, including initial exploitation, credential dumping via DCSync, and subsequent privilege escalation in Active Directory environments. Used exclusively for authorized red teaming and security testing.
View Details
Detecting DCSync Attacks Via Event Logs
hunting-for-dcsync-attacks
mukul975/Anthropic-Cybersecurity-Skills
338
This guide details how to hunt for DCSync attacks, a technique used to steal password hashes from Active Directory. It involves analyzing Windows Event ID 4662 to identify unauthorized DS-Replication-Get-Changes requests originating from non-domain-controller accounts. Essential for incident response and threat detection.
View Details
Hunting for NTLM Relay Attacks Detection
hunting-for-ntlm-relay-attacks
mukul975/Anthropic-Cybersecurity-Skills
389
This skill provides advanced threat hunting capabilities to detect NTLM relay attacks within Active Directory environments. It analyzes critical Windows Security Event 4624 logs, specifically focusing on logon type 3 using NTLMSSP authentication. The detection logic identifies suspicious patterns, including IP-to-hostname mismatches, rapid multi-host authentications, and lack of SMB signing enforcement, helping SOC analysts pinpoint unauthorized credential access attempts.
View Details
Active Directory BloodHound Attack Path Analysis
performing-active-directory-bloodhound-analysis
mukul975/Anthropic-Cybersecurity-Skills
490
BloodHound is an open-source reconnaissance tool that leverages graph theory to analyze Active Directory relationships. This guide details the process of collecting AD data using SharpHound and visualizing complex attack paths. It helps identify potential privilege escalation chains, trust abuses, and misconfigurations necessary for an attacker to move from a low-privilege user account to Domain Admin, making it essential for advanced red-teaming and security auditing.
View Details
Investigating Active Directory Compromises
performing-active-directory-compromise-investigation
mukul975/Anthropic-Cybersecurity-Skills
313
A comprehensive guide for incident responders detailing how to investigate Active Directory (AD) compromises. This skill covers analyzing critical components like NTDS.dit integrity, detecting Kerberos anomalies (Golden/Silver Tickets), tracing lateral movement, and identifying Group Policy abuse to reconstruct attacker activity and determine the full scope of a breach.
View Details
Active Directory Forest Trust Attack Enumeration
performing-active-directory-forest-trust-attack
mukul975/Anthropic-Cybersecurity-Skills
492
This skill systematically enumerates and audits Active Directory forest trust relationships using advanced techniques like SID filtering analysis, detecting SID history abuse, and assessing inter-realm Kerberos ticket configurations. It is designed for red-teaming and security auditing to identify potential lateral movement paths and trust vulnerabilities across organizational boundaries.
View Details
Advanced Active Directory Penetration Testing
performing-active-directory-penetration-test
mukul975/Anthropic-Cybersecurity-Skills
109
Conducts a comprehensive Active Directory penetration test, covering domain enumeration, misconfiguration discovery, and attack path analysis using BloodHound. Techniques include exploiting Kerberos weaknesses (Kerberoasting, AS-REP Roasting) and escalating privileges via DCSync and constrained delegation, culminating in domain compromise demonstration.
View Details
Prev
1
2
3
4
Next
Language
简体中文
English