CtrlK
BlogDocsLog inGet started
Tessl Logo

active-directory-attack

内网域攻击:BloodHound,Kerberoast,ADCS ESC1/ESC8,NTLM Relay,Coerce,DACL,DCSync,Zerologon/NoPac/PrintNightmare,mitm6,LLMNR,Linux内网。Use when attacking Active Directory, ADCS, NTLM relay, or internal domain.

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/active-directory-attack/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A token-efficient, highly actionable AD/internal-domain attack cheatsheet that assumes Claude's expertise and surfaces current tactical context, but it is structured as a monolithic code block with no explicit workflow sequence or validation checkpoints for destructive operations.

Suggestions

Break the single code block into markdown sections (## Recon, ## Kerberos, ## ADCS, ## NTLM Relay, ## Domain CVEs, etc.) so techniques are navigable rather than a wall of text.

Add an explicit attack-chain workflow with validation checkpoints (e.g. verify relay success before escalating, confirm DCSync retrieved krbtgt before forging Golden Ticket) to lift workflow clarity above the destructive-operation cap of 3.

Expand the shorthand technique notes (e.g. ESC1, NoPac, PrintNightmare) into full copy-paste-ready commands or move detailed syntax into a reference file referenced one level deep.

DimensionReasoningScore

Conciseness

The body is a lean cheatsheet that assumes Claude's competence — it names tools, CVEs, and tactics ("certipy find -vulnerable", "secretsdump -just-dc → krbtgt hash→Golden Ticket") without explaining what BloodHound or Kerberoast are, and every line carries non-obvious tactical context such as "(比PtH重要,PtH常被EDR拦)".

5 / 5

Actionability

It cites concrete executable tools and subcommands ("ntlmrelayx -t ldap --escalate-user", "certipy shadow", "responder抓NetNTLMv2→hashcat", "CONFIG SET dir写SSH key"), but several entries are shorthand ("ESC1指定SAN申域管证书") lacking the exact full command syntax, leaving minor gaps.

4 / 5

Workflow Clarity

The body is a categorical catalog (recon → Kerberos → ADCS → relay → coerce → DACL → DCSync → CVEs → IPv6 → LLMNR → Linux) rather than an explicitly sequenced, numbered workflow, and contains no validation/verification checkpoints for these destructive attack operations, which caps the score at 3 per the destructive-operations guideline.

3 / 5

Progressive Disclosure

The content is a single monolithic code block with emoji/pipe markers providing some categorical structure, but no markdown section headings and no split into separate reference files; while it is under 50 lines, the lack of well-organized sections keeps it below the simple-skill exception's 5 anchor.

3 / 5

Total

15

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A tightly-scoped, distinctive trigger description for internal-domain/AD attack techniques with explicit "Use when" guidance; its main weakness is that the capability statement is a compressed bilingual keyword dump rather than a clean action-verb description.

Suggestions

Reframe the "what" portion as concrete action verbs (e.g. "Discover AD attack paths with BloodHound, roast Kerberos tickets, abuse ADCS via ESC1/ESC8, relay NTLM...") instead of a comma-separated technique list.

Add common synonyms a user might say ("red team", "domain controller takeover", "lateral movement", "Golden Ticket") to broaden trigger coverage.

Consider stating scope limits (e.g. internal-network authorized engagements only) to sharpen distinctiveness and reduce ambiguity with generic pentest skills.

DimensionReasoningScore

Specificity

The description enumerates many concrete named techniques ("BloodHound,Kerberoast,ADCS ESC1/ESC8,NTLM Relay,Coerce,DACL,DCSync,Zerologon/NoPac/PrintNightmare,mitm6,LLMNR,Linux内网"), but presents them as a compressed keyword dump of noun-phrases rather than articulated action verbs, leaving a minor gap versus the comprehensive action-phrase anchor.

4 / 5

Completeness

Both "what" (the enumerated internal-domain attack techniques) and "when" ("Use when attacking Active Directory, ADCS, NTLM relay, or internal domain.") are present and explicit; the "what" is a keyword list rather than a polished capability statement, so it sits just below the fully-articulated 5 anchor.

4 / 5

Trigger Term Quality

The English trigger clause supplies natural phrases a practitioner would say ("attacking Active Directory, ADCS, NTLM relay, or internal domain") plus "penetration-testing/红队" tags, giving good keyword coverage, though some common synonyms (e.g. "red team", "domain controller", "lateral movement") are absent.

4 / 5

Distinctiveness Conflict Risk

The skill targets a clear, specialized niche (Active Directory / ADCS / NTLM relay / internal domain attacks) with distinct trigger phrases, making conflict with unrelated skills unlikely.

5 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
Ed1s0nZ/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.