Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction.
68
85%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
| Skill | Use for |
|---|---|
/skills/standard/ad/bloodhound-query/SKILL.md | Ingest + common Cypher queries |
/skills/standard/ad/kerberoasting/SKILL.md | Roast SPN users, crack with hashcat |
/skills/standard/ad/asrep-roasting/SKILL.md | dontreqpreauth users |
/skills/standard/ad/adcs-esc1/SKILL.md | ESC1 template abuse → domain admin |
/skills/standard/ad/dcsync/SKILL.md | Replication rights → krbtgt dump |
/skills/standard/ad/laps/SKILL.md | LAPS local admin password extraction |
/skills/standard/ad/netexec/SKILL.md | NetExec (formerly CrackMapExec) cheatsheet — SMB/WinRM/LDAP/MSSQL modules |
bash("bloodhound-python -u user -p pass -d DOMAIN -c all --zip")bh_ingest_zip("/workspace/bh.zip")dcsync_check — if any principal, that's instant domain compromisekg_query(kind="user") and filter for hasspn=true → Kerberoast queuekg_query(kind="user") and filter for dontreqpreauth=true → AS-REP roastbash("certipy find -u user -p pass -dc-ip X -json") then adcs_auditplan_attack_chains to see graph-computed domain compromise pathskg_add_node(kind="crown_jewel", label="Domain Admins group")
kg_add_node(kind="crown_jewel", label="krbtgt account")
kg_add_node(kind="crown_jewel", label="DC: DC01.corp.local")5e34a6d
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.