Authorized Active Directory and Windows identity attacks: Kerberos abuse, AD CS escalation, BloodHound path analysis, NTLM relay, and domain privilege-escalation research.
Scanned 9/3/2026
Install to Claude Code
npx -y skills add sickn33/agentic-awesome-skills --skill windows-ad --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Windows Ad?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/sickn33-windows-ad-agentic-awesome-skills)More formats (shields.io, HTML) on the badges page.
---
name: windows-ad
description: "Authorized Active Directory and Windows identity attacks: Kerberos abuse, AD CS escalation, BloodHound path analysis, NTLM relay, and domain privilege-escalation research."
risk: offensive
source: "https://github.com/zhaoxuya520/reverse-skill"
source_repo: "zhaoxuya520/reverse-skill"
source_type: community
date_added: "2026-08-25"
license: "MIT"
license_source: "https://github.com/zhaoxuya520/reverse-skill/blob/main/LICENSE"
---
> **⚠️ AUTHORIZED USE ONLY**
> This skill is for educational purposes or authorized security assessments only.
> You must have explicit, written permission from the system owner before using this tool.
> Misuse of this tool is illegal and strictly prohibited.
> **Mandatory confirmation gate**
> Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:
> 1. Ask the user to state the exact target URL, IP, account, or resource.
> 2. Ask the user to confirm written authorization and the permitted scope.
> 3. Show the exact command(s) and explain their expected effect.
> 4. Wait for explicit confirmation in the current conversation.
>
> Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.
# Windows / Active Directory Security
## When to Use
- Mapping and attacking AD trust paths in an authorized engagement.
- Researching escalation routes (AD CS, Kerberos delegation) in labs.
## 适用场景
- 域渗透、Kerberoasting、AS-REP、委派
- AD CS(ESC1–ESC8 等)证书攻击
- BloodHound / SharpHound 攻击路径
- NTLM Relay / Coercer 强制认证
- 本地提权到域路径(Potato 等作为跳板)
## 与 attack-chain 关系
- **多阶段从外网到域控** → PRIMARY 可仍是 `attack-chain/`,本 skill 为 **AD 专科**
- **已在域内专注身份** → PRIMARY = 本 skill
## 工作流
### 1. 枚举
```bash
# 示例 Impacket / 内置(需凭据与授权)
nxc smb <range> -u user -p pass
bloodhound-python -d domain.local -u user -p pass -c All -ns <DC>
```
### 2. 常见路径(先图后枪)
```text
□ Kerberoast / AS-REP → 离线破解
□ ACL 滥用(GenericAll/WriteDacl)
□ 委派(非约束/约束/基于资源)
□ AD CS 模板错误 → Certipy
□ 中继:LLMNR/NBT-NS + ntlmrelayx(确认授权)
```
### 3. 凭证与横向
```text
□ secretsdump / lsassy / mimikatz(严格授权与清理)
□ PtH / PtT / 黄金票仅在授权红队范围
□ 每步写 Evidence;高危等用户确认
```
## 工具链
| 工具 | 用途 |
|------|------|
| BloodHound / SharpHound | 路径图 |
| Certipy | AD CS |
| Impacket / NetExec | 横向与枚举 |
| Rubeus / Mimikatz | 票据与凭证(授权) |
| Coercer / Responder | 强制认证 / 投毒 |
## 参考
- `references/ad-attack-paths.md`
- `../pentest-tools/references/network-attack-defense.md`
- `../attack-chain/`
- seeds: `field-journal/seed-005_ad-certipy-esc1.md` `seed-007_ntlm-relay-coercer.md` `seed-013_kerberoasting-spn.md`
## 路由上下文
**上游**: MASTER R24
**下游**: 报告 `docs-generator`;需 EDR 研究 `edr-bypass-re`
**MUST NOT**: 无授权 DCSync / 黄金票打生产
## 任务完成自检
- [ ] 是否先有图/枚举再有利用?
- [ ] 是否记录可复现命令并脱敏?
- [ ] 是否遵守 scope 禁止项?
- [ ] Checklist?
## Limitations
- Domain attacks can destabilize production AD; stage in labs first.
- Relay attacks need signing-disabled targets; modern defaults block many paths.
> Adapted from [zhaoxuya520/reverse-skill](https://github.com/zhaoxuya520/reverse-skill) (MIT).
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!