conducting-domain-persistence-with-dcsync

mukul975/conducting-domain-persistence-with-dcsync · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Extract Active Directory credentials via DCSync attacks and establish domain persistence by dumping KRBTGT, Domain Admin, and service account hashes for Golden Ticket creation.

SKILL.md

Files

This skill is a package of 8 files. Install with the command above, or download the folder.

Related

  1. detecting-dcsync-attack-in-active-directory · mukul975 bundle
    Detect DCSync attacks by monitoring Active Directory replication requests from non-domain-controller accounts via Event ID 4662 and associated GUIDs.
    24.6k
    repo stars
  2. hunting-for-dcsync-attacks · mukul975 bundle
    Detect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests from non-domain-controller accounts.
    24.6k
    repo stars
  3. executing-active-directory-attack-simulation · mukul975 bundle
    Executes authorized attack simulations against Active Directory environments to identify misconfigurations, weak credentials, dangerous privilege paths, and exploitable trust relationships that could lead to domain compromise.
    24.6k
    repo stars
  4. performing-active-directory-penetration-test · mukul975 bundle
    Enumerate Active Directory domain objects, discover attack paths with BloodHound, exploit Kerberos weaknesses, escalate privileges via ADCS/DCSync, and demonstrate domain compromise.
    24.6k
    repo stars
  5. detecting-mimikatz-execution-patterns · mukul975 bundle
    Hunt for Mimikatz execution using command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules.
    24.6k
    repo stars
  6. exploiting-nopac-cve-2021-42278-42287 · mukul975 bundle
    Escalate from standard domain user to Domain Admin by exploiting the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion) in Active Directory environments.
    24.6k
    repo stars

Frequently asked questions

How do I install the conducting-domain-persistence-with-dcsync skill?

Run npx skillmds add mukul975/conducting-domain-persistence-with-dcsync in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the conducting-domain-persistence-with-dcsync skill do?

Extract Active Directory credentials via DCSync attacks and establish domain persistence by dumping KRBTGT, Domain Admin, and service account hashes for Golden Ticket creation. It is listed under Security, Coding & Dev Tools, Penetration Testing on SkillMD.

Is conducting-domain-persistence-with-dcsync safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: CAUTION, Skill Scanner: PASS. Capability flags: executes scripts, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with conducting-domain-persistence-with-dcsync?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is conducting-domain-persistence-with-dcsync free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published conducting-domain-persistence-with-dcsync?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.