deploying-active-directory-honeytokens

mukul975/deploying-active-directory-honeytokens · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Deploys deception-based honeytokens in Active Directory, including fake privileged accounts, SPNs for Kerberoasting detection, decoy GPOs with cpassword traps, and deceptive BloodHound paths, with monitoring for Windows Security Event IDs.

SKILL.md

Files

This skill is a package of 5 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 11.7 KB
  • 📁scripts
  • ⚙️agent.py 52.7 KB
  • ⚙️Deploy-ADHoneytokens.ps1 22.2 KB
  • 📄LICENSE 11.0 KB

Related

  1. detecting-kerberoasting-attacks · mukul975 bundle
    Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with SPNs for offline password cracking.
    24.6k
    repo stars
  2. conducting-internal-network-penetration-test · mukul975 bundle
    Simulate an insider threat or post-breach attacker to identify lateral movement paths, privilege escalation vectors, and sensitive data exposure within a corporate network.
    24.6k
    repo stars
  3. executing-active-directory-attack-simulation · mukul975 bundle
    Executes authorized attack simulations against Active Directory environments to identify misconfigurations, weak credentials, dangerous privilege paths, and exploitable trust relationships that could lead to domain compromise.
    24.6k
    repo stars
  4. performing-active-directory-bloodhound-analysis · mukul975 bundle
    Enumerate Active Directory relationships and identify attack paths from compromised users to Domain Admin using BloodHound and SharpHound.
    24.6k
    repo stars
  5. windows-ad · zhaoxuya520 bundle
    Guides authorized Active Directory security research covering Kerberos attacks, AD CS vulnerabilities, BloodHound path analysis, NTLM relay, and domain privilege escalation techniques.
    12.8k
    repo stars
  6. performing-active-directory-vulnerability-assessment · mukul975 bundle
    Assess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations, privilege escalation paths, and attack vectors.
    24.6k
    repo stars

Frequently asked questions

How do I install the deploying-active-directory-honeytokens skill?

Run npx skillmds add mukul975/deploying-active-directory-honeytokens in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the deploying-active-directory-honeytokens skill do?

Deploys deception-based honeytokens in Active Directory, including fake privileged accounts, SPNs for Kerberoasting detection, decoy GPOs with cpassword traps, and deceptive BloodHound paths, with monitoring for Windows Security Event IDs. It is listed under Security, Incident Response, Penetration Testing on SkillMD.

Is deploying-active-directory-honeytokens safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: CAUTION, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with deploying-active-directory-honeytokens?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is deploying-active-directory-honeytokens free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published deploying-active-directory-honeytokens?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.