performing-active-directory-compromise-investigation

mukul975/performing-active-directory-compromise-investigation · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Investigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateral movement paths.

SKILL.md

Files

This skill is a package of 8 files. Install with the command above, or download the folder.

Related

  1. hunting-for-dcsync-attacks · mukul975 bundle
    Detect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests from non-domain-controller accounts.
    24.6k
    repo stars
  2. performing-active-directory-penetration-test · mukul975 bundle
    Enumerate Active Directory domain objects, discover attack paths with BloodHound, exploit Kerberos weaknesses, escalate privileges via ADCS/DCSync, and demonstrate domain compromise.
    24.6k
    repo stars
  3. windows-ad · zhaoxuya520 bundle
    Guides authorized Active Directory security research covering Kerberos attacks, AD CS vulnerabilities, BloodHound path analysis, NTLM relay, and domain privilege escalation techniques.
    12.8k
    repo stars
  4. abusing-shadow-credentials-for-privesc · mukul975 bundle
    Take over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy, then authenticate via PKINIT.
    24.6k
    repo stars
  5. exploiting-active-directory-with-bloodhound · mukul975 bundle
    Graph-based Active Directory reconnaissance tool that reveals hidden relationships and attack paths from compromised accounts to high-value targets like Domain Admins.
    24.6k
    repo stars
  6. executing-active-directory-attack-simulation · mukul975 bundle
    Executes authorized attack simulations against Active Directory environments to identify misconfigurations, weak credentials, dangerous privilege paths, and exploitable trust relationships that could lead to domain compromise.
    24.6k
    repo stars

Frequently asked questions

How do I install the performing-active-directory-compromise-investigation skill?

Run npx skillmds add mukul975/performing-active-directory-compromise-investigation in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the performing-active-directory-compromise-investigation skill do?

Investigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateral movement paths. It is listed under Security, Coding & Dev Tools, Incident Response on SkillMD.

Is performing-active-directory-compromise-investigation safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: CAUTION, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with performing-active-directory-compromise-investigation?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is performing-active-directory-compromise-investigation free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published performing-active-directory-compromise-investigation?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.