Relaying Ntlm For Adcs Esc8

mukul975/relaying-ntlm-for-adcs-esc8 · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Coerce a domain controller to authenticate to an attacker-controlled host and relay that NTLM authentication to an AD CS web enrollment endpoint to obtain a certificate for the DC machine account, enabling full domain compromise via DCSync.

SKILL.md

Files

This skill is a package of 5 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.6 KB
  • 📄standards.md 1.9 KB
  • 📁scripts
  • ⚙️agent.py 7.4 KB
  • 📄LICENSE 11.0 KB

Related

  1. Coercing Authentication With Coercer Petitpotam · mukul975 bundle
    Trigger machine account authentication with PetitPotam (MS-EFSR) and Coercer across MS-RPRN, MS-DFSNM, and MS-FSRVP to feed NTLM relay into AD CS Web Enrollment (ESC8) and other relay targets.
    24.6k
    repo stars
  2. Windows Ad · zhaoxuya520 bundle
    Guides authorized Active Directory security research covering Kerberos attacks, AD CS vulnerabilities, BloodHound path analysis, NTLM relay, and domain privilege escalation techniques.
    12.8k
    repo stars
  3. Exploiting Adcs With Certipy · mukul975 bundle
    Enumerate and exploit Active Directory Certificate Services ESC1 through ESC16 misconfigurations with Certipy, including SAN abuse, NTLM relay to web enrollment (ESC8), and golden certificate forgery.
    24.6k
    repo stars
  4. Exploiting Active Directory Certificate Services Esc1 · mukul975 bundle
    Exploit misconfigured Active Directory Certificate Services ESC1 vulnerability to request certificates as high-privileged users and escalate domain privileges during authorized red team assessments.
    24.6k
    repo stars
  5. Abusing Shadow Credentials For Privesc · mukul975 bundle
    Take over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy, then authenticate via PKINIT.
    24.6k
    repo stars
  6. Performing Active Directory Penetration Test · mukul975 bundle
    Enumerate Active Directory domain objects, discover attack paths with BloodHound, exploit Kerberos weaknesses, escalate privileges via ADCS/DCSync, and demonstrate domain compromise.
    24.6k
    repo stars

Frequently asked questions

How do I install the Relaying Ntlm For Adcs Esc8 skill?

Run npx skillmds add mukul975/relaying-ntlm-for-adcs-esc8 in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the Relaying Ntlm For Adcs Esc8 skill do?

Coerce a domain controller to authenticate to an attacker-controlled host and relay that NTLM authentication to an AD CS web enrollment endpoint to obtain a certificate for the DC machine account, enabling full domain compromise via DCSync. It is listed under Security, Coding & Dev Tools, Penetration Testing on SkillMD.

Is Relaying Ntlm For Adcs Esc8 safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: FAIL. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with Relaying Ntlm For Adcs Esc8?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is Relaying Ntlm For Adcs Esc8 free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published Relaying Ntlm For Adcs Esc8?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.