Ad Recon

Active Directory reconnaissance with or without credentials: user/group/computer enumeration, ACL/delegation, ADCS, modern Windows LAPS, BloodHound, Server 2025/dMSA/Ghost SPN candidates, and trust mapping. Recon only — do not exploit Kerberoast-to-DA, DCSync, or change passwords. Operator may select /ad-attack after cards are ready.

pale-knight c140871 6 files · 23.0 KB Updated

File contents

pale-knight/redteam-skill/tree/main/skills/ad-recon commit c1408714bc

Frequently asked questions

npx skillmds@latest add pale-knight/ad-recon