active-directory-attacks

Simulate authorized Active Directory attacks for red-team security assessments.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/aleister1102/skills --skill active-directory-attacks
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: active-directory-attacks
Source: https://github.com/aleister1102/skills/tree/main/active-directory-attacks
Command: npx skills add https://github.com/aleister1102/skills --skill active-directory-attacks

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This skill consolidates advanced Active Directory attack techniques to help security teams simulate intrusions, evaluate defenses, and improve incident response during authorized red-team engagements.

Core Features & Use Cases

  • Reproduces credential harvesting, Kerberoasting, DCSync, Golden/Silver Ticket, and NTLM relay scenarios in controlled settings.
  • Provides guidance for AD reconnaissance, privilege escalation, and lateral movement workflows using common tooling (BloodHound, PowerView, Impacket, Mimikatz).
  • Supports documenting findings, mapping attack paths, and validating compensating controls in scoped environments.

Quick Start

Provide an authorized domain context and request AD attack guidance to enumerate and simulate Kerberoasting and DCSync workflows.

Frequently Asked Questions about active-directory-attacks

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I simulate Kerberoasting and DCSync attacks in an Active Directory environment?

To simulate Active Directory attacks like Kerberoasting and DCSync, you must provide authorized domain credentials and access to a scoped test AD environment. The skill guides you through simulating these attack scenarios using recommended tooling like Impacket and Mimikatz.

What is the best way to perform Active Directory reconnaissance for privilege escalation?

Performing Active Directory reconnaissance for privilege escalation is best achieved using BloodHound and PowerView. This skill provides guidance on mapping attack paths and identifying lateral movement workflows within your scoped infrastructure.

Can I use Impacket and Mimikatz for credential harvesting and lateral movement in AD?

Yes, you can use Impacket and Mimikatz for credential harvesting and lateral movement in AD. This skill specifically covers reproducing these attack scenarios in controlled settings, requiring explicit authorization and documenting findings to ensure safe, reversible actions.

How do Golden Ticket and NTLM relay attacks work in a red-team engagement?

Golden Ticket and NTLM relay attacks work in red-team engagements by exploiting Kerberos and authentication protocols to achieve persistence and lateral movement. This skill helps reproduce these scenarios to evaluate defenses and validate compensating controls.

Do I need explicit authorization to test Active Directory security with attack simulations?

Yes, you need explicit authorization or access to a test AD environment to test Active Directory security with attack simulations. This skill requires scoped AD infrastructures and emphasizes documenting findings while ensuring safe, reversible actions during red-team engagements.

What are the limitations of simulating AD attacks in a production environment?

The limitations of simulating AD attacks in a production environment include the risk of irreversible damage and unauthorized access. This skill requires a scoped test AD infrastructure, explicit authorization, and strict adherence to safe, reversible actions to prevent unintended consequences.