Active Directory Attacks

Identify and exploit vulnerabilities in Microsoft Active Directory environments.

Updated Jan 12, 2026
One-click install
npx skills add https://github.com/giosuetedeschi-spec/bobu-website --skill active-directory-attacks-giosuetedeschi-spec
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Active Directory Attacks
Source: https://github.com/giosuetedeschi-spec/bobu-website/tree/main/.claude/skills/active-directory-attacks
Command: npx skills add https://github.com/giosuetedeschi-spec/bobu-website --skill active-directory-attacks-giosuetedeschi-spec

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This skill provides a structured, professional-grade framework for conducting authorized Active Directory security assessments, helping security professionals identify and remediate complex domain vulnerabilities.

Core Features & Use Cases

  • Attack Path Analysis: Leverages tools like BloodHound to visualize and exploit complex domain relationships.
  • Credential & Ticket Attacks: Provides precise workflows for Kerberoasting, AS-REP roasting, Golden/Silver Ticket creation, and NTLM relaying.
  • Use Case: During a red team engagement, use this skill to safely enumerate domain attack paths, extract service account hashes, and demonstrate privilege escalation risks to stakeholders.

Quick Start

Use the Active Directory Attacks skill to guide you through the process of performing a Kerberoasting attack against a target domain controller.

Frequently Asked Questions about Active Directory Attacks

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a Kerberoasting attack in Active Directory?

Active Directory Kerberoasting is performed by requesting service tickets for service accounts and extracting their hashes offline. This skill provides precise workflows to guide red team operations from initial reconnaissance through extracting service account hashes against a target domain controller.

What is the best way to enumerate Active Directory attack paths?

Enumerating Active Directory attack paths involves mapping complex domain relationships to find privilege escalation risks. This skill provides methodologies leveraging BloodHound to visualize domain vulnerabilities and safely identify lateral movement routes during security assessments.

How does AS-REP roasting work for Windows domain infrastructures?

AS-REP roasting targets user accounts with Kerberos pre-authentication disabled, extracting their AS-REP tickets to crack offline. This skill provides professional-grade workflows for credential harvesting and security auditing of Windows domain infrastructures.

Can I use this for privilege escalation in Microsoft Active Directory?

Yes, this skill is designed for authorized Active Directory security assessments to demonstrate privilege escalation risks. It covers the full spectrum of red team operations including lateral movement, credential harvesting, and achieving domain dominance to identify vulnerabilities.

Do I need prior penetration testing experience for Active Directory security auditing?

This skill satisfies technical requirements for professional penetration testing and security auditing of Windows domain infrastructures. It provides a structured framework for red team engagements, assuming familiarity with Kerberos, enumeration, and domain reconnaissance concepts.