ad-overview

Automate Active Directory attack and defense operations with BloodHound, Kerberoasting, ADCS ESC scanning, DCSync, and LAPS extraction.

7|1|Updated Apr 14, 2026
One-click install
npx skills add https://github.com/ArianHobson333/claude-bug-bounty-stack --skill ad-overview
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ad-overview
Source: https://github.com/ArianHobson333/claude-bug-bounty-stack/tree/main/vendor/Decepticon/skills/ad
Command: npx skills add https://github.com/ArianHobson333/claude-bug-bounty-stack --skill ad-overview

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires bloodhound, kerberoasting, adcs, dcsync, laps, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a comprehensive toolkit for attacking and securing Active Directory, including BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, and LAPS extraction.

Core Features & Use Cases

  • BloodHound Ingestion: Automates the process of importing and querying BloodHound data for Active Directory analysis.
  • Kerberoasting: Exploits Kerberos authentication weaknesses to obtain domain credentials.
  • ADCS ESC Scanning: Identifies and scans for misconfigured Active Directory Certificate Services (ADCS) Escrow.
  • DCSync: Leverages replication rights to dump krbtgt hashes.
  • LAPS Extraction: Extracts local administrator passwords from the LAPS tool.
  • Use Case: Utilize this Skill to perform a full attack chain on an Active Directory environment, identifying potential vulnerabilities and taking remedial actions.

Quick Start

Use the ad-overview skill to check for potential vulnerabilities in your Active Directory environment.

Frequently Asked Questions about ad-overview

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate BloodHound data ingestion for Active Directory analysis?

You can automate BloodHound data ingestion for Active Directory analysis by running the ad-overview skill, which imports and queries BloodHound data to map attack paths and identify vulnerabilities in your environment.

Can I scan for ADCS ESC misconfigurations in Active Directory?

Yes, you can scan for ADCS ESC misconfigurations in Active Directory using this skill, which identifies and scans for misconfigured Active Directory Certificate Services Escrow vulnerabilities.

What is the best way to perform Kerberoasting and DCSync attacks during an audit?

The best way to perform Kerberoasting and DCSync attacks during an audit is using this skill, which exploits Kerberos authentication weaknesses to obtain domain credentials and leverages replication rights to dump krbtgt hashes.

How do I extract LAPS passwords in an Active Directory environment?

You can extract LAPS passwords in an Active Directory environment by utilizing this skill, which includes LAPS extraction tooling to retrieve local administrator passwords during security assessments.

Do I need specific tools installed to perform a full Active Directory attack chain?

Yes, you need BloodHound, Kerberoasting tools, ADCS scanning, DCSync, and LAPS tooling installed, as this skill requires these dependencies to execute a full attack chain on an Active Directory environment.

What is DCSync and how does it work in Active Directory?

DCSync is an attack technique that leverages replication rights in Active Directory to dump krbtgt hashes, allowing security professionals to extract domain credentials during offensive and defensive audits.