ad-pentest

Perform six-phase Active Directory penetration testing with BloodHound and ADCS enumeration.

21|1|Updated Apr 12, 2026
One-click install
npx skills add https://github.com/woohyun212/security-skill --skill ad-pentest
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ad-pentest
Source: https://github.com/woohyun212/security-skill/tree/main/ad-pentest
Command: npx skills add https://github.com/woohyun212/security-skill --skill ad-pentest

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Identifies and prioritizes Active Directory attack paths, credential weaknesses, ADCS misconfigurations, and lateral movement opportunities to produce actionable findings and remediation guidance for enterprise Windows domains.

Core Features & Use Cases

  • Structured six-phase assessment covering unauthenticated enumeration, authenticated BloodHound collection, credential attacks, ADCS/ACL privilege escalation analysis, lateral movement checks, and consolidated reporting.
  • Tool orchestration and guidance for BloodHound, certipy, impacket, crackmapexec, kerbrute, and Responder to capture evidence and generate prioritized attack paths.
  • Use Case: Conduct an authorized internal pentest to discover Kerberoastable accounts, ADCS ESC issues, and shortest paths to Domain Admins, then produce a remediation-focused report.

Quick Start

Run the ad-pentest workflow to perform a six-phase Active Directory assessment and generate a consolidated findings report.

Frequently Asked Questions about ad-pentest

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map Active Directory attack paths to Domain Admins?

Active Directory penetration testing requires documented authorization controls for internal Windows domain engagements. This structured assessment performs reconnaissance, credential attacks, ADCS enumeration, ACL analysis, and lateral movement checks to produce actionable findings.

What is the best way to enumerate ADCS misconfigurations during an AD pentest?

Certipy is used during the ADCS enumeration phase to identify ESC issues and certificate template weaknesses in enterprise Windows domains. This six-phase assessment processes authenticated enumeration data to produce prioritized, remediation-focused findings.

Can I use BloodHound data to find Kerberoastable accounts in Windows domains?

Yes, BloodHound-compatible collection identifies Kerberoastable accounts during the credential attacks phase. The assessment orchestrates BloodHound data with Kerberos and NTLM tooling to capture evidence and generate prioritized attack paths.

Does this Active Directory assessment cover lateral movement and ACL analysis?

Yes, the assessment includes dedicated lateral movement checks and ACL privilege escalation analysis phases. It orchestrates impacket and crackmapexec to validate movement opportunities and ACL weaknesses across enterprise domains.

What tools do I need for an internal Active Directory penetration test?

Internal Active Directory penetration testing requires BloodHound, certipy, impacket, crackmapexec, kerbrute, and Responder. This assessment orchestrates these tools for LDAP enumeration, credential attacks, and ADCS analysis to generate consolidated reports.