performing-kerberoasting-attack

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/agent.py and scripts/process.py files provide functionality to execute various security tools including ldapsearch, powershell, wevtutil, and the impacket toolkit. These executions are intended for Active Directory enumeration and ticket manipulation as part of authorized security testing.
  • [EXTERNAL_DOWNLOADS]: The skill documentation references well-known security libraries such as impacket, ldap3, and python-evtx for installation via standard package registries.
  • [SAFE]: The skill follows professional security testing standards, includes appropriate legal notices, and maps its activities to established frameworks like MITRE ATT&CK. No malicious patterns such as exfiltration, obfuscation, or unauthorized access were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 02:56 AM