active-directory-kerberos-attacks

Warn

Audited by Socket on Apr 9, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

High-risk offensive security skill. Its capabilities match its stated purpose, but that purpose is to enable AI-driven Kerberos attacks against Active Directory, including credential abuse, ticket forgery, delegation exploitation, and chaining with other attack skills. Not confirmed malware, but clearly dangerous and inappropriate for general agent deployment.

Confidence: 94%Severity: 91%
SecurityMEDIUM
KERBEROS_ATTACK_CHAINS.md

This fragment is not benign software code; it is an offensive Kerberos/Active Directory attack-chain guide with explicit steps to crack credentials, abuse delegation/ACLs, forge Kerberos tickets, perform DCSync/secrets dumping, and move laterally. If included in a public dependency/library, it represents a high-risk malicious/abusive content profile even though it is presented as instructions rather than executable logic. Malware likelihood is lower because there is no self-executing code shown, but security risk is extremely high due to its direct facilitation of domain compromise and credential theft.

Confidence: 80%Severity: 90%
Audit Metadata
Analyzed At
Apr 9, 2026, 01:14 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Factive-directory-kerberos-attacks%2F@8088ed0abc86c05a8d347261c15deadb93ba9246