Active Directory Attacks
Audited by Socket on Feb 16, 2026
1 alert found:
SecurityThis skill is a high-risk offensive playbook that explicitly instructs how to perform powerful Active Directory attacks (credential harvesting, DCSync, ticket forging, NTLM relays, CVE exploitation). The capabilities match the stated purpose, so there's internal consistency, but the required privileges and operations are highly sensitive and can lead to full domain compromise. There is no evidence the skill itself contains backdoor code or obfuscation; the danger is legitimate: it provides step-by-step instructions and commands that enable credential theft and persistence. Operators should treat this as suspicious/dangerous content: acceptable for authorized red-team/penetration-testing under strict governance, but unsuitable and dangerous for general use. Verify provenance of any exploit scripts referenced and protect any output files (hashes, ticket caches, pfx) appropriately.