Claude Skills · Support

Active Directory exploitation after domain credentials exist: Kerberos (AS-REP/Kerberoast including cracking the ticket then using the account), delegation, NTLM coercion/relay, lateral movement, ACL abuse, ADCS ESC1-ESC17 and CVE paths, dMSA/BadSuccessor, Kerberos reflection, identity confusion, management-plane, domain trust, and domain persistence. Own the current AD chain through crack-and-use to DA, equivalent domain control, or the targeted host SYSTEM. Do not stop after requesting TGS. Host C2 belongs to /post. Operator chooses next modules.

★ 27 Synced 1 hour ago View SKILL.md

At a glance

Support Manual install

This skill is for Support and helps you exploit active directory credentials, escalate to domain admin, and move laterally through domain.

Install git clone --depth 1 https://github.com/pale-knight/redteam-skill cp -r redteam-skill/skills/ad-attack ~/.claude/skills/ad-attack
Can use Not declared by the author

active-directoryKerberosNtlmLateral MovementPrivilege EscalationPost Exploitation

Also in pale-knight/redteam-skill

View the repo
Ad Recon DevOps & Infrastructure

Active Directory reconnaissance with or without credentials: user/group/computer enumeration, ACL/delegation, ADCS, modern Windows LAPS, Blo...

Cicd DevOps & Infrastructure

CI/CD pipeline and software-supply-chain exploitation: Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps, Gitea/Forgejo, self-hosted runne...

Cloud Attack DevOps & Infrastructure

Cloud control-plane exploitation for AWS, Azure/Entra, GCP, and Alibaba Cloud: IAM/RAM privilege escalation, impersonation, cross-account tr...

Cloud Recon DevOps & Infrastructure

Cloud control-plane reconnaissance for AWS, Azure/Entra, GCP, and Alibaba Cloud: identity, IAM/RAM, trust, resources, metadata, and managed-...

Creds Support

Credential operations: secret discovery, classification, extraction, conversion, offline cracking of hashes the operator already has as a cr...

Edr Bypass DevOps & Infrastructure

Endpoint defense evasion after an operator-selected chain already has a valid execution path but AV/EDR/AMSI/WDAC/PPL/memory/kernel telemetr...

K8S DevOps & Infrastructure

Kubernetes and container exploitation: identity/RBAC, secrets, kubelet/etcd, managed-cloud workload identities, container-to-node escape inc...

Phishing Support

Client-side initial access and social-engineering attack module. Use when the operator selects a human/client/browser/identity-delivery atta...

Post DevOps & Infrastructure

OS post-exploitation after a stable host foothold: quiet host recon, host-native persistence (Windows Run/tasks/services/COM/WMI and Linux S...

Privesc Linux DevOps & Infrastructure

Linux local privilege escalation from a low-privilege shell to root. Covers quiet vs loud enumeration, sudo/GTFOBins, CVE-2025-32463 chwoot...

Privesc Win Legal

Windows local privilege escalation from a low-privilege shell to Administrator or SYSTEM. Covers quiet vs loud enumeration, SeImpersonate/Po...

Recon Research

通用网络与资产信息收集。面向 IP、CIDR、主机名、企业/域名等尚未明确攻击面的目标,完成资产扩展、主机发现、TCP/UDP端口发现、服务/版本/协议识别...

Other Support skills

To Tickets mattpocock/skills

Break a plan, spec, or the current conversation into a set of tracer-bullet tickets, each declaring its blocking edges, published to the con...

Implement mattpocock/skills

Implement a piece of work based on a spec or set of tickets.

Wayfinder mattpocock/skills

Plan a huge chunk of work — more than one agent session can hold — as a shared map of decision tickets on your issue tracker, and resolve th...

Gws Modelarmor googleworkspace/cli

Google Model Armor: Filter user-generated content for safety.

Persona Customer Support googleworkspace/cli

Manage customer support — track tickets, respond, escalate issues.

Atlassian MCP Jeffallan/claude-skills

Integrates with Atlassian products to manage project tracking and documentation via MCP protocol. Use when querying Jira issues with JQL fil...