windows-ad
Use for authorized Active Directory and Windows identity attacks including Kerberos, AD CS, BloodHound paths, NTLM relay, and domain privilege escalation research.
Install
npx skills add https://github.com/zhaoxuya520/reverse-skill --skill windows-adSKILL.md
Windows / Active Directory Security
ACTION REQUIRED(读完后立刻执行)
NOW: 读取../field-journal/precedent-pentest.mdNOW: 域/AD 测试必须明确授权范围(含 DC、是否允许投毒/中继)NOW: case-init;network_profile 与禁止动作写清NEXT: tool-index(impacket/certipy/bloodhound 等常手动)ACT: 从身份枚举与 BloodHound 图开始,不先上破坏性利用
适用场景
- 域渗透、Kerberoasting、AS-REP、委派
- AD CS(ESC1–ESC8 等)证书攻击
- BloodHound / SharpHound 攻击路径
- NTLM Relay / Coercer 强制认证
- 本地提权到域路径(Potato 等作为跳板)
与 attack-chain 关系
- 多阶段从外网到域控 → PRIMARY 可仍是
attack-chain/,本 skill 为 AD 专科 - 已在域内专注身份 → PRIMARY = 本 skill
工作流
1. 枚举
# 示例 Impacket / 内置(需凭据与授权)
nxc smb <range> -u user -p pass
bloodhound-python -d domain.local -u user -p pass -c All -ns <DC>
2. 常见路径(先图后枪)
□ Kerberoast / AS-REP → 离线破解
□ ACL 滥用(GenericAll/WriteDacl)
□ 委派(非约束/约束/基于资源)
□ AD CS 模板错误 → Certipy
□ 中继:LLMNR/NBT-NS + ntlmrelayx(确认授权)
3. 凭证与横向
□ secretsdump / lsassy / mimikatz(严格授权与清理)
□ PtH / PtT / 黄金票仅在授权红队范围
□ 每步写 Evidence;高危等用户确认
工具链
| 工具 | 用途 |
|---|---|
| BloodHound / SharpHound | 路径图 |
| Certipy | AD CS |
| Impacket / NetExec | 横向与枚举 |
| Rubeus / Mimikatz | 票据与凭证(授权) |
| Coercer / Responder | 强制认证 / 投毒 |
参考
references/ad-attack-paths.md../pentest-tools/references/network-attack-defense.md../attack-chain/- seeds:
field-journal/seed-005_ad-certipy-esc1.mdseed-007_ntlm-relay-coercer.mdseed-013_kerberoasting-spn.md
路由上下文
上游: MASTER R24
下游: 报告 docs-generator;需 EDR 研究 edr-bypass-re
MUST NOT: 无授权 DCSync / 黄金票打生产
任务完成自检
- 是否先有图/枚举再有利用?
- 是否记录可复现命令并脱敏?
- 是否遵守 scope 禁止项?
- Checklist?
Related skills
azure-compliancemicrosoft606KRun Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.firebase-security-rules-auditorfirebase124KAudits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege escalation, role bypasses, create vs update inconsistencies, resource exhaustion, type safety, size limits, and hasOnly ownership checks. Use when auditing/reviewing rules, running red-team rule assessments, or scoring against auditor checklists. Don't use for Firebase CLI (login, deploy), Auth, Crashlytics, Remote Config, or database queries.browser-fingerprint-auditliarjsdev69KAudit a browser fingerprint for internal contradictions with the liarjs CLI - canvas, WebGL, WebGL2, WebGPU, audio, 220 fonts, WebRTC and timezone probes, scored against the TLS/HTTP/ASN view of the same request. Use when asked to run a browser fingerprint test, see what a fingerprint looks like, check canvas or WebGL fingerprint stability, compare a spoofed profile against a real browser, or find out whether a browser profile is self-consistent.cloudflare-onecloudflare66KDesign, configure, troubleshoot, or review Cloudflare One Zero Trust and SASE deployments. Use cloudflare-one-migrations for migration planning from other vendors.
