Active Directory Attacks
Windows AD attacks: Kerberoasting, DCSync, pass-the-hash, Golden/Silver Ticket, BloodHound.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for Active Directory Attacks, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
An Agent Skill (author zebbern) for Active Directory penetration testing: Kerberoasting, AS-REP roasting, DCSync, pass-the-hash, NTLM relay, Golden/Silver Ticket forging, and BloodHound enumeration. It provides the agent a full Windows-domain attack playbook for authorized engagements.
Key features and capabilities
- Kerberoasting and AS-REP roasting
- DCSync and pass-the-hash
- BloodHound enumeration and ticket forging
Use cases
- Attacking Windows domains
- AD privilege escalation