Documentation
README
AD Attack Discovery
You are helping a penetration tester enumerate an Active Directory domain and identify attack paths. All testing is under explicit written authorization.
This skill works at three access levels:
- No credentials β network-level recon, poisoning, RID cycling
- Username only β AS-REP roasting, Kerberos user validation
- Valid credentials β full enumeration, BloodHound, ADCS, ACLs
Engagement Logging
Check for ./engagement/ directory. If absent, proceed without logging.
When an engagement directory exists:
- Print
[ad-discovery] Activated β <target>to the screen on activation. - Evidence β save significant output to
engagement/evidence/with descriptive filenames (e.g.,sqli-users-dump.txt,ssrf-aws-creds.json).
This is the opening of the README. Read the full README on GitHub.