🎟️
AutomationPython

Kerberos Ticket Forging

by blacklanternsecurity

Kerberos Ticket Forging is an Automation skill for Claude Code, published by blacklanternsecurity in red-run.

266 stars37 forkson blacklanternsecurity/red-runAdded 2026/09/02+3% in starsRepository updated 2026/04/01
claudeclaude-codectfoffensive-securitypenetration-testingred-teamsecurity
Install in seconds
Install Kerberos Ticket Forging
Copy Kerberos Ticket Forging into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/blacklanternsecurity/red-run/tree/main/skills/ad/kerberos-ticket-forging ~/.claude/skills/kerberos-ticket-forging

Requires Node.js. Downloads this skill only β€” not the rest of the repository β€” into your Claude Code skills folder.

Without Node.js

git clone https://github.com/blacklanternsecurity/red-run.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
skills/ad/kerberos-ticket-forging/SKILL.md in blacklanternsecurity/red-run
Installs to
~/.claude/skills/kerberos-ticket-forging
Collection
One of 25 skills cataloged from this repository
Category
Automation β€” 1648 skills

What Kerberos Ticket Forging does

Kerberos Ticket Forging for forging Golden, Silver, Diamond, Sapphire, and pass-the-ticket Kerberos tickets during authorized red team testing. Use it when you have domain or service key material and need Kerberos-based persistence or privilege escalation.

Kerberos Ticket Forging is cataloged under Automation on DirSkills. Kerberos Ticket Forging comes from a repository tagged claude, claude-code, ctf, offensive-security and penetration-testing.

Documentation

README

Kerberos Ticket Forging

You are helping a penetration tester forge Kerberos tickets for domain persistence and privilege escalation. All testing is under explicit written authorization.

Kerberos-first authentication: Forged tickets are inherently Kerberos. Use -k -no-pass (Impacket) or --use-kcache (NetExec) for all operations with forged tickets.

Engagement Logging

Check for ./engagement/ directory. If absent, proceed without logging.

When an engagement directory exists:

  • Print [kerberos-ticket-forging] Activated β†’ <target> to the screen on activation.
  • Evidence β†’ save significant output to engagement/evidence/ with descriptive filenames (e.g., sqli-users-dump.txt, ssrf-aws-creds.json).

This is the opening of the README. Read the full README on GitHub.

Commands Kerberos Ticket Forging provides

Slash commands named in this skill’s SKILL.md, listed in the order they first appear.

  • /ldap
  • /nowrap
  • /ptt
  • /tgtdeleg
  • /opsec

Frequently asked about Kerberos Ticket Forging

  • What else does blacklanternsecurity publish alongside Kerberos Ticket Forging?

    Kerberos Ticket Forging is one of 25 skills that DirSkills catalogs from blacklanternsecurity/red-run, the repository it ships in. Its siblings there include AD Persistence, ADCS Persistence and ADCS Template Abuse. Each one is a separate skill with its own page in this directory, installs the same way Kerberos Ticket Forging does, and is maintained by blacklanternsecurity in that same repository. The rest of the collection is listed on the blacklanternsecurity/red-run page.

  • How does Kerberos Ticket Forging compare to other Automation skills?

    Kerberos Ticket Forging ranks #1385 by stars among the 1648 Automation skills in this catalog. The most-starred ones next to it are Autonomous Loops, Autonomous Agent Harness and Automation Audit Ops. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Kerberos Ticket Forging against them. Open each page to compare what they document and how they install.

More from blacklanternsecurity/red-run

Kerberos Ticket Forging is one of 25 skills cataloged on DirSkills from blacklanternsecurity/red-run.

See all 25 skills β†’
πŸͺͺ
1h ago

AD Persistence

AD Persistence documents post-compromise techniques for maintaining access in Active Directory after domain admin access. It covers methods like DCShadow, Golden SAML, SID history, certificate persistence, and security descriptor backdoors.
Automation
26637
πŸͺͺ
1h ago

ADCS Persistence

ADCS Persistence establishes long-lived access through AD CS certificate abuse and weak certificate mapping. It is used for Golden Certificates, ESC9/10, altSecIdentities, certificate theft, and related persistence techniques.
AI Engineering
26637
πŸͺͺ
1h ago

ADCS Template Abuse

ADCS Template Abuse exploits misconfigured AD CS certificate templates and CA flags to impersonate domain users with certificates. Use it during authorized assessments to enumerate ESC1, ESC2, ESC3, and ESC6 paths.
AI Engineering
26637
πŸ›‘οΈ
1h ago

AV EDR Evasion

AV EDR Evasion covers payload compilation and runtime bypass methods when antivirus or endpoint protection blocks execution. Use it to build alternate DLL, EXE, script, AMSI, or ETW-based payloads for an authorized engagement.
AI Engineering
26637
πŸ”
1h ago

Acl Abuse

Acl Abuse exploits misconfigured Active Directory ACLs for privilege escalation. It is used to abuse rights like GenericAll, WriteDACL, shadow credentials, SPN manipulation, and password reset paths.
Automation
26637
πŸ—ΊοΈ
1h ago

Ad Discovery

Ad Discovery enumerates Active Directory domains to map hosts, signing settings, and attack paths during authorized testing. It supports unauthenticated and credentialed reconnaissance and records findings for orchestration.
Automation
26637