tag

active-directory

26 indexed skills · max 10 per page

skills (26)

detecting-pass-the-ticket-attacks

mukul975/Anthropic-Cybersecurity-Skills · detecting-pass-the-ticket-attacks

0

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM

detecting-dcsync-attack-in-active-directory

mukul975/Anthropic-Cybersecurity-Skills · detecting-dcsync-attack-in-active-directory

0

Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes by monitoring for non-domain-controller accounts requesting directory replication via DsGetNCChanges.

performing-active-directory-vulnerability-assessment

mukul975/Anthropic-Cybersecurity-Skills · performing-active-directory-vulnerability-assessment

0

Assess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations, privilege escalation paths, and attack vectors.

performing-active-directory-forest-trust-attack

mukul975/Anthropic-Cybersecurity-Skills · performing-active-directory-forest-trust-attack

0

Enumerate and audit Active Directory forest trust relationships using impacket for SID filtering analysis, trust key extraction, cross-forest SID history abuse detection, and inter-realm Kerberos ticket assessment.

exploiting-constrained-delegation-abuse

mukul975/Anthropic-Cybersecurity-Skills · exploiting-constrained-delegation-abuse

0

Exploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users via S4U2self and S4U2proxy extensions for lateral movement and privilege escalation.

performing-active-directory-bloodhound-analysis

mukul975/Anthropic-Cybersecurity-Skills · performing-active-directory-bloodhound-analysis

0

Use BloodHound and SharpHound to enumerate Active Directory relationships and identify attack paths from compromised users to Domain Admin.

detecting-golden-ticket-attacks-in-kerberos-logs

mukul975/Anthropic-Cybersecurity-Skills · detecting-golden-ticket-attacks-in-kerberos-logs

0

Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs.

performing-active-directory-compromise-investigation

mukul975/Anthropic-Cybersecurity-Skills · performing-active-directory-compromise-investigation

0

Investigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateral movement paths.

analyzing-active-directory-acl-abuse

mukul975/Anthropic-Cybersecurity-Skills · analyzing-active-directory-acl-abuse

0

Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and WriteOwner abuse paths

performing-kerberoasting-attack

mukul975/Anthropic-Cybersecurity-Skills · performing-kerberoasting-attack

0

Kerberoasting is a post-exploitation technique that targets service accounts in Active Directory by requesting Kerberos TGS (Ticket Granting Service) tickets for accounts with Service Principal Names

prevpage 1 / 3next