tag

active-directory

26 indexed skills · max 10 per page

skills (26)

exploiting-nopac-cve-2021-42278-42287

mukul975/Anthropic-Cybersecurity-Skills · exploiting-nopac-cve-2021-42278-42287

0

Exploit the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion) to escalate from standard domain user to Domain Admin in Active Directory environments.

detecting-golden-ticket-forgery

mukul975/Anthropic-Cybersecurity-Skills · detecting-golden-ticket-forgery

0

Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17), abnormal ticket lifetimes, and krbtgt account anomalies in Splunk and Elastic SIEM

exploiting-zerologon-vulnerability-cve-2020-1472

mukul975/Anthropic-Cybersecurity-Skills · exploiting-zerologon-vulnerability-cve-2020-1472

0

Exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controller compromise by resetting the machine account password to empty.

deploying-active-directory-honeytokens

mukul975/Anthropic-Cybersecurity-Skills · deploying-active-directory-honeytokens

0

Deploys deception-based honeytokens in Active Directory including fake privileged accounts with AdminCount=1, fake SPNs for Kerberoasting detection (honeyroasting), decoy GPOs with cpassword traps, and fake BloodHound paths. Monitors Windows Security Event IDs 4769, 4625, 4662, 5136 for honeytoken interaction. Use when implementing AD deception defenses for detecting lateral movement, credential theft, and reconnaissance.

conducting-internal-reconnaissance-with-bloodhound-ce

mukul975/Anthropic-Cybersecurity-Skills · conducting-internal-reconnaissance-with-bloodhound-ce

0

Conduct internal Active Directory reconnaissance using BloodHound Community Edition to map attack paths, identify privilege escalation chains, and discover misconfigurations in domain environments.

configuring-active-directory-tiered-model

mukul975/Anthropic-Cybersecurity-Skills · configuring-active-directory-tiered-model

0

Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered administration model for Active Directory. Covers Tier 0/1/2 separation, privileged access workstations (PAWs), administrative f

prevpage 3 / 3next