Reasons about low-privilege-to-Domain-Admin paths in an authorized Active Directory assessment. Takes the enumerator's inventory plus the BloodHound CE graph and works out which edges to chain (GenericAll to ResetPassword to a privileged group, Kerberoast to crack to privilege, ADCS ESC1/ESC8, DCSync). It plans and…
Runs the COLLECTION phase of an authorized Active Directory assessment from a low-privilege domain account. Orchestrates standard tools (netexec/nxc, impacket, rusthound-ce or bloodhound-python, certipy) to enumerate users, groups, SPNs, interesting ACLs, ADCS templates and trusts, then returns a structured inventory…
Executes ONE exploitation step from an approved attack plan in an authorized Active Directory assessment, invoking the matching technique skill (kerberos-attacks, adcs-attacks, acl-abuse, coercion-ntlm-relay) with the standard tool. Always asks for human confirmation before any action that modifies the directory…
An AI-assisted framework for security testing that uses many penetration-testing tools through the Model Context Protocol, a standard way for agents to use external tools.
Use when Active Directory Certificate Services or PKI is in scope and templates, enrollment ACLs, CA endpoints, or ESC-pattern alignment need specialist review—typically alongside /web3-audit. Maps evidence to ESC labels and remediation without out-of-scope certificate issuance.
Use when starting authorized Active Directory reconnaissance. Guides DNS SRV resolution, LDAP and RPC enumeration, Kerberos user and SPN discovery, password policy and spray gates, and BloodHound collection planning strictly within ROE. Does not perform credential attacks—that belongs to hunt workflows after scope…
Use when validated Active Directory findings must become a professional internal or red team report. Follows engagement-reporting structure for executive summary, scope, methodology, findings, and remediation. Assumes validator has PASS or agreed DOWNGRADE on included items.