Active Directory exploitation after domain credentials exist: Kerberos (AS-REP/Kerberoast including cracking the ticket then using the account), delegation, NTLM coercion/relay, lateral movement, ACL abuse, ADCS ESC1-ESC17 and CVE paths, dMSA/BadSuccessor, Kerberos reflection, identity confusion, management-plane, domain trust, and domain persistence. Own the current AD chain through crack-and-use to DA, equivalent domain control, or the targeted host SYSTEM. Do not stop after requesting TGS. Host C2 belongs to /post. Operator chooses next modules.
日本語の概要は準備中です。原文の説明を表示しています。
pale-knight/redteam-skill☆ 492026年8月23日 更新
Active Directory reconnaissance with or without credentials: user/group/computer enumeration, ACL/delegation, ADCS, modern Windows LAPS, BloodHound, Server 2025/dMSA/Ghost SPN candidates, and trust mapping. Recon only — do not exploit Kerberoast-to-DA, DCSync, or change passwords. Operator may select /ad-attack after cards are ready.
日本語の概要は準備中です。原文の説明を表示しています。
pale-knight/redteam-skill☆ 492026年8月23日 更新
CI/CD pipeline and software-supply-chain exploitation: Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps, Gitea/Forgejo, self-hosted runners/agents, poisoned pipeline execution, artifact/cache abuse, dependency confusion, third-party Action trust, GitOps/registry poisoning, workload identity/OIDC, and emerging agentic CI/CD. Use this skill when the operator has access to a CI/CD system, source repository, build/deploy configuration, runner/agent, artifact/package/registry path, or software delivery trust chain.
日本語の概要は準備中です。原文の説明を表示しています。
pale-knight/redteam-skill☆ 492026年8月23日 更新
Cloud control-plane exploitation for AWS, Azure/Entra, GCP, and Alibaba Cloud: IAM/RAM privilege escalation, impersonation, cross-account trust, serverless/compute control, and cloud-native persistence. Host OS persistence/C2 after root/SYSTEM belongs to /post. K8s RBAC belongs to /k8s. Operator chooses next modules; new identities default to /cloud-recon first.
日本語の概要は準備中です。原文の説明を表示しています。
pale-knight/redteam-skill☆ 492026年8月23日 更新
Cloud control-plane reconnaissance for AWS, Azure/Entra, GCP, and Alibaba Cloud: identity, IAM/RAM, trust, resources, metadata, and managed-Kubernetes cloud-side boundary. Recon only — no policy changes, no privilege escalation. Operator may select /cloud-attack or /k8s.
日本語の概要は準備中です。原文の説明を表示しています。
pale-knight/redteam-skill☆ 492026年8月23日 更新
Credential operations: secret discovery, classification, extraction, conversion, offline cracking of hashes the operator already has as a credential job, policy-aware spraying, NetNTLM capture, generic SMB relay, and Windows/Linux harvest. Do not hijack an in-progress /ad-attack Kerberoast/AS-REP chain (that module cracks and uses the ticket itself). Do not DCSync, read LAPS LDAP, or escalate cloud IAM. Usable credentials are recorded; the operator chooses the next module.
日本語の概要は準備中です。原文の説明を表示しています。
pale-knight/redteam-skill☆ 492026年8月23日 更新