mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-08-01 16:47:42 +03:00
Initial commit - 611 cybersecurity skills across all subdomains
This commit is contained in:
@@ -0,0 +1,23 @@
|
||||
# Standards — Active Directory Penetration Testing
|
||||
|
||||
## Key Frameworks
|
||||
- MITRE ATT&CK for Enterprise: https://attack.mitre.org/matrices/enterprise/
|
||||
- ANSSI AD Security Guide: https://www.cert.ssi.gouv.fr/uploads/guide-ad.html
|
||||
- Microsoft Tiered Administration Model: https://learn.microsoft.com/en-us/security/privileged-access-workstations/privileged-access-access-model
|
||||
|
||||
## MITRE ATT&CK Techniques for AD Testing
|
||||
|
||||
| Technique | ID | Description |
|
||||
|-----------|----|-------------|
|
||||
| Kerberoasting | T1558.003 | Steal Kerberos TGS tickets for offline cracking |
|
||||
| AS-REP Roasting | T1558.004 | Target accounts without pre-auth |
|
||||
| DCSync | T1003.006 | Replicate domain credentials via DRSUAPI |
|
||||
| Golden Ticket | T1558.001 | Forge TGT using krbtgt hash |
|
||||
| Pass-the-Hash | T1550.002 | Authenticate using NTLM hash |
|
||||
| Unconstrained Delegation | T1558 | Abuse delegation to steal TGTs |
|
||||
| ADCS Abuse | T1649 | Exploit misconfigured certificate templates |
|
||||
|
||||
## AD Security Benchmarks
|
||||
- CIS Microsoft Windows Server Benchmark
|
||||
- STIG (Security Technical Implementation Guide) for Windows
|
||||
- Microsoft Security Compliance Toolkit
|
||||
@@ -0,0 +1,36 @@
|
||||
# Workflows — Active Directory Penetration Testing
|
||||
|
||||
## AD Attack Flow
|
||||
|
||||
```
|
||||
Domain User Credentials
|
||||
│
|
||||
├── Enumeration
|
||||
│ ├── BloodHound (attack paths)
|
||||
│ ├── LDAP queries (users, groups, GPOs)
|
||||
│ └── Service account discovery (SPNs)
|
||||
│
|
||||
├── Kerberos Attacks
|
||||
│ ├── Kerberoasting → Hash cracking
|
||||
│ ├── AS-REP Roasting → Hash cracking
|
||||
│ └── Delegation abuse (unconstrained/constrained/RBCD)
|
||||
│
|
||||
├── ADCS Attacks
|
||||
│ ├── ESC1-ESC8 template exploitation
|
||||
│ └── Certificate-based auth to DA
|
||||
│
|
||||
├── Credential Harvesting
|
||||
│ ├── LSASS dump (Mimikatz)
|
||||
│ ├── SAM/SYSTEM extraction
|
||||
│ └── DPAPI credential decryption
|
||||
│
|
||||
├── Domain Escalation
|
||||
│ ├── DCSync (krbtgt + all hashes)
|
||||
│ ├── Golden Ticket
|
||||
│ └── AdminSDHolder persistence
|
||||
│
|
||||
└── Impact Demonstration
|
||||
├── Full domain hash extraction
|
||||
├── Access to sensitive resources
|
||||
└── Cross-forest trust abuse
|
||||
```
|
||||
Reference in New Issue
Block a user