Credential Theft skills
Free agent skills tagged credential theft, ready to install into any SKILL.md-compatible agent.
4 skills
Extracting Config from Agent Tesla RAT
mukul975
Automate extraction of Agent Tesla RAT configurations for analysis.
Detecting Pass-the-Ticket Attacks
mukul975
Identify and analyze Kerberos PtT attacks effectively.
Detecting Golden Ticket Forgery
mukul975
Identify forged Kerberos tickets in Active Directory.
Detecting DCSync Attack
Detect DCSync attacks (MITRE T1003.006) where adversaries abuse Active Directory replication privileges to extract password hashes, by auditing Event ID 4662 for the DS-Replication-Get-Changes GUIDs and flagging non-domain-controller accounts issuing DsGetNCChanges RPC calls. Use when hunting for credential theft via Mimikatz lsadump::dcsync or Impacket secretsdump, investigating lateral movement with domain admin credentials, or auditing AD replication permissions.
