feat(agents): deep Active Directory suite — 25 host/infra skills + 7 AD chains

Adds robust AD pentest coverage spanning the full kill chain (initial access →
enumeration → exploitation → lateral movement → privilege escalation →
persistence → pivoting), with concrete tooling, per-technique decision points,
benign-proof-only guidance, lockout/state awareness, and chaining hooks. All
GENERIC — no lab-specific hosts/IPs/creds/flags; works in any AD environment.

New infra/ skills: ad_recon_enum, ad_bloodhound_paths, ad_llmnr_poisoning,
ad_ntlm_relay, ad_password_spray, ad_kerberos_delegation, ad_adcs_esc,
ad_pth_ptt, ad_coerce_auth, ad_critical_cve (Zerologon/noPac), ad_smb_share_hunt,
ad_laps_gmsa_read, ad_gpo_abuse, ad_dpapi_looting, ad_trust_abuse,
ad_persistence_review, ad_mssql_abuse. Enriched: ad_kerberoasting, ad_asreproasting,
ad_dcsync, ad_acl_privesc, ad_default_creds, windows_priv_esc.

New chains/: chain_ad_web_to_forest_root, chain_ad_rbcd_s4u_to_adcs,
chain_ad_coerce_relay_adcs, chain_ad_kerberoast_to_domain,
chain_ad_mssql_linked_pivot, chain_ad_trust_cross_forest, chain_ad_local_to_domain.

attack_graph: map CWE-294/295/1392/269 to OWASP/MITRE/stage + CVSS bands so AD
findings grade and place in the kill chain correctly. 473 agents, 421 tests.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 4.8 committed 2026-10-03 01:08:57 -03:00
1 parent 8051464a84
commit 7741290193
32 files changed
+1479 -86

No files matched your search

@@ -52,6 +52,11 @@ fn map_cwe(cwe: &str) -> (&'static str, &'static str, &'static str) {
434 => ("A04:2021-Insecure-Design", "T1505.003", "execution"),
1321 | 915 => ("A08:2021-Software-Data-Integrity", "T1059", "execution"),
400 | 770 | 1333 | 799 => ("A04:2021-Insecure-Design", "T1499", "impact"),
// AD: capture-replay auth (NTLM relay/LLMNR/coercion), cert abuse (AD CS), default creds, privilege mgmt.
294 => ("A07:2021-Auth-Failures", "T1557", "credential-access"),
295 => ("A07:2021-Auth-Failures", "T1649", "credential-access"),
1392 => ("A07:2021-Auth-Failures", "T1078", "initial-access"),
269 => ("A01:2021-Broken-Access-Control", "T1068", "privesc"),
_ => ("A04:2021-Insecure-Design", "T1190", "initial-access"),
}
}
@@ -331,6 +336,9 @@ pub fn cvss_graded(f: &Finding) -> Option<crate::cvss::Graded> {
1021 => ("N", "L", "N", Scope::Unchanged),
113 | 93 | 644 => ("L", "L", "N", Scope::Unchanged),
525 | 524 => ("L", "N", "N", Scope::Unchanged),
294 | 295 => ("H", "H", "N", Scope::Changed),
1392 => ("H", "H", "N", Scope::Unchanged),
269 => ("H", "H", "H", Scope::Changed),
_ => ("L", "N", "N", Scope::Unchanged),
};
let authenticated = f.auth_context.eq_ignore_ascii_case("authenticated") || !f.account.is_empty();