An automated security assessment tool for mapping and validating Active Directory identity attack paths and privilege escalation routes.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install pentest-active-directory
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install pentest-active-directory using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
Pentest Active Directory is a robust security testing skill designed to systematically identify and validate vulnerabilities within Active Directory environments. By focusing on identity attack paths—such as Kerberoasting, NTLM relaying, and delegation abuse—this skill enables security professionals to discover how attackers might move laterally or escalate privileges in a network. As a core component of Openclaw Skills, it bridges the gap between raw data collection and actionable security intelligence.
The tool is built with a focus on compliance and safety, adhering to industry-standard frameworks like PTES and MITRE ATT&CK. It ensures that all testing is performed within a strictly defined scope, making it an essential asset for internal audits, red teaming exercises, and continuous security monitoring within complex corporate infrastructures.
To get started with this skill, ensure you have the necessary environment and authorization. Use the following command structure to initialize a dry run:
python skills/pentest-active-directory/scripts/active_directory.py --scope scope.json --target <target> --input <path> --output <path> --format json --dry-run
For live execution, the --i-have-authorization flag must be explicitly passed to comply with ethical security testing standards.
The skill generates structured artifacts to facilitate automated analysis and reporting within the Openclaw Skills ecosystem:
| File Name | Purpose |
|---|---|
ad-findings.json |
Contains technical details of vulnerabilities following the canonical finding schema. |
ad-attack-paths.json |
A graph-ready representation of privilege escalation and lateral movement routes. |
ad-report.json |
A synthesized summary of the assessment results for documentation. |
Loading
Orchestrate authorized Nmap host discovery, service enumeration, and automated security reporting.

A technical tool for producing consistent model rankings from metric-weighted evaluation inputs and deterministic benchmarking logic.

A standardized framework for planning and documenting reproducible machine learning experiments before training begins.

A specialized tool for designing secure, scope-aware automation plans for Gmail, Drive, Sheets, and Calendar.

A professional security testing skill designed to enumerate and audit API endpoints against the OWASP API Security Top 10.

A specialized security testing skill designed to identify authentication bypass vulnerabilities and account takeover risks.








































