LogoClawIndex
CasesSkillsAbout
LogoClawIndex

pentesting-freeipa - FreeIPA Penetration Testing Tool

Enumerates and attacks FreeIPA domains with LDAP enumeration, Kerberos ticket abuse, and delegation analysis

Tags

Updated: 2026-06-30

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • enumerate LDAP anonymously
  • enumerate LDAP with GSSAPI
  • obtain Kerberos tickets
  • reuse CCACHE tickets
  • extract TGT from keytab
  • analyze HBAC rules
  • analyze sudo rules
  • enumerate users
  • enumerate groups
  • enumerate hosts
  • dump password hashes
  • build attack graph
  • query delegation paths
  • write certificates
  • impersonate users
  • extract tickets from keyring

Inputs

  • FreeIPA server address
  • Kerberos realm
  • host keytab
  • CCACHE ticket
  • password
  • IPA credentials

Outputs

  • LDAP directory data
  • attack path graph
  • password hashes
  • user lists
  • HBAC rules
  • sudo rules
  • delegation attributes
  • certificates

Requirements

  • authorized penetration testing environment
  • Kerberos client tools
  • LDAP client tools
  • Neo4j for IPAHound graphing

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
freeipa
ldap
kerberos
penetration-testing
hbac
delegation
linux
authentication
identity-management
ipv4
enumerate LDAP anonymously
enumerate LDAP with GSSAPI
obtain Kerberos tickets
reuse CCACHE tickets
FreeIPA server address
Kerberos realm
host keytab
LDAP directory data
attack path graph
password hashes