# bloodyAD

> Use this tool when you need to perform Active Directory penetration testing and enumeration, solving problems such as vulnerability assessment and privilege escalation. It takes input through various authentication methods, including Kerberos, and outputs results from 26 specialized tools covering reconnaissance, privilege escalation, and object manipulation. Use it in controlled lab environments, such as HackTheBox, to streamline AI-assisted Active Directory attack workflows.

Canonical page: https://skillsregistry.net/skills/dcollaoa-bloodyad  
JSON: https://api.skillsregistry.net/v1/skills/dcollaoa-bloodyad

## Description

This bloodyAD MCP server by Diego Collao Albornoz provides Active Directory penetration testing and enumeration capabilities through a Docker-containerized wrapper around the bloodyAD tool. Built with FastMCP and running on Kali Linux in Docker, it offers 26 specialized tools covering AD reconnaissance (object enumeration, DNS dumping, trust mapping), privilege escalation (DCSync rights, shadow credentials, RBCD), and object manipulation (user/computer creation, group membership management, password changes) with support for various authentication methods including Kerberos. The implementation includes comprehensive setup automation scripts for Windows, Linux, and macOS that handle Docker image building, MCP configuration, and Gemini CLI integration, making it valuable for penetration testers and red team operators who need AI-assisted Active Directory attack workflows within controlled lab environments like HackTheBox.

## Trust

- **Trust score (0–1):** 0.94
- **Verification tier:** verified
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** cloud-infra
- **Updated:** 2026-09-28

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/dcollaoa-bloodyad)
- **Repository:** <https://github.com/dcollaoa/bloodyad_mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "dcollaoa-bloodyad"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/dcollaoa-bloodyad` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/dcollaoa-bloodyad/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
