{"slug":"exploiting-nopac-cve-2021-42278-42287","source_name":"exploiting-nopac-cve-2021-42278-42287","name":"Exploiting Nopac Cve 2021 42278 42287","description":"Exploit the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion) to escalate from standard domain user to Domain Admin in Active Directory environments.","version":1,"lift":{"pass_rate_delta_pts":36.36,"pass_rate_pct":36.4,"total_cases":22,"passed_cases":8,"tokens_delta_pct":88.8,"turns_delta_pct":0,"verdict":"mixed","benchmark_model":"gemini-3.6-flash","grading_method":"judged","completed_at":"2026-07-28T08:28:49.013397+00:00"},"skill_score":0.3636,"benchmark_models":[{"model":"gemini-3.6-flash","headline":true,"delta_pts":36.36,"with_pass_pct":36.4,"without_pass_pct":0,"tokens_delta_pct":88.8,"turns_delta_pct":0,"total_cases":22,"cases_aggregated":21,"verdict":"mixed","never_hurt":true,"completed_at":"2026-07-28T08:28:49.013397+00:00","run_id":"44c926d6-a2ed-4fc8-b809-0a5bf862693d","version_number":1,"is_latest_version":true,"gate":null}],"trust":{"skill_safety":"passed","safety_status":"clean","intent_verdict":null,"content_status":"clean","indexable":true},"license":"Apache-2.0","install_count":0,"manifest_hash":"b27155f04023cced3159cc0df9f4de202885820cbdb97fe0c480b84ad268cb7f","raw_url":"https://app.decimal.ai/s/exploiting-nopac-cve-2021-42278-42287/SKILL.md","scorecard_url":"https://app.decimal.ai/skills/exploiting-nopac-cve-2021-42278-42287"}