Claude Code instructions for Evaluris-Solutions/claude-active-directory, covering claude active directory — plugin guide, what's here, commands (13 slash commands — same filenames), agents (7) and rules (always active).
Claude Active Directory — authorized AD offensive security master skill. ROE, recon, Kerberos and NTLM, coercion awareness, delegation and ACL abuse, AD CS ESC1–ESC11, lateral movement, MITRE-ready validation and reporting. Evaluris Solutions, pentest, red team.
Use when Active Directory Certificate Services or PKI is in scope and templates, enrollment ACLs, CA endpoints, or ESC-pattern alignment need specialist review—typically alongside /web3-audit. Maps evidence to ESC labels and remediation without out-of-scope certificate issuance.
Use when an operator wants a phased checklist for an authorized AD engagement with explicit ROE checkpoints between recon, rank, hunt, validate, and report. Structures work; does not bypass human approval or /scope.
Use when several confirmed Active Directory primitives must be combined into one defensible multi-hop narrative for reporting or validation. Covers Kerberos, delegation, ACL abuse, AD CS, and lateral steps with evidence per hop. Does not invent hops that were not demonstrated.
Use when starting authorized Active Directory reconnaissance. Guides DNS SRV resolution, LDAP and RPC enumeration, Kerberos user and SPN discovery, password policy and spray gates, and BloodHound collection planning strictly within ROE. Does not perform credential attacks—that belongs to hunt workflows after scope…
Use when recon or BloodHound output exists and the operator needs a prioritized list of where to spend time next. Ranks Tier-0 proximity, Kerberoast density, delegation hints, AD CS presence, and stale accounts. Does not replace /scope or execute attacks.
Use when validated Active Directory findings must become a professional internal or red team report. Follows engagement-reporting structure for executive summary, scope, methodology, findings, and remediation. Assumes validator has PASS or agreed DOWNGRADE on included items.
Use when a single Active Directory finding needs QA before customer or management delivery. Applies evidence, ROE, impact, and false-positive gates from the finding-validation skill. Does not write full reports—that is report-writer after PASS.
Domain controller and Windows Server build intel — patch level, known abuse techniques relevant to version, planning prioritization. Usage: /intel corp.local.
Active Directory reconnaissance — DNS SRV/LDAP DC discovery, LDAP user and group enumeration, Kerberos pre-auth and AS-REP candidates, SPN discovery for Kerberoasting, SMB signing and null session policy, password policy, trust relationships, BloodHound/SharpHound collection prep. Requires ROE. Usage: /recon…
Generate internal penetration test / red team report structure for Active Directory engagements — executive summary, scope, methodology, findings, remediation. Usage: /report.
AD CS and PKI security review — enterprise CA inventory, certificate templates, enrollment permissions, ESC-pattern triage with Certipy-style methodology, optional web enrollment attack surface. Filename legacy; content is PKI only. Usage: /web3-audit or /web3-audit corp.local.
Use when selecting command patterns for authorized AD testing or when documenting OPSEC and defender-visible telemetry—NetExec/CrackMapExec, Impacket, Certipy, SharpHound, representative Windows Event IDs, and certificate enrollment logs. Use to enrich report appendices and kickoff expectations, not for EDR evasion…
Use when classifying or explaining authorized Active Directory attack techniques—Kerberos and NTLM paths, coercion awareness, delegation and RBCD, ACL and DCSync concepts, LAPS and shadow credentials, GPP, trust paths, AD-joined SQL pivots, and lateral movement by protocol. Use as a reference when writing findings or…