active directory agents

11 tagged active directory, measured the same way as everything else here.

Browse within: active-directory-security 10cybersecurity 8

ad-attack-planner

01

ADScanPro/Claude-AD

Agent

Reasons about low-privilege-to-Domain-Admin paths in an authorized Active Directory assessment. Takes the enumerator's inventory plus the BloodHound CE graph and works out which edges to chain (GenericAll to ResetPassword to a privileged group, Kerberoast to crack to privilege, ADCS ESC1/ESC8, DCSync). It plans and…

137 8d ago A 96 tokens original MIT

ad-enumerator

02

ADScanPro/Claude-AD

Agent

Runs the COLLECTION phase of an authorized Active Directory assessment from a low-privilege domain account. Orchestrates standard tools (netexec/nxc, impacket, rusthound-ce or bloodhound-python, certipy) to enumerate users, groups, SPNs, interesting ACLs, ADCS templates and trusts, then returns a structured inventory…

137 8d ago B 87 tokens original MIT

ad-exploit-operator

03

ADScanPro/Claude-AD

Agent

Executes ONE exploitation step from an approved attack plan in an authorized Active Directory assessment, invoking the matching technique skill (kerberos-attacks, adcs-attacks, acl-abuse, coercion-ntlm-relay) with the standard tool. Always asks for human confirmation before any action that modifies the directory…

137 8d ago A 91 tokens original MIT

lucy

04

ktol1/RedTeam-Agent

Agent

An AI-assisted framework for security testing that uses many penetration-testing tools through the Model Context Protocol, a standard way for agents to use external tools.

67 4mo ago not scanned tokens not measured

ad-cs-auditor

05

Evaluris-Solutions/claude-active-directory

Agent

Use when Active Directory Certificate Services or PKI is in scope and templates, enrollment ACLs, CA endpoints, or ESC-pattern alignment need specialist review—typically alongside /web3-audit. Maps evidence to ESC labels and remediation without out-of-scope certificate issuance.

16 3mo ago A 60 tokens

recon-agent

06

Evaluris-Solutions/claude-active-directory

Agent

Use when starting authorized Active Directory reconnaissance. Guides DNS SRV resolution, LDAP and RPC enumeration, Kerberos user and SPN discovery, password policy and spray gates, and BloodHound collection planning strictly within ROE. Does not perform credential attacks—that belongs to hunt workflows after scope…

16 3mo ago A 62 tokens

report-writer

07

Evaluris-Solutions/claude-active-directory

Agent

Use when validated Active Directory findings must become a professional internal or red team report. Follows engagement-reporting structure for executive summary, scope, methodology, findings, and remediation. Assumes validator has PASS or agreed DOWNGRADE on included items.

16 3mo ago A 52 tokens