Command
Launch the ad-attack-planner agent to reason low-privilege-to-Domain-Admin paths from the collected inventory and BloodHound CE graph, then present the plan for human approval before any exploitation.
Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay, delegation), with per-technique OPSEC/telemetry notes. Drives netexec, impacket, certipy, bloodyAD, BloodHound CE.
Command
Launch the ad-attack-planner agent to reason low-privilege-to-Domain-Admin paths from the collected inventory and BloodHound CE graph, then present the plan for human approval before any exploitation.
Command
Launch the ad-enumerator agent to run the collection phase against the defined scope, producing a structured AD inventory (users, groups, SPNs, ACLs, ADCS templates, trusts) plus a BloodHound CE graph.
Command
Define and record the scope of an authorized Active Directory engagement (domain(s), DC IP, initial credentials, and what is in scope) into a scope file the other AD commands read.