autopilot
01Evaluris-Solutions/claude-active-directory
Command
Phased autonomous checklist for AD engagements within ROE — not unsupervised internet-wide scanning. Usage: /autopilot corp.local --normal.
AI agent harness for Active Directory offensive security — 8 skill domains, 13 slash commands, 7 agents, ROE-safe orchestration. Part of DoOS by Evaluris Solutions Labs.
Evaluris-Solutions/claude-active-directory
Command
Phased autonomous checklist for AD engagements within ROE — not unsupervised internet-wide scanning. Usage: /autopilot corp.local --normal.
Evaluris-Solutions/claude-active-directory
Command
Build multi-hop Active Directory attack paths — combine AS-REP, Kerberoast, delegation, ACL abuse, AD CS, lateral steps into one narrative. Usage: /chain.
Evaluris-Solutions/claude-active-directory
Command
Active Directory offensive phase — credential attacks (spray if allowed), AS-REP and Kerberoast workflows, NTLM relay opportunities, delegation abuse paths, ACL-based escalation, AD CS template abuse, lateral movement within ROE. Usage: /hunt corp.local.
Evaluris-Solutions/claude-active-directory
Command
Domain controller and Windows Server build intel — patch level, known abuse techniques relevant to version, planning prioritization. Usage: /intel corp.local.
Evaluris-Solutions/claude-active-directory
Command
Active Directory reconnaissance — DNS SRV/LDAP DC discovery, LDAP user and group enumeration, Kerberos pre-auth and AS-REP candidates, SPN discovery for Kerberoasting, SMB signing and null session policy, password policy, trust relationships, BloodHound/SharpHound collection prep. Requires ROE. Usage: /recon…
Evaluris-Solutions/claude-active-directory
Command
Log a technique, finding, or pattern to engagement memory for later reuse. Usage: /remember.
Evaluris-Solutions/claude-active-directory
Command
Generate internal penetration test / red team report structure for Active Directory engagements — executive summary, scope, methodology, findings, remediation. Usage: /report.
Evaluris-Solutions/claude-active-directory
Command
Resume a previous Active Directory engagement — read journal, recon folder, and untested paths. Usage: /resume corp.local.
Evaluris-Solutions/claude-active-directory
Command
Rules of engagement — verify authorized domains, DCs, subnets, accounts, destructive actions, and exclusions before testing. Usage: /scope or /scope corp.local.
Evaluris-Solutions/claude-active-directory
Command
Rank and prioritize Active Directory attack surface — high-value hosts, Tier-0 proximity, Kerberoastable accounts, AD CS CAs, delegation flags. Usage: /surface corp.local.
Evaluris-Solutions/claude-active-directory
Command
Quick go/no-go on a suspected AD finding before deep validation. Usage: /triage.
Evaluris-Solutions/claude-active-directory
Command
Validate an Active Directory finding for internal reporting — reproducibility, ROE, impact, evidence quality. Usage: /validate.
Evaluris-Solutions/claude-active-directory
Command
AD CS and PKI security review — enterprise CA inventory, certificate templates, enrollment permissions, ESC-pattern triage with Certipy-style methodology, optional web enrollment attack surface. Filename legacy; content is PKI only. Usage: /web3-audit or /web3-audit corp.local.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: