ADScanPro/Claude-AD

Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay, delegation), with per-technique OPSEC/telemetry notes. Drives netexec, impacket, certipy, bloodyAD, BloodHound CE.

141Stars on the repository
15Mods indexed here, across every type
8d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

acl-abuse

01

ADScanPro/Claude-AD

Skill Claude CodeCodex

Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbound control edge from a principal you…

141 +4 8d ago A 120 tokens original MIT

ADScanPro/Claude-AD

Skill Claude CodeCodex

Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding requiring LDAPS on 636, Kerberos clock skew (KRBAPERRSKEW), SPNs that must be FQDNs never short names or IPs (the…

141 +4 8d ago B 183 tokens original MIT

ad-methodology

03

ADScanPro/Claude-AD

Skill Claude CodeCodex

The order of operations for an Active Directory penetration test: setup, collection, exploitation, post-processing. Use this whenever you are planning or driving an AD assessment and need to know what to run before what and why (map before you exploit; harvest easy credentials before spraying to avoid lockouts…

141 +4 8d ago B 125 tokens original MIT

ad-opsec-telemetry

04

ADScanPro/Claude-AD

Skill Claude CodeCodex

The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the DS-Replication-Get-Changes GUID, AS-REP roasting produces Event 4768 with no pre-auth, LSASS dumping is blocked by EDR…

141 +4 8d ago C 171 tokens original MIT

adcs-attacks

05

ADScanPro/Claude-AD

Skill Claude CodeCodex

Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k). Use when the target runs a Certificate Authority and you want to find vulnerable certificate templates or CA misconfigurations, request a certificate that impersonates a privileged user, and know…

141 +4 8d ago A 104 tokens original MIT

coercion-ntlm-relay

06

ADScanPro/Claude-AD

Skill Claude CodeCodex

Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB. Use when SMB signing is not enforced or LDAP channel binding is missing, and you want to force a privileged machine account to…

141 +4 8d ago A 131 tokens original MIT

compliance-mapping

07

ADScanPro/Claude-AD

Skill Claude CodeCodex

A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch. Kerberoasting relates to authentication and logging, so it brushes ENS op.acc.5 / op.exp.8, NIS2 Art.21(2)(h), DORA RTS Art.9 / Art.21. Use this when a reader wants to understand which regulatory control an…

141 +4 8d ago A 159 tokens original MIT

kerberos-attacks

08

ADScanPro/Claude-AD

Skill Claude CodeCodex

Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD). Use when the target has SPN-bearing service accounts, accounts without pre-authentication, or delegation configured on computer/user objects, and…

141 +4 8d ago B 105 tokens original MIT