Evaluris-Solutions/claude-active-directory

AI agent harness for Active Directory offensive security — 8 skill domains, 13 slash commands, 7 agents, ROE-safe orchestration. Part of DoOS by Evaluris Solutions Labs.

16Stars on the repository
30Mods indexed here, across every type
4mo agoLast push, which is what freshness is scored on
customA LICENSE file GitHub cannot name, so bodies are not copied

active-directory

01

Evaluris-Solutions/claude-active-directory

Skill Claude CodeCodex

Claude Active Directory — authorized AD offensive security master skill. ROE, recon, Kerberos and NTLM, coercion awareness, delegation and ACL abuse, AD CS ESC1–ESC11, lateral movement, MITRE-ready validation and reporting. Evaluris Solutions, pentest, red team.

not rated 16 4mo ago A 62 tokens

ad-arsenal

02

Evaluris-Solutions/claude-active-directory

Skill Claude CodeCodex

Use when selecting command patterns for authorized AD testing or when documenting OPSEC and defender-visible telemetry—NetExec/CrackMapExec, Impacket, Certipy, SharpHound, representative Windows Event IDs, and certificate enrollment logs. Use to enrich report appendices and kickoff expectations, not for EDR evasion…

not rated 16 4mo ago A 70 tokens

ad-attack-classes

03

Evaluris-Solutions/claude-active-directory

Skill Claude CodeCodex

Use when classifying or explaining authorized Active Directory attack techniques—Kerberos and NTLM paths, coercion awareness, delegation and RBCD, ACL and DCSync concepts, LAPS and shadow credentials, GPP, trust paths, AD-joined SQL pivots, and lateral movement by protocol. Use as a reference when writing findings or…

not rated 16 4mo ago A 85 tokens

ad-cs-pki

04

Evaluris-Solutions/claude-active-directory

Skill Claude CodeCodex

Use when triaging or reporting authorized Active Directory Certificate Services risk—enterprise CA inventory, template permissions, ESC1–ESC11 style labels from Certipy-style tools, DC certificate mapping and strong-binding evidence, web enrollment and RPC relay surfaces. Use with /web3-audit command content and…

not rated 16 4mo ago A 72 tokens

ad-methodology

05

Evaluris-Solutions/claude-active-directory

Skill Claude CodeCodex

Use when planning or unblocking an authorized Active Directory assessment—phasing work, choosing which skill to open next, routing when stuck (no creds, empty BH graph, SQL in scope), or aligning deliverables with MITRE-ready reporting. Covers session discipline, optional read-only baselines, and tool routing. Does…

not rated 16 4mo ago A 76 tokens

ad-pentest

06

Evaluris-Solutions/claude-active-directory

Skill Claude CodeCodex

Use when orchestrating an authorized Active Directory offensive assessment from ROE check through recon, credentials, escalation, lateral movement, AD CS, validation, and reporting. Anchors the engagement in evidence, /scope, BloodHound-style path reasoning, hybrid-identity context, and MITRE-ready deliverables.…

not rated 16 4mo ago A 77 tokens

ad-recon

07

Evaluris-Solutions/claude-active-directory

Skill Claude CodeCodex

Use when performing or planning authorized Active Directory reconnaissance—DNS and DC SRV, forest and trust mapping, LDAP/LDAPS and signing posture, gMSA discovery, SMB signing, password policy and spray approval gates, Kerberos SPN and pre-auth discovery, BloodHound collection choice, and LDAP filter cookbook. Use…

not rated 16 4mo ago A 79 tokens

Evaluris-Solutions/claude-active-directory

Skill Claude CodeCodex

Use when writing or restructuring internal Active Directory penetration test or red team reports after findings exist. Guides executive summary, scope, AD-specific object fields, optional MITRE ATT&CK columns, evidence bundles, remediation, and narrative severity. Third-person reporting tone for Evaluris-style…

not rated 16 4mo ago A 61 tokens

finding-validation

09

Evaluris-Solutions/claude-active-directory

Skill Claude CodeCodex

Use when validating an Active Directory finding before client or management delivery, or when triaging BloodHound edges, Kerberoast lists, or AD CS template visibility for false positives. Covers seven-question gates, AD-specific KILL/DOWNGRADE rules, narrative severity, and optional MITRE ATT&CK mapping. Improves…

not rated 16 4mo ago A 73 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: