active directory skills

63 tagged active directory, measured the same way as everything else here.

Browse within: cybersecurity 24active-directory-security 17privilege-escalation 16bloodhound 12adcs 9bug-bounty 9mimikatz 9ldap 8red-team 8acl-abuse 7ai-for-cybersecurity 7credential-access 7impacket 7kerberos 7

mukul975/Anthropic-Cybersecurity-Skills

Skill Claude CodeCodex

Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or Impacket's dpapi.py, including domain-wide decryption via the DPAPI backup key. Use during authorized red-team…

32k 8d ago A 97 tokens original Apache-2.0

m14r41/PentestingEverything

Skill Claude CodeCodex

Guides authorized penetration testing with PentestingEverything as the source-grounded knowledge base. Use when scoping an engagement, building domain checklists, hunting a vulnerability class, choosing tools/commands, or drafting evidence-based findings from this repository's Markdown.

2.1k 16d ago A 56 tokens original MIT

acl-abuse

03

ADScanPro/Claude-AD

Skill Claude CodeCodex

Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbound control edge from a principal you…

137 8d ago A 120 tokens original MIT

adcs-attacks

04

ADScanPro/Claude-AD

Skill Claude CodeCodex

Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k). Use when the target runs a Certificate Authority and you want to find vulnerable certificate templates or CA misconfigurations, request a certificate that impersonates a privileged user, and know…

137 8d ago A 104 tokens original MIT

coercion-ntlm-relay

05

ADScanPro/Claude-AD

Skill Claude CodeCodex

Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB. Use when SMB signing is not enforced or LDAP channel binding is missing, and you want to force a privileged machine account to…

137 8d ago A 131 tokens original MIT

redteam

06

ktol1/RedTeam-Agent

Skill Claude CodeCodex

RedTeam physical terminal execution skill. ONLY run using runinterminal. Use for network scan, lateral movement, etc.

67 4mo ago A 27 tokens

ad-attack-classes

07

Evaluris-Solutions/claude-active-directory

Skill Claude CodeCodex

Use when classifying or explaining authorized Active Directory attack techniques—Kerberos and NTLM paths, coercion awareness, delegation and RBCD, ACL and DCSync concepts, LAPS and shadow credentials, GPP, trust paths, AD-joined SQL pivots, and lateral movement by protocol. Use as a reference when writing findings or…

16 3mo ago A 85 tokens

ad-cs-pki

08

Evaluris-Solutions/claude-active-directory

Skill Claude CodeCodex

Use when triaging or reporting authorized Active Directory Certificate Services risk—enterprise CA inventory, template permissions, ESC1–ESC11 style labels from Certipy-style tools, DC certificate mapping and strong-binding evidence, web enrollment and RPC relay surfaces. Use with /web3-audit command content and…

16 3mo ago A 72 tokens

ad-recon

09

Evaluris-Solutions/claude-active-directory

Skill Claude CodeCodex

Use when performing or planning authorized Active Directory reconnaissance—DNS and DC SRV, forest and trust mapping, LDAP/LDAPS and signing posture, gMSA discovery, SMB signing, password policy and spray approval gates, Kerberos SPN and pre-auth discovery, BloodHound collection choice, and LDAP filter cookbook. Use…

16 3mo ago A 79 tokens

penetration-tester

10

chandrudp29/skillhub

Skill Claude CodeCodex

Authorized penetration tester persona — offensive security specialist for network, web app, cloud, and Active Directory assessments. Requires explicit authorization.

13 2mo ago A 30 tokens original MIT

ad-exploitation

11

DouglasRao/Claude-Pentest-Skills

Skill Claude CodeCodex

Active Directory exploitation skill — credential attacks, lateral movement, privilege escalation, and domain domination. Activate when the user wants to exploit an AD environment after enumeration, or mentions: Kerberoasting, AS-REP Roasting, pass-the-hash, pass-the-ticket, lateral movement, DCSync, Golden Ticket…

11 4mo ago A 111 tokens original MIT

ad-report

12

DouglasRao/Claude-Pentest-Skills

Skill Claude CodeCodex

Active Directory penetration testing report generation skill. Activate when the user wants to write, generate, or finalize a report for an AD pentest engagement. Consolidates outputs from ad-recon, ad-exploitation, and ad-postexploitation skills into a structured technical and executive report. Produces findings in…

11 4mo ago A 99 tokens original MIT

web-recon

13

DouglasRao/Claude-Pentest-Skills

Skill Claude CodeCodex

Full offensive reconnaissance skill for Web Pentest and Bug Bounty. Activate when the user mentions recon, reconnaissance, subdomain enumeration, attack surface mapping, bug bounty recon, or any variation of "start a pentest" on a domain/target. Covers: subdomain enumeration, DNS resolution, live detection…

11 4mo ago A 120 tokens original MIT

gpmc

14

stewartcelani/skills

Skill Claude CodeCodex

Read-only Active Directory Group Policy inventory via LDAP — list GPOs, show OU/site links (enabled/disabled/enforced), find unlinked GPOs, search by name, and gpresult for the current user. Use when the user asks about GPOs, Group Policy, GPMC, linked vs unlinked policies, RSoP, what applies to this user, or runs…

2 1mo ago A 115 tokens original MIT

spec-herdr-review

15

stewartcelani/skills

Skill Claude CodeCodex

Run visible multi-agent spec reviews in Herdr through interactive agent CLIs such as Claude, Codex, Copilot/GLM, or Grok/Composer. Supports two modes — a spec review (the design, before implementation) and an implementation review (the implemented diff vs the spec, after the calling model has built it). Ask for…

2 1mo ago A 88 tokens original MIT

spec

16

stewartcelani/skills

Skill Claude CodeCodex

Spec-driven development in the active repository's spec/{feature}/ directory. Use when user says /spec, "write a spec", "plan a feature", "create a PRD", "spec status", "spec out this epic", or references spec/ directory. Sizes work from small to epic, where an epic is a parent spec with numbered child specs.…

2 1mo ago A 83 tokens original MIT