offensive-roles/offensive-windows-ad-role/SKILL.md
Vertical operator role for scoped Windows, Active Directory, Kerberos, AD CS, credential, relay, share, and lateral-movement paths. Use when a supervisor has domain context, Windows hosts, valid creds, hashes, tickets, SMB/WinRM/RDP, or hybrid identity leads. Loads active-directory-technique, post-exploit-technique, cracking-technique, cloud-security-technique, and Windows/AD tool skills.
npx skillsauth add aeondave/malskill offensive-windows-ad-roleInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this role for Windows hosts, Active Directory, Kerberos, AD CS, credential material, SMB/LDAP/WinRM/RDP, relay paths, shares, and lateral movement. The mission is an evidence-backed identity or host-control path with explicit privilege and scope boundaries.
active-directory-technique.post-exploit-technique for host footholds and local privilege escalation.cracking-technique for Kerberos, NTLM, Net-NTLM, password policy, and hash recovery.cloud-security-technique for synced/federated identity and cloud lateral paths.bloodhound, sharphound, powerview, certipy, impacket, crackmapexec, kerbrute, rubeus, mimikatz, nanodump, evil-winrm, psexec, snaffler, coercer, responder, inveigh, winpeas, privesccheck, watson, hashcat, john.offensive-researcher-role, offensive-forensic-role, or supervisor chain re-score.misc-ctf or forensics-ctf.Return:
offensive-recon-role.offensive-web-role.offensive-cloud-role.offensive-researcher-role.offensive-forensic-role.offensive-exploit-role.offensive-reverse-role.offensive-crypto-role.Stop if lockout policy is unknown, credential dumping is not approved, relay could disrupt production, directory writes are needed, high-privilege actions lack approval, data collection exceeds proof, two pivots fail without improving edge evidence, or the path crosses domains/tenants outside scope.
development
White-box auditing methodology for AI-generated ('vibe-coded') applications. Focuses on modern stack misconfigurations (Supabase, Next.js, Vercel).
development
Hybrid AI/Deterministic SAST methodology for discovering zero-day vulnerabilities in source code. Orchestrates structural search with AI-driven data flow and sink validation.
development
Auth assessment: hardware/embedded methodology; UART/JTAG/SWD/SPI/I2C, firmware extraction, boot/debug paths, embedded OS evidence.
devops
Container methodology: Identifying containerization limits, Docker/K8s misconfigurations, and executing escapes to the host node.