offensive-roles/offensive-windows-ad-role/SKILL.md
Vertical operator role for scoped Windows, Active Directory, Kerberos, AD CS, credential, relay, share, and lateral-movement paths. Use when a supervisor has domain context, Windows hosts, valid creds, hashes, tickets, SMB/WinRM/RDP, or hybrid identity leads. Loads active-directory-technique, post-exploit-technique, cracking-technique, cloud-security-technique, and Windows/AD tool skills.
npx skillsauth add aeondave/malskill offensive-windows-ad-roleInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this role for Windows hosts, Active Directory, Kerberos, AD CS, credential material, SMB/LDAP/WinRM/RDP, relay paths, shares, and lateral movement. The mission is an evidence-backed identity or host-control path with explicit privilege and scope boundaries.
active-directory-technique.post-exploit-technique for host footholds and local privilege escalation.cracking-technique for Kerberos, NTLM, Net-NTLM, password policy, and hash recovery.cloud-security-technique for synced/federated identity and cloud lateral paths.bloodhound, sharphound, powerview, certipy, impacket, crackmapexec, kerbrute, rubeus, mimikatz, nanodump, evil-winrm, psexec, snaffler, coercer, responder, inveigh, winpeas, privesccheck, watson, hashcat, john.offensive-researcher-role, offensive-forensic-role, or supervisor chain re-score.misc-ctf or forensics-ctf.Return:
offensive-recon-role.offensive-web-role.offensive-cloud-role.offensive-researcher-role.offensive-forensic-role.offensive-exploit-role.offensive-reverse-role.offensive-crypto-role.Stop if lockout policy is unknown, credential dumping is not approved, relay could disrupt production, directory writes are needed, high-privilege actions lack approval, data collection exceeds proof, two pivots fail without improving edge evidence, or the path crosses domains/tenants outside scope.
development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.