⏳ This skill is pending AI review.

Scores will appear once the review pipeline completes.

version unknown

active-directory-attack

@hypnguyen1209⭐ 385 stars

Use when attacking a Windows Active Directory domain — Kerberos roasting/delegation, coercion + NTLM/Kerberos relay (CVE-2025-33073), ADCS ESC1-16 (EKUwu), ticket forgery & DCSync, dMSA BadSuccessor (CVE-2025-53779), BloodHound attack-path enumeration, domain dominance

Choose how to use this skill

You do not need every option. Choose the path your AI client supports. The stable page stays the same; versioned files are immutable.

1. Native installer

This listing has no registered native installer command. Use the complete package or source fallback below, depending on what your client supports.

Do not guess an installer command or replace an existing version without reviewing the diff.

2. Complete package recommended

Download the ZIP when available. It includes SKILL.md plus the references, security notes and version metadata.

No complete ProSkills package is published for this listing yet.

3. Prompt-only

Copy the prompt above when the agent can read the stable page or when you want to adopt the workflow without installing a skill.

Need only the instruction file?

Download SKILL.md only if your client requires a single file. The complete ZIP is safer for a full installation because it preserves the references and release context.

No path installs or executes anything by itself. Your agent still needs access to the project files. Before updating, compare the installed version and review the diff.

—/10

// RATINGS

⭐GitHub Stars
⭐⭐⭐ 385 on GitHubGitHub ↗

Popular

🟢ProSkills Score
—
📍

Not yet listed on ClawHub or SkillsMP

// README

Offensive Security Research Config for Claude Code

A spec-driven offensive security framework for Claude Code — structured engagement workflows based on the Cyber Kill Chain, 32 kill-chain skills (multi-file progressive-disclosure) plus a discipline layer (a SessionStart dispatcher + 6 process/discipline skills), 8 collaborative agents, and a shared 47-file vulnerability reference library. Inspired by GitHub's spec-kit, obra/superpowers, and gadievron/raptor (crash→exploitability + OSS-repo forensics).

Quick Setup

# Method 0: Install as a Claude Code plugin (recommended — auto-loads the skill dispatcher)
/plugin marketplace add hypnguyen1209/offensive-claude
/plugin install offensive-claude@offensive-claude-marketplace

Installing as a plugin registers a SessionStart hook that injects the using-offensive-claude dispatcher into every conversation, so the skill-invocation discipline (scope → finding → OPSEC) is active from the first message.

# Method 1: One-liner install (recommended)
curl -sL https://raw.githubusercontent.com/hypnguyen1209/offensive-claude/main/install.sh | bash
# Method 2: Clone + install script
git clone https://github.com/hypnguyen1209/offensive-claude.git ~/offensive-claude
cd ~/offensive-claude && bash install.sh
# Method 3: Manual copy
git clone https://github.com/hypnguyen1209/offensive-claude.git ~/offensive-claude
cp -r ~/offensive-claude/skills ~/.claude/skills
cp -r ~/offensive-claude/agents ~/.claude/agents
cp -r ~/offensive-claude/templates ~/.claude/templates
cp -r ~/offensive-claude/workflows ~/.claude/workflows
cp -r ~/offensive-claude/commands ~/.claude/commands
cp -r ~/offensive-claude/presets ~/.claude/presets
cp ~/offensive-claude/CLAUDE.md ~/.claude/CLAUDE.md

Skills and agents activate automatically — no additional configuration needed.

Engagement Workflow

Engagements follow the Cyber Kill Chain as a structured 9-phase pipeline with quality gates:

Phase 0    Phase 1    Phase 2      Phase 3     Phase 4       Phase 5       Phase 6    Phase 7       Phase 8
SCOPE  →  RECON  →  WEAPONIZE →  DELIVERY →  EXPLOIT  →  INSTALLATION →   C2    →  ACTIONS ON →  REPORT
                                                                                    OBJECTIVES

Quick Start — Web App Pentest

/engage.init web-app --client ACME
/engage.scope                           # Define targets, ROE, authorization
/engage.recon                           # Subdomain enum, port scan, tech fingerprint
/engage.weaponize                       # Select exploits, design payloads
/engage.exploit                         # Execute exploits, document findings
/engage.report                          # Generate technical report + executive summary

Orchestration Commands

CommandPhaseAction
/engage.init <preset>—Initialize engagement with workflow preset
/engage.scope0Define targets, ROE, authorization
/engage.recon1Passive/active reconnaissance
/engage.weaponize2Payload development, exploit design
/engage.deliver3Delivery vector execution
/engage.exploit4Exploitation, finding documentation
/engage.install5Persistence establishment
/engage.c26C2 infrastructure setup
/engage.actions7Objectives execution, lateral movement
/engage.report8Report generation
/engage.status—Show pipeline status and progress
/engage.gate—Validate current phase gate
/engage.crash4Crash → root cause (rr) → reachability (gcov/trace) → empirical exploitability verdict
/engage.cvediff2,4Find a CVE's canonical fix commit(s) across sources, then scope-gated diff for root cause
/engage.scorecard—Calibrate model verdict trust (Wilson-bounded miss-rate) to short-circuit re-validation
/engage.threatmodel1Materialize / lint / drift-check the engagement threat model
/engage.memory—Recall prior patterns / record confirmed findings (cross-engagement learning)
/engage.pickup—Resume an engagement from the engine trace (skip completed steps)

Workflow Presets

PresetPhasesUse Case
web-app0,1,2,3,4,8OWASP-focused web application assessment
network0,1,2,4,5,6,7,8Internal network penetration test
red-teamALL (0-8)Full adversary simulation
cloud0,1,4,8AWS/Azure/GCP security audit
mobile0,1,2,4,8Android/iOS application pentest
ad-domain0,1,2,4,5,7,8Active Directory domain assessment
bug-bounty0,1,4,8Bug bounty vulnerability hunting

Quality Gates

Each phase transition validates:

  • Required artifacts exist (templates filled)
  • Findings have mandatory fields (CWE, CVSS, evidence, ATT&CK ID)
  • Gate PASS → suggests next phase + relevant skills
  • Gate FAIL → lists missing items

Structure

.
├── skills/                        # 32 skill modules (progressive-disclosure layout)
│   ├── recon-osint/
│   │   ├── SKILL.md               #   thin router: when-to-activate + technique map + OPSEC/detection
│   │   ├── references/            #   per-skill technique deep-dives (theory + code + detection + OPSEC)
│   │   └── scripts/               #   runnable tooling backing each technique
│   ├── coding-mastery/scripts/_lib/  # shared safety libs: scope_guard, action_guard, http_creds, redact_headers
│   ├── engagement-memory/         #   cross-engagement pattern-learning memory (support skill)
│   ├── using-offensive-claude/    #   SessionStart DISPATCHER — skill-invocation discipline
│   ├── engagement-flow/           #   process skills: sequence the kill chain,
│   ├── scope-discipline/          #   no target without authorization,
│   ├── threat-model-discipline/   #   model the attack surface + detect drift before exploiting,
│   ├── finding-discipline/        #   no [CONFIRMED] without proof,
│   ├── opsec-discipline/          #   detection/cleanup/redaction before acting,
│   ├── writing-offensive-skills/  #   authoring conventions
│   ├── exploit-development/
│   ├── ...
│   └── references/                # shared 47-file vulnerability pattern library
├── .claude-plugin/                # plugin.json + marketplace.json (install as a Claude Code plugin)
├── hooks/                         # SessionStart hook that injects the dispatcher every session
├── .devcontainer/                 # reproducible binary-analysis toolchain (rr/gdb/gcov/afl++) for the
│                                  #   crash→exploitability pipeline; scoped SYS_PTRACE/SYS_PERFMON, not --privileged
├── agents/                        # 8 collaborative sub-agents (incl. finding-validator, finding-checker)
├── engine/                        # bounded, resumable, traceable autopilot runner
│   ├── engine.py                  #   phase runner (budget + loop-detect + trace + resume; not an LLM)
│   ├── budget.py  loop_detector.py  tracer.py
│   ├── rebuttal.py                #   bounded generator↔checker rebuttal loop (default-to-skeptic)
│   └── model_scorecard.py         #   Wilson-bounded, fail-closed model-verdict trust calibration
├── tests/                         # pytest suite for the safety-critical scripts (run: pytest)
├── templates/                     # Structured templates per Kill Chain phase
│   ├── scope/                     #   scope-definition + scope.schema.json/example (machine-readable ROE)
│   ├── threat-model/              #   threat model (assets/entry-points/boundaries/ATT&CK) + drift baseline
│   └── ... (recon, weaponize, delivery, exploit, install, c2, actions, report)
├── workflows/                     # Kill Chain workflow definitions (YAML) + WORKFLOW-ENGINE.md
├── commands/                      # /engage.* o

// HOW IT'S BUILT

KEY FILES

skills/active-directory-attack/SKILL.mdREADME.md

// REPO STATS

385 stars