⏳ This skill is pending AI review.
Scores will appear once the review pipeline completes.
active-directory-attack
Use when attacking a Windows Active Directory domain — Kerberos roasting/delegation, coercion + NTLM/Kerberos relay (CVE-2025-33073), ADCS ESC1-16 (EKUwu), ticket forgery & DCSync, dMSA BadSuccessor (CVE-2025-53779), BloodHound attack-path enumeration, domain dominance
Choose how to use this skill
You do not need every option. Choose the path your AI client supports. The stable page stays the same; versioned files are immutable.
1. Native installer
This listing has no registered native installer command. Use the complete package or source fallback below, depending on what your client supports.
Do not guess an installer command or replace an existing version without reviewing the diff.
2. Complete package recommended
Download the ZIP when available. It includes SKILL.md plus the references, security notes and version metadata.
No complete ProSkills package is published for this listing yet.3. Prompt-only
Copy the prompt above when the agent can read the stable page or when you want to adopt the workflow without installing a skill.
Need only the instruction file?
Download SKILL.md only if your client requires a single file. The complete ZIP is safer for a full installation because it preserves the references and release context.
No path installs or executes anything by itself. Your agent still needs access to the project files. Before updating, compare the installed version and review the diff.
// RATINGS
Not yet listed on ClawHub or SkillsMP
// README
Offensive Security Research Config for Claude Code
A spec-driven offensive security framework for Claude Code — structured engagement workflows based on the Cyber Kill Chain, 32 kill-chain skills (multi-file progressive-disclosure) plus a discipline layer (a SessionStart dispatcher + 6 process/discipline skills), 8 collaborative agents, and a shared 47-file vulnerability reference library. Inspired by GitHub's spec-kit, obra/superpowers, and gadievron/raptor (crash→exploitability + OSS-repo forensics).
Quick Setup
# Method 0: Install as a Claude Code plugin (recommended — auto-loads the skill dispatcher)
/plugin marketplace add hypnguyen1209/offensive-claude
/plugin install offensive-claude@offensive-claude-marketplace
Installing as a plugin registers a SessionStart hook that injects the
using-offensive-claude dispatcher into every conversation, so the skill-invocation discipline
(scope → finding → OPSEC) is active from the first message.
# Method 1: One-liner install (recommended)
curl -sL https://raw.githubusercontent.com/hypnguyen1209/offensive-claude/main/install.sh | bash
# Method 2: Clone + install script
git clone https://github.com/hypnguyen1209/offensive-claude.git ~/offensive-claude
cd ~/offensive-claude && bash install.sh
# Method 3: Manual copy
git clone https://github.com/hypnguyen1209/offensive-claude.git ~/offensive-claude
cp -r ~/offensive-claude/skills ~/.claude/skills
cp -r ~/offensive-claude/agents ~/.claude/agents
cp -r ~/offensive-claude/templates ~/.claude/templates
cp -r ~/offensive-claude/workflows ~/.claude/workflows
cp -r ~/offensive-claude/commands ~/.claude/commands
cp -r ~/offensive-claude/presets ~/.claude/presets
cp ~/offensive-claude/CLAUDE.md ~/.claude/CLAUDE.md
Skills and agents activate automatically — no additional configuration needed.
Engagement Workflow
Engagements follow the Cyber Kill Chain as a structured 9-phase pipeline with quality gates:
Phase 0 Phase 1 Phase 2 Phase 3 Phase 4 Phase 5 Phase 6 Phase 7 Phase 8
SCOPE → RECON → WEAPONIZE → DELIVERY → EXPLOIT → INSTALLATION → C2 → ACTIONS ON → REPORT
OBJECTIVES
Quick Start — Web App Pentest
/engage.init web-app --client ACME
/engage.scope # Define targets, ROE, authorization
/engage.recon # Subdomain enum, port scan, tech fingerprint
/engage.weaponize # Select exploits, design payloads
/engage.exploit # Execute exploits, document findings
/engage.report # Generate technical report + executive summary
Orchestration Commands
| Command | Phase | Action |
|---|---|---|
/engage.init <preset> | — | Initialize engagement with workflow preset |
/engage.scope | 0 | Define targets, ROE, authorization |
/engage.recon | 1 | Passive/active reconnaissance |
/engage.weaponize | 2 | Payload development, exploit design |
/engage.deliver | 3 | Delivery vector execution |
/engage.exploit | 4 | Exploitation, finding documentation |
/engage.install | 5 | Persistence establishment |
/engage.c2 | 6 | C2 infrastructure setup |
/engage.actions | 7 | Objectives execution, lateral movement |
/engage.report | 8 | Report generation |
/engage.status | — | Show pipeline status and progress |
/engage.gate | — | Validate current phase gate |
/engage.crash | 4 | Crash → root cause (rr) → reachability (gcov/trace) → empirical exploitability verdict |
/engage.cvediff | 2,4 | Find a CVE's canonical fix commit(s) across sources, then scope-gated diff for root cause |
/engage.scorecard | — | Calibrate model verdict trust (Wilson-bounded miss-rate) to short-circuit re-validation |
/engage.threatmodel | 1 | Materialize / lint / drift-check the engagement threat model |
/engage.memory | — | Recall prior patterns / record confirmed findings (cross-engagement learning) |
/engage.pickup | — | Resume an engagement from the engine trace (skip completed steps) |
Workflow Presets
| Preset | Phases | Use Case |
|---|---|---|
web-app | 0,1,2,3,4,8 | OWASP-focused web application assessment |
network | 0,1,2,4,5,6,7,8 | Internal network penetration test |
red-team | ALL (0-8) | Full adversary simulation |
cloud | 0,1,4,8 | AWS/Azure/GCP security audit |
mobile | 0,1,2,4,8 | Android/iOS application pentest |
ad-domain | 0,1,2,4,5,7,8 | Active Directory domain assessment |
bug-bounty | 0,1,4,8 | Bug bounty vulnerability hunting |
Quality Gates
Each phase transition validates:
- Required artifacts exist (templates filled)
- Findings have mandatory fields (CWE, CVSS, evidence, ATT&CK ID)
- Gate PASS → suggests next phase + relevant skills
- Gate FAIL → lists missing items
Structure
.
├── skills/ # 32 skill modules (progressive-disclosure layout)
│ ├── recon-osint/
│ │ ├── SKILL.md # thin router: when-to-activate + technique map + OPSEC/detection
│ │ ├── references/ # per-skill technique deep-dives (theory + code + detection + OPSEC)
│ │ └── scripts/ # runnable tooling backing each technique
│ ├── coding-mastery/scripts/_lib/ # shared safety libs: scope_guard, action_guard, http_creds, redact_headers
│ ├── engagement-memory/ # cross-engagement pattern-learning memory (support skill)
│ ├── using-offensive-claude/ # SessionStart DISPATCHER — skill-invocation discipline
│ ├── engagement-flow/ # process skills: sequence the kill chain,
│ ├── scope-discipline/ # no target without authorization,
│ ├── threat-model-discipline/ # model the attack surface + detect drift before exploiting,
│ ├── finding-discipline/ # no [CONFIRMED] without proof,
│ ├── opsec-discipline/ # detection/cleanup/redaction before acting,
│ ├── writing-offensive-skills/ # authoring conventions
│ ├── exploit-development/
│ ├── ...
│ └── references/ # shared 47-file vulnerability pattern library
├── .claude-plugin/ # plugin.json + marketplace.json (install as a Claude Code plugin)
├── hooks/ # SessionStart hook that injects the dispatcher every session
├── .devcontainer/ # reproducible binary-analysis toolchain (rr/gdb/gcov/afl++) for the
│ # crash→exploitability pipeline; scoped SYS_PTRACE/SYS_PERFMON, not --privileged
├── agents/ # 8 collaborative sub-agents (incl. finding-validator, finding-checker)
├── engine/ # bounded, resumable, traceable autopilot runner
│ ├── engine.py # phase runner (budget + loop-detect + trace + resume; not an LLM)
│ ├── budget.py loop_detector.py tracer.py
│ ├── rebuttal.py # bounded generator↔checker rebuttal loop (default-to-skeptic)
│ └── model_scorecard.py # Wilson-bounded, fail-closed model-verdict trust calibration
├── tests/ # pytest suite for the safety-critical scripts (run: pytest)
├── templates/ # Structured templates per Kill Chain phase
│ ├── scope/ # scope-definition + scope.schema.json/example (machine-readable ROE)
│ ├── threat-model/ # threat model (assets/entry-points/boundaries/ATT&CK) + drift baseline
│ └── ... (recon, weaponize, delivery, exploit, install, c2, actions, report)
├── workflows/ # Kill Chain workflow definitions (YAML) + WORKFLOW-ENGINE.md
├── commands/ # /engage.* o
// HOW IT'S BUILT
KEY FILES