~ / rigs / ADScanPro / Claude-AD

ADScanPro/Claude-AD

Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay, delegation), with per-technique OPSEC/telemetry notes. Drives

↗ GitHub ★ 209 mit updated 2mo ago project Claude Code Claude plugin
share on X
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
CONTEXT TAX · EVERY TURN
~654 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
0/5
No committed guardrails · details

Copy this rig

# review before running: this installs third-party code
$ npx degit ADScanPro/Claude-AD/agents ./rig-claude-ad/agents
$ npx degit ADScanPro/Claude-AD/commands ./rig-claude-ad/commands
$ npx degit ADScanPro/Claude-AD/skills ./rig-claude-ad/skills

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit ADScanPro/Claude-AD/skills/acl-abuse .claude/skills/acl-abuse
$ npx degit ADScanPro/Claude-AD/skills/ad-environment-constraints .claude/skills/ad-environment-constraints
$ npx degit ADScanPro/Claude-AD/skills/ad-methodology .claude/skills/ad-methodology
$ npx degit ADScanPro/Claude-AD/skills/ad-opsec-telemetry .claude/skills/ad-opsec-telemetry
$ npx degit ADScanPro/Claude-AD/skills/adcs-attacks .claude/skills/adcs-attacks
$ npx degit ADScanPro/Claude-AD/skills/coercion-ntlm-relay .claude/skills/coercion-ntlm-relay
$ npx degit ADScanPro/Claude-AD/skills/compliance-mapping .claude/skills/compliance-mapping
$ npx degit ADScanPro/Claude-AD/skills/kerberos-attacks .claude/skills/kerberos-attacks
$ curl -fsSL --create-dirs -o .claude/agents/ad-attack-planner.md https://raw.githubusercontent.com/ADScanPro/Claude-AD/main/agents/ad-attack-planner.md
$ curl -fsSL --create-dirs -o .claude/agents/ad-enumerator.md https://raw.githubusercontent.com/ADScanPro/Claude-AD/main/agents/ad-enumerator.md
$ curl -fsSL --create-dirs -o .claude/agents/ad-exploit-operator.md https://raw.githubusercontent.com/ADScanPro/Claude-AD/main/agents/ad-exploit-operator.md

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(.env)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(~/.aws/**)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/*.key)",
      "Read(**/.env.*)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(git rebase *)",
      "Bash(wget *)",
      "Bash(npm publish:*)",
      "Bash(git commit *)",
      "Bash(gh pr merge *)"
    ]
  }
}

Skills (8)

Subagents (3)

ad-attack-planner
model: sonnet
Reasons about low-privilege-to-Domain-Admin paths in an authorized Active Directory assessment. Takes the enumerator's inventory plus the BloodHound CE graph and works out which edges to chain (Generi
ad-enumerator
model: sonnet
Runs the COLLECTION phase of an authorized Active Directory assessment from a low-privilege domain account. Orchestrates standard tools (netexec/nxc, impacket, rusthound-ce or bloodhound-python, certi
ad-exploit-operator
model: sonnet
Executes ONE exploitation step from an approved attack plan in an authorized Active Directory assessment, invoking the matching technique skill (kerberos-attacks, adcs-attacks, acl-abuse, coercion-ntl

Slash commands (3)

/ad-attack-paths/ad-recon/ad-scope

Similar rigs

copied ✓