Authorization Bypass Detection
Tencent/AI-Infra-Guard
Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries.
The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the…
$ npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ADScanPro/Claude-AD ad-opsec-telemetry --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ad-opsec-telemetry .claude/skills/ad-opsec-telemetry && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ad-opsec-telemetry" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry into .claude/skills/ad-opsec-telemetry/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ad-opsec-telemetry", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetryType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ADScanPro/Claude-AD ad-opsec-telemetry --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/ad-opsec-telemetry .agents/skills/ad-opsec-telemetry && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ad-opsec-telemetry" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry into .agents/skills/ad-opsec-telemetry/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ad-opsec-telemetry", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ADScanPro/Claude-AD ad-opsec-telemetry --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/ad-opsec-telemetry .cursor/skills/ad-opsec-telemetry && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ad-opsec-telemetry" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry into .cursor/skills/ad-opsec-telemetry/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ad-opsec-telemetry", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ADScanPro/Claude-AD.git --path skills/ad-opsec-telemetry--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ADScanPro/Claude-AD ad-opsec-telemetry --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/ad-opsec-telemetry .gemini/skills/ad-opsec-telemetry && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ad-opsec-telemetry" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry into .gemini/skills/ad-opsec-telemetry/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ad-opsec-telemetry", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ADScanPro/Claude-AD ad-opsec-telemetryInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/ad-opsec-telemetry .github/skills/ad-opsec-telemetry && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ad-opsec-telemetry" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry into .github/skills/ad-opsec-telemetry/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ad-opsec-telemetry", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ADScanPro/Claude-AD ad-opsec-telemetry --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/ad-opsec-telemetry .opencode/skills/ad-opsec-telemetry && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ad-opsec-telemetry" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry into .opencode/skills/ad-opsec-telemetry/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ad-opsec-telemetry", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ad-opsec-telemetryThe telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the…
Ad Opsec Telemetry is an agent skill from ADScanPro/Claude-AD. The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the DS-Replication-Get-Changes GUID, AS-REP roasting produces Event 4768 with no pre-auth, LSASS dumping is blocked by EDR, plus a lateral-movement telemetry table by protocol (SMB/WMI/WinRM/RDP/DCOM). Use this whenever you run or plan an offensive AD technique and need to know what noise it makes, when writing the…
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Red teaming and adversary simulation. The repository describes itself as: Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay… The licence is MIT.
Read from SKILL.md and the folder at commit 73efec5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ad Opsec Telemetry loads about 2.4k tokens when it runs. Until then it costs about 180 tokens; SKILL.md has 1,104 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ADScanPro/Claude-AD at commit 73efec5, republished under its MIT licence (© ADScanPro). 1,104 words, ~2,355 tokens.
.claude/skills/ad-opsec-telemetry/SKILL.md (or your agent's skills folder).Every technique leaves a trace. The goal here is not evasion. It is knowing the noise profile of each action so you can document it for the client before the engagement, pick the quieter of two functionally equivalent techniques, and correlate what you did with what their SOC saw. For a defender, read the same tables backwards: they are the events to monitor and alert on.
Two rules of engagement throughout:
Microsoft Defender for Identity (MDI) is the sensor that matters most in AD; it reads DC traffic directly and ships tuned detections for most of what follows.
Requesting service tickets for accounts with SPNs, to crack offline.
Ticket Encryption Type = 0x17 (RC4-HMAC). Attackers request RC4 because the
resulting hash cracks fastest, but a service that normally uses AES suddenly requested
with RC4 is the classic signature.GetUserSPNs.py corp.local/user:pass -dc-ip <dc_ip> -request -outputfile roast.txtCracking accounts that have Kerberos pre-authentication disabled, no valid credential needed to request the roastable material.
Pre-Authentication Type = 0. Normal accounts always
pre-authenticate; a 4768 with no pre-auth is the signature.GetNPUsers.py corp.local/ -usersfile users.txt -dc-ip <dc_ip> -no-pass -format hashcatDONT_REQUIRE_PREAUTH.DONT_REQUIRE_PREAUTH wherever possible; strong passwords on
accounts that genuinely need it; alert on the flag being set.Replicating credentials out of the DC using directory-replication rights. High severity, never transparent, so coordinate before running.
1131f6aa-9c07-11d1-f79f-00c04fc2dcd2: DS-Replication-Get-Changes1131f6ad-9c07-11d1-f79f-00c04fc2dcd2: DS-Replication-Get-Changes-Allsecretsdump.py corp.local/user:pass@dc01.corp.local -just-dc-user krbtgtDumping process memory of lsass.exe to extract credentials.
MiniDumpWriteDump against lsass. The result is a blocked/empty dump, a
crashed process, or an immediate alert naming your tool.Alternatives that avoid touching lsass live:
# Registry-hive route: avoids a live lsass handle
secretsdump.py -sam sam.save -system system.save LOCALCollector queries have well-known shapes: (objectCategory=computer) pulling dozens of
attributes, plus queries for msDS-AllowedToDelegateTo, delegation and ACL attributes in
bulk.
MDI and legacy ATA carry specific detection for BloodHound-style enumeration.
Quieter collection requests only the attributes it needs (never *) and spreads queries
over time instead of firing them all at connect.
MITRE: T1087 (Account Discovery), T1069 (Permission Groups Discovery).
Defender watch: a single principal issuing large attribute-heavy LDAP sweeps in a short window.
When you need remote execution, the protocol you pick determines the noise. From loudest to quietest:
| Protocol | Telemetry | OPSEC note |
|---|---|---|
| PsExec (SCM service install) | Event 7045 service install — very visible, routinely EDR-blocked | Avoid when EDR is active |
| WMI exec | Event 4688 process create — MDE detects | Quieter than PsExec |
| Scheduled task | Event 4698/4702 task created — moderately visible | Acceptable |
| WinRM / PSRemoting | Legitimate channel, but Event 4624 logon type 3 + PowerShell logs | Preferred when available |
| DCOM / MMC | Fewer known signatures | Best profile under EDR |
Coercion (PetitPotam, PrinterBug, DFSCoerce) forces a target to authenticate to you, producing inbound auth requests visible in SIEM. Coercing at scale generates hundreds of auth events.
ntlmrelayx in automatic mode can capture credentials of real users in production, so
coordinate before running it against a live environment.
MITRE: T1187 (Forced Authentication), T1557.001 (LLMNR/NBT-NS Poisoning and SMB Relay).
Defender watch: spikes of inbound authentications to a non-standard host; EFSRPC / spoolss / DFS RPC calls to unexpected destinations.
Remediation: SMB signing enforced; LDAP channel binding; EPA on AD CS web endpoints; disable spooler on DCs.
Windows Server 2016+ disables null sessions by default; some SOCs alert on the attempt as anonymous recon.
When you hold credentials, always use them. Null session is a last-resort fallback only, and worth documenting when used.
MITRE: T1135 (Network Share Discovery), T1087.
Show a warning and get sign-off (or document that it ran) before any of these:
| Action | Why |
|---|---|
| DCSync | Critical MDI alert; your IP visible in DC logs |
| Password spraying | Risk of locking out real accounts |
| ntlmrelayx (auto) | May capture real users' credentials in production |
| Coercion at scale | Hundreds of auth requests, SIEM-visible |
| Kerberoasting all accounts | MDI volume alert; document targeted accounts |
| LSASS dump | EDR-detectable; risk of crashing the process |
Running a technique: check its row, warn the client about the events it will generate, and prefer the quieter equivalent when there is one (WMI over PsExec, one SPN over the whole domain, registry-hive over live lsass). Writing the report: turn these tables into the detection-and-remediation section so the defender can find every action you took and close the gap that let it work.
© ADScanPro, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/ad-opsec-telemetry of ADScanPro/Claude-AD.
Open the folder on GitHubat commit 73efec5
Ad Opsec Telemetry next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ad Opsec Telemetry this skillADScanPro/Claude-AD | 210 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Authorization Bypass DetectionTencent/AI-Infra-Guard | 6.8k | — | ~753 | Automated safety check: Pass | Apache-2.0 | |
| Run Assert Evalresponsibleai/ASSERT | 328 | — | ~11k | Automated safety check: Notes | MIT | |
| Osint Methodologyelementalsouls/Claude-OSINT | 2.8k | — | ~8.7k | Automated safety check: Notes | MIT | |
| Lfd Designelvisun/loss-function-development | 176 | — | ~2.9k | Automated safety check: Notes | MIT | |
| Web Exfiltration DetectionTencent/AI-Infra-Guard | 6.8k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 |
Tencent/AI-Infra-Guard
Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries.
responsibleai/ASSERT
Run an ASSERT evaluation against a described risk. An agent skill from responsibleai/ASSERT.
elementalsouls/Claude-OSINT
Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.
elvisun/loss-function-development
Design a loss function and harness for a long-running /goal optimization run (loss-function development, LFD).
Tencent/AI-Infra-Guard
Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths.
Tencent/AI-Infra-Guard
Probes whether an agent can be hijacked by instructions hidden in documents, retrieved chunks or fetched web pages, using test prompts that embed a hidden instruction.
ADScanPro/Claude-AD
Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…
ADScanPro/Claude-AD
Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding…
ADScanPro/Claude-AD
Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k).
ADScanPro/Claude-AD
Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB.
ADScanPro/Claude-AD
Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD).
ADScanPro/Claude-AD
A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch.
Categories
The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the…. Ad Opsec Telemetry is an agent skill from ADScanPro/Claude-AD. The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the DS-Replication-Get-Changes GUID, AS-REP roasting produces Event 4768 with no pre-auth, LSASS dumping is blocked by EDR, plus a lateral-movement telemetry table by protocol (SMB/WMI/WinRM/RDP/DCOM).
Ad Opsec Telemetry fits situations like: tasks that involve Red teaming and adversary simulation.
Run `npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry -a claude-code`. Or copy the skill folder (skills/ad-opsec-telemetry in ADScanPro/Claude-AD) into .claude/skills/ad-opsec-telemetry in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry -a codex`. Or copy the skill folder (skills/ad-opsec-telemetry in ADScanPro/Claude-AD) into .agents/skills/ad-opsec-telemetry in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ad-opsec-telemetry, .gemini/skills/ad-opsec-telemetry, .github/skills/ad-opsec-telemetry and .opencode/skills/ad-opsec-telemetry in your project.
SKILL.md names no scripts, command-line tools or credentials: Ad Opsec Telemetry is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Ad Opsec Telemetry is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Ad Opsec Telemetry: Authorization Bypass Detection (Tencent/AI-Infra-Guard, 6.8k stars), Run Assert Eval (responsibleai/ASSERT, 328 stars), Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars) and Lfd Design (elvisun/loss-function-development, 176 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ADScanPro (a GitHub user) maintains it in ADScanPro/Claude-AD, which has 210 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on August 24, 2026.
Source: ADScanPro/Claude-AD on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.