Agent skill

Compliance Mapping

by ADScanPro in ADScanPro/Claude-AD

A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch.

MITAuto-check passedSecurity

Install Compliance Mapping

skills CLI
$ npx skills add ADScanPro/Claude-AD --skill compliance-mapping -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ADScanPro/Claude-AD compliance-mapping --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/compliance-mapping .claude/skills/compliance-mapping && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
compliance-mapping
GitHub stars
210
Token cost
~1.7k tokens
SKILL.md length
703 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch.

  • Tasks that involve Red teaming and adversary simulation
  • SKILL.md covers How to read this, The frameworks, briefly, The mapping and Using this in a report
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Penetration testing

What it does

Compliance Mapping is an agent skill from ADScanPro/Claude-AD. A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch. Kerberoasting relates to authentication and logging, so it brushes ENS op.acc.5 / op.exp.8, NIS2 Art.21(2)(h), DORA RTS Art.9 / Art.21. Use this when a reader wants to understand which regulatory control an AD finding relates to, or to add an orientation note to a technical finding. This is a conceptual, orientative mapping only; it is NOT an auditor-defensible, curated, ID-by-ID control matrix. Covers…

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Red teaming and adversary simulation and Penetration testing. The repository describes itself as: Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay… The licence is MIT.

When your agent uses it

  • Tasks that involve Red teaming and adversary simulation
  • Tasks that involve Penetration testing

Example prompts

  • “/compliance-mapping”

What it can do on your machine

Read from SKILL.md and the folder at commit 73efec5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Compliance Mapping loads about 1.7k tokens when it runs. Until then it costs about 156 tokens; SKILL.md has 703 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~156
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ADScanPro/Claude-AD at commit 73efec5, republished under its MIT licence (© ADScanPro). 703 words, ~1,661 tokens.

Download SKILL.mdSave it as .claude/skills/compliance-mapping/SKILL.md (or your agent's skills folder).
name
compliance-mapping
description
A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch. Kerberoasting relates to authentication and logging, so it brushes ENS op.acc.5 / op.exp.8, NIS2 Art.21(2)(h), DORA RTS Art.9 / Art.21. Use this when a reader wants to understand which regulatory control an AD finding relates to, or to add an orientation note to a technical finding. This is a conceptual, orientative mapping only; it is NOT an auditor-defensible, curated, ID-by-ID control matrix. Covers ENS (op.acc.*, op.exp.*), NIS2 (Directive 2022/2555 Art.21), and DORA (RTS 2024/1774).

AD Technique → Compliance Control (Conceptual Mapping)

Disclaimer, read first. This is a conceptual, orientative mapping. It shows, at a high level, which family of controls an AD attack technique relates to, so a practitioner can point a finding in the right regulatory direction. It is not an auditor-defensible control matrix. A defensible mapping (one an auditor accepts, cross-referenced ID by ID to the exact control text, scoped to your organization's applicability statement, with evidence per control) is a curated product, not something you infer from a technique name. ADscan (free and source-available) produces that curated, ID-by-ID matrix as part of its report. Use this skill to orient a finding; do not present it to an auditor as compliance evidence.

How to read this

An AD technique succeeds because a control is weak or absent. Kerberoasting works because service-account authentication is weak and the requests are not monitored, so it relates to the authentication and logging control families. That relationship is conceptual: it tells a reader where in a framework to look, not that the finding satisfies or violates a specific control clause. The mapping direction is always technique → control family → representative article, and it stops there.

The frameworks, briefly

  • ENS (Esquema Nacional de Seguridad, Spain): control families used here:
    • op.acc.1 Identificación
    • op.acc.4 Proceso de gestión de derechos de acceso
    • op.acc.5 Mecanismo de autenticación (usuarios externos)
    • op.acc.6 Mecanismo de autenticación (usuarios de la organización)
    • op.exp.2 Configuración de seguridad
    • op.exp.8 Registro de la actividad
    • op.exp.10 Protección de claves criptográficas
  • NIS2 (Directive (EU) 2022/2555): Art.21(2) cybersecurity risk-management measures:
    • (g) basic cyber hygiene and training
    • (h) cryptography and encryption
    • (i) human resources security, access control policies, asset management
    • (j) multi-factor authentication, secured communications
  • DORA (Regulation (EU) 2022/2554) with RTS (EU) 2024/1774 on ICT risk management:
    • Art.20: identity management
    • Art.21: access control (management of access rights)
    • Art.9 (DORA level-1, protection and prevention) is the parent duty the RTS details

The mapping

Kerberoasting / AS-REP roasting

Weak service-account or pre-auth-disabled credentials cracked offline. Touches authentication strength and activity logging (the ticket requests should be monitored).

  • ENS: op.acc.5 / op.acc.6 (authentication mechanism), op.exp.8 (activity logging)
  • NIS2: Art.21(2)(h) cryptography, Art.21(2)(i) access-control policy
  • DORA: RTS Art.21 access control, Art.9 (protection/prevention parent)
DCSync

Replication of the credential database using directory-replication rights. Touches access-rights management (who holds Get-Changes) and logging.

  • ENS: op.acc.4 (access-rights management), op.acc.1 (identification), op.exp.8 (logging)
  • NIS2: Art.21(2)(i) access control, Art.21(2)(j) secured communications
  • DORA: RTS Art.20 identity management, Art.21 access control
ACL abuse (GenericAll / WriteDACL / WriteOwner)

Excessive or misconfigured object permissions used to escalate. Touches access-rights management and secure configuration.

  • ENS: op.acc.4 (access-rights management), op.exp.2 (security configuration)
  • NIS2: Art.21(2)(i) access control and asset management
  • DORA: RTS Art.21 access control
Show full SKILL.md (265 more words)Show less
AD CS abuse (ESC1-ESC17)

Certificate-template and PKI misconfiguration leading to authentication as another principal. Touches cryptographic-key protection, secure configuration, and authentication.

  • ENS: op.exp.10 (cryptographic-key protection), op.exp.2 (configuration), op.acc.5/op.acc.6
  • NIS2: Art.21(2)(h) cryptography, Art.21(2)(i) access control
  • DORA: RTS Art.21 access control, Art.9 (protection/prevention)
Kerberos delegation abuse (unconstrained / constrained / RBCD)

Delegation misconfiguration used to impersonate. Touches access-rights management and secure configuration.

  • ENS: op.acc.4 (access-rights management), op.exp.2 (configuration)
  • NIS2: Art.21(2)(i) access control
  • DORA: RTS Art.21 access control
Coercion + NTLM relay

Forced authentication relayed to escalate; weak signing/channel-binding configuration. Touches secured communications and secure configuration.

  • ENS: op.exp.2 (security configuration), op.acc.5/op.acc.6 (authentication)
  • NIS2: Art.21(2)(j) secured communications, Art.21(2)(h) cryptography
  • DORA: RTS Art.21 access control, Art.9 (protection/prevention)
Password spraying / weak-credential findings

Weak or reused passwords and missing MFA. Touches authentication and cyber hygiene.

  • ENS: op.acc.5/op.acc.6 (authentication mechanism), op.acc.1 (identification)
  • NIS2: Art.21(2)(j) MFA, Art.21(2)(g) cyber hygiene
  • DORA: RTS Art.20 identity management, Art.21 access control
Credential exposure (GPP passwords, LDAP descriptions, shares)

Secrets left in SYSVOL, object attributes, or file shares. Touches cryptographic-key / secret protection and secure configuration.

  • ENS: op.exp.10 (key protection), op.exp.2 (configuration), op.acc.4 (access-rights)
  • NIS2: Art.21(2)(h) cryptography, Art.21(2)(i) asset management
  • DORA: RTS Art.21 access control

Using this in a report

Attach one line of orientation to a finding, such as "relates to ENS op.acc.5 and NIS2 Art.21(2)(h)", so the reader knows the regulatory neighbourhood. Then stop. Do not stretch a conceptual relationship into a compliance verdict, do not claim the finding proves non-compliance with a specific clause, and do not present this as the control matrix an auditor signs off on. That curated, evidence-backed, ID-by-ID matrix is a separate, deliberate piece of work.

© ADScanPro, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/compliance-mapping of ADScanPro/Claude-AD.

Open the folder on GitHubat commit 73efec5

Compare with similar skills

Compliance Mapping next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Compliance Mapping compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Compliance Mapping this skillADScanPro/Claude-AD210—~1.7kAutomated safety check: PassMIT
Cybersecurityohmyjahh/xquads-squads276—~895Automated safety check: PassMIT
Detecting T1548 Abuse Elevation Control Mechanismmukul975/Anthropic-Cybersecurity-Skills34k—~1.5kAutomated safety check: NotesApache-2.0
Exploiting Vulnerabilities With Metasploit Frameworkmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: NotesApache-2.0
Detecting Attacks On Historian Serversmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Performing Web Application Firewall Bypassmukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.0

Similar skills

  • Cybersecurity

    ohmyjahh/xquads-squads

    Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…

    276 GitHub stars~895 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Detecting T1548 Abuse Elevation Control Mechanism

    mukul975/Anthropic-Cybersecurity-Skills

    Detect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry…

    34k GitHub stars~1.5k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Exploiting Vulnerabilities With Metasploit Framework

    mukul975/Anthropic-Cybersecurity-Skills

    Uses the Metasploit Framework (msfconsole and its exploit, auxiliary, and post-exploitation modules) to validate that identified CVEs and vulnerabilities are actually exploitable, gather…

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Detecting Attacks On Historian Servers

    mukul975/Anthropic-Cybersecurity-Skills

    Detect cyber attacks on OT historian servers (OSIsoft PI, Ignition, GE Proficy, Wonderware InSQL) using a Python detector that flags unauthorized queries, data manipulation, and lateral-movement…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Web Application Firewall Bypass

    mukul975/Anthropic-Cybersecurity-Skills

    Bypasses Web Application Firewall protections using encoding tricks, HTTP method manipulation, parameter pollution, and payload obfuscation to smuggle SQL injection, XSS, and other exploit payloads…

    34k GitHub stars~2.4k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Testing For Business Logic Vulnerabilities

    mukul975/Anthropic-Cybersecurity-Skills

    Manually identifies flaws in application business logic - price manipulation, multi-step workflow bypass, and privilege escalation - by intercepting and modifying requests with Burp Suite, going…

    34k GitHub stars~3.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from ADScanPro/Claude-AD

  • Acl Abuse

    ADScanPro/Claude-AD

    Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…

    210 GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Ad Environment Constraints

    ADScanPro/Claude-AD

    Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding…

    210 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • Ad Opsec Telemetry

    ADScanPro/Claude-AD

    The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the…

    210 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Adcs Attacks

    ADScanPro/Claude-AD

    Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k).

    210 GitHub stars~3.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Coercion Ntlm Relay

    ADScanPro/Claude-AD

    Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB.

    210 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Kerberos Attacks

    ADScanPro/Claude-AD

    Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD).

    210 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check: notes

Categories

Questions about Compliance Mapping

What does Compliance Mapping do?

A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch. Compliance Mapping is an agent skill from ADScanPro/Claude-AD. A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch.

When should I use Compliance Mapping?

Compliance Mapping fits situations like: tasks that involve Red teaming and adversary simulation; tasks that involve Penetration testing.

How do I install Compliance Mapping in Claude Code?

Run `npx skills add ADScanPro/Claude-AD --skill compliance-mapping -a claude-code`. Or copy the skill folder (skills/compliance-mapping in ADScanPro/Claude-AD) into .claude/skills/compliance-mapping in your project. Claude Code loads it when a task matches its description.

How do I install Compliance Mapping in Codex?

Run `npx skills add ADScanPro/Claude-AD --skill compliance-mapping -a codex`. Or copy the skill folder (skills/compliance-mapping in ADScanPro/Claude-AD) into .agents/skills/compliance-mapping in your project. Codex loads it when a task matches its description.

Can I use Compliance Mapping in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ADScanPro/Claude-AD --skill compliance-mapping -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/compliance-mapping, .gemini/skills/compliance-mapping, .github/skills/compliance-mapping and .opencode/skills/compliance-mapping in your project.

What does Compliance Mapping need to run?

SKILL.md names no scripts, command-line tools or credentials: Compliance Mapping is instructions for the agent only.

Does Compliance Mapping access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Compliance Mapping safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Compliance Mapping use?

Compliance Mapping is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Compliance Mapping use?

About 1.7k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Compliance Mapping?

Skills that share tags, products or a category with Compliance Mapping: Cybersecurity (ohmyjahh/xquads-squads, 276 stars), Detecting T1548 Abuse Elevation Control Mechanism (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Exploiting Vulnerabilities With Metasploit Framework (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Detecting Attacks On Historian Servers (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Compliance Mapping?

ADScanPro (a GitHub user) maintains it in ADScanPro/Claude-AD, which has 210 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on August 24, 2026.

Source: ADScanPro/Claude-AD on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.