Cybersecurity
ohmyjahh/xquads-squads
Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…
A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch.
$ npx skills add ADScanPro/Claude-AD --skill compliance-mapping -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ADScanPro/Claude-AD compliance-mapping --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/compliance-mapping .claude/skills/compliance-mapping && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "compliance-mapping" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/compliance-mapping into .claude/skills/compliance-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "compliance-mapping", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ADScanPro/Claude-AD/tree/main/skills/compliance-mappingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ADScanPro/Claude-AD --skill compliance-mapping -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ADScanPro/Claude-AD compliance-mapping --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/compliance-mapping .agents/skills/compliance-mapping && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "compliance-mapping" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/compliance-mapping into .agents/skills/compliance-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "compliance-mapping", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ADScanPro/Claude-AD --skill compliance-mapping -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ADScanPro/Claude-AD compliance-mapping --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/compliance-mapping .cursor/skills/compliance-mapping && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "compliance-mapping" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/compliance-mapping into .cursor/skills/compliance-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "compliance-mapping", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ADScanPro/Claude-AD.git --path skills/compliance-mapping--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ADScanPro/Claude-AD --skill compliance-mapping -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ADScanPro/Claude-AD compliance-mapping --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/compliance-mapping .gemini/skills/compliance-mapping && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "compliance-mapping" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/compliance-mapping into .gemini/skills/compliance-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "compliance-mapping", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ADScanPro/Claude-AD compliance-mappingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ADScanPro/Claude-AD --skill compliance-mapping -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/compliance-mapping .github/skills/compliance-mapping && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "compliance-mapping" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/compliance-mapping into .github/skills/compliance-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "compliance-mapping", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ADScanPro/Claude-AD --skill compliance-mapping -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ADScanPro/Claude-AD compliance-mapping --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/compliance-mapping .opencode/skills/compliance-mapping && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "compliance-mapping" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/compliance-mapping into .opencode/skills/compliance-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "compliance-mapping", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
compliance-mappingA high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch.
Compliance Mapping is an agent skill from ADScanPro/Claude-AD. A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch. Kerberoasting relates to authentication and logging, so it brushes ENS op.acc.5 / op.exp.8, NIS2 Art.21(2)(h), DORA RTS Art.9 / Art.21. Use this when a reader wants to understand which regulatory control an AD finding relates to, or to add an orientation note to a technical finding. This is a conceptual, orientative mapping only; it is NOT an auditor-defensible, curated, ID-by-ID control matrix. Covers…
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Red teaming and adversary simulation and Penetration testing. The repository describes itself as: Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay… The licence is MIT.
Read from SKILL.md and the folder at commit 73efec5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Compliance Mapping loads about 1.7k tokens when it runs. Until then it costs about 156 tokens; SKILL.md has 703 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ADScanPro/Claude-AD at commit 73efec5, republished under its MIT licence (© ADScanPro). 703 words, ~1,661 tokens.
.claude/skills/compliance-mapping/SKILL.md (or your agent's skills folder).Disclaimer, read first. This is a conceptual, orientative mapping. It shows, at a high level, which family of controls an AD attack technique relates to, so a practitioner can point a finding in the right regulatory direction. It is not an auditor-defensible control matrix. A defensible mapping (one an auditor accepts, cross-referenced ID by ID to the exact control text, scoped to your organization's applicability statement, with evidence per control) is a curated product, not something you infer from a technique name. ADscan (free and source-available) produces that curated, ID-by-ID matrix as part of its report. Use this skill to orient a finding; do not present it to an auditor as compliance evidence.
An AD technique succeeds because a control is weak or absent. Kerberoasting works because service-account authentication is weak and the requests are not monitored, so it relates to the authentication and logging control families. That relationship is conceptual: it tells a reader where in a framework to look, not that the finding satisfies or violates a specific control clause. The mapping direction is always technique → control family → representative article, and it stops there.
Weak service-account or pre-auth-disabled credentials cracked offline. Touches authentication strength and activity logging (the ticket requests should be monitored).
Replication of the credential database using directory-replication rights. Touches access-rights management (who holds Get-Changes) and logging.
Excessive or misconfigured object permissions used to escalate. Touches access-rights management and secure configuration.
Certificate-template and PKI misconfiguration leading to authentication as another principal. Touches cryptographic-key protection, secure configuration, and authentication.
Delegation misconfiguration used to impersonate. Touches access-rights management and secure configuration.
Forced authentication relayed to escalate; weak signing/channel-binding configuration. Touches secured communications and secure configuration.
Weak or reused passwords and missing MFA. Touches authentication and cyber hygiene.
Secrets left in SYSVOL, object attributes, or file shares. Touches cryptographic-key / secret protection and secure configuration.
Attach one line of orientation to a finding, such as "relates to ENS op.acc.5 and NIS2 Art.21(2)(h)", so the reader knows the regulatory neighbourhood. Then stop. Do not stretch a conceptual relationship into a compliance verdict, do not claim the finding proves non-compliance with a specific clause, and do not present this as the control matrix an auditor signs off on. That curated, evidence-backed, ID-by-ID matrix is a separate, deliberate piece of work.
© ADScanPro, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/compliance-mapping of ADScanPro/Claude-AD.
Open the folder on GitHubat commit 73efec5
Compliance Mapping next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Compliance Mapping this skillADScanPro/Claude-AD | 210 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Cybersecurityohmyjahh/xquads-squads | 276 | — | ~895 | Automated safety check: Pass | MIT | |
| Detecting T1548 Abuse Elevation Control Mechanismmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | |
| Exploiting Vulnerabilities With Metasploit Frameworkmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~1.9k | Automated safety check: Notes | Apache-2.0 | |
| Detecting Attacks On Historian Serversmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Performing Web Application Firewall Bypassmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 |
ohmyjahh/xquads-squads
Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…
mukul975/Anthropic-Cybersecurity-Skills
Detect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry…
mukul975/Anthropic-Cybersecurity-Skills
Uses the Metasploit Framework (msfconsole and its exploit, auxiliary, and post-exploitation modules) to validate that identified CVEs and vulnerabilities are actually exploitable, gather…
mukul975/Anthropic-Cybersecurity-Skills
Detect cyber attacks on OT historian servers (OSIsoft PI, Ignition, GE Proficy, Wonderware InSQL) using a Python detector that flags unauthorized queries, data manipulation, and lateral-movement…
mukul975/Anthropic-Cybersecurity-Skills
Bypasses Web Application Firewall protections using encoding tricks, HTTP method manipulation, parameter pollution, and payload obfuscation to smuggle SQL injection, XSS, and other exploit payloads…
mukul975/Anthropic-Cybersecurity-Skills
Manually identifies flaws in application business logic - price manipulation, multi-step workflow bypass, and privilege escalation - by intercepting and modifying requests with Burp Suite, going…
ADScanPro/Claude-AD
Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…
ADScanPro/Claude-AD
Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding…
ADScanPro/Claude-AD
The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the…
ADScanPro/Claude-AD
Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k).
ADScanPro/Claude-AD
Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB.
ADScanPro/Claude-AD
Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD).
Categories
A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch. Compliance Mapping is an agent skill from ADScanPro/Claude-AD. A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch.
Compliance Mapping fits situations like: tasks that involve Red teaming and adversary simulation; tasks that involve Penetration testing.
Run `npx skills add ADScanPro/Claude-AD --skill compliance-mapping -a claude-code`. Or copy the skill folder (skills/compliance-mapping in ADScanPro/Claude-AD) into .claude/skills/compliance-mapping in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ADScanPro/Claude-AD --skill compliance-mapping -a codex`. Or copy the skill folder (skills/compliance-mapping in ADScanPro/Claude-AD) into .agents/skills/compliance-mapping in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ADScanPro/Claude-AD --skill compliance-mapping -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/compliance-mapping, .gemini/skills/compliance-mapping, .github/skills/compliance-mapping and .opencode/skills/compliance-mapping in your project.
SKILL.md names no scripts, command-line tools or credentials: Compliance Mapping is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Compliance Mapping is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Compliance Mapping: Cybersecurity (ohmyjahh/xquads-squads, 276 stars), Detecting T1548 Abuse Elevation Control Mechanism (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Exploiting Vulnerabilities With Metasploit Framework (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Detecting Attacks On Historian Servers (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ADScanPro (a GitHub user) maintains it in ADScanPro/Claude-AD, which has 210 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on August 24, 2026.
Source: ADScanPro/Claude-AD on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.