windows-ad
What this skill does
This skill is a security/teaching tool focused on authorized Active Directory and Windows identity attacks, including Kerberos, AD CS, BloodHound paths, NTLM relay, and domain privilege escalation res
github/zhaoxuya520 - teaching/educational content - 23.3k stars
Threat analysis
Skill info
pkg:github/zhaoxuya520/reverse-skill@cf745b8?skill=windows-adAssessments (2)
teaching/educational content
teaching/educational content via local-llm-review
SKILL.md
The skill contains detailed instructions on using tools like Mimikatz, BloodHound, and Certipy for AD attacks. These are explicitly described as teaching material for authorized red-team operations, ntool usage guidance
tool usage guidance via local-llm-review
SKILL.md
The skill includes guidance on using tools like ntlmrelayx and Responder for NTLM relay attacks. These are described as requiring explicit authorization and are part of the educational content, not exBadge
Add the Anomity scan badge for windows-ad to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of windows-ad? Report an issue or request a rescan.




