{"slug":"adscanpro-ad-opsec-telemetry","name":"ad-opsec-telemetry","description":"The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the DS-Replication-Get-Changes GUID, AS-REP roasting produces Event 4768 with no pre-auth, LSASS dumping is blocked by EDR, plus a lateral-movement telemetry table by protocol (SMB/WMI/WinRM/RDP/DCOM). Use this whenever you run or plan an offensive AD technique and need to know what noise it makes, when writing the engagement's detection notes, or when a defender wants to know what to monitor. Teaches red teamers what is loud and blue teamers what to watch. Standard-tooling knowledge, no vendor engine.","long_description":"---\nname: ad-opsec-telemetry\ndescription: >\n  The telemetry each Active Directory technique generates and what alerts a defender:\n  Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync\n  produces Event 4662 with the DS-Replication-Get-Changes GUID, AS-REP roasting produces\n  Event 4768 with no pre-auth, LSASS dumping is blocked by EDR, plus a lateral-movement\n  telemetry table by protocol (SMB/WMI/WinRM/RDP/DCOM). Use this whenever you run or plan an\n  offensive AD technique and need to know what noise it makes, when writing the engagement's\n  detection notes, or when a defender wants to know what to monitor. Teaches red teamers\n  what is loud and blue teamers what to watch. Standard-tooling knowledge, no vendor engine.\n---\n\n# AD OPSEC and Telemetry\n\nEvery technique leaves a trace. The goal here is not evasion. It is knowing the noise\nprofile of each action so you can document it for the client before the engagement, pick\nthe quieter of two functionally equivalent techniques, and correlate what you did with what\ntheir SOC saw. For a defender, read the same tables backwards: they are the events to\nmonitor and alert on.\n\nTwo rules of engagement throughout:\n\n- **Document the noise.** Tell the client what each high-signal action generated, with the\n  event ID and the source IP, so they can find it in their logs.\n- **Coordinate the loud ones.** DCSync, mass spraying, coercion at scale, and LSASS dumps\n  need explicit client sign-off or an end-of-engagement window when detection no longer\n  matters.\n\nMicrosoft Defender for Identity (MDI) is the sensor that matters most in AD; it reads DC\ntraffic directly and ships tuned detections for most of what follows.\n\n---\n\n## Kerberoasting: Event 4769, RC4 (0x17)\n\nRequesting service tickets for accounts with SPNs, to crack offline.\n\n- **Event 4769** (Kerberos service ticket requested) fires for each SPN targeted. The tell\n  is `Ticket Encryption Type = 0x17 (RC4-HMAC)`. Attackers request RC4 because the\n  resulting hash cracks fastest, but a service that normally uses AES suddenly requested\n  with RC4 is the classic signature.\n- **MDI**: \"Suspected Kerberoasting attack\" is on by default and triggers on the volume and\n  RC4 pattern.\n- Requesting all SPNs at once amplifies the signal. Targeting one high-value account is far\n  quieter than roasting the whole domain.\n\n```bash\nGetUserSPNs.py corp.local/user:pass -dc-ip <dc_ip> -request -outputfile roast.txt\n```\n\n- **MITRE**: T1558.003 (Steal or Forge Kerberos Tickets: Kerberoasting).\n- **Defender watch**: 4769 with 0x17 for accounts that otherwise use AES; a single principal\n  requesting many distinct SPN tickets in a short window.\n- **Remediation**: strong (25+ char) service-account passwords or gMSA; AES-only on service\n  accounts; monitor 4769 by encryption type.\n\n---\n\n## AS-REP Roasting: Event 4768, no pre-auth\n\nCracking accounts that have Kerberos pre-authentication disabled, no valid credential\nneeded to request the roastable material.\n\n- **Event 4768** (TGT requested) with `Pre-Authentication Type = 0`. Normal accounts always\n  pre-authenticate; a 4768 with no pre-auth is the signature.\n- **MDI**: \"Suspected AS-REP Roasting attack.\"\n\n```bash\nGetNPUsers.py corp.local/ -usersfile users.txt -dc-ip <dc_ip> -no-pass -format hashcat\n```\n\n- **MITRE**: T1558.004 (AS-REP Roasting).\n- **Defender watch**: 4768 with pre-auth type 0; any account carrying `DONT_REQUIRE_PREAUTH`.\n- **Remediation**: remove `DONT_REQUIRE_PREAUTH` wherever possible; strong passwords on\n  accounts that genuinely need it; alert on the flag being set.\n\n---\n\n## DCSync: Event 4662, replication GUIDs\n\nReplicating credentials out of the DC using directory-replication rights. High severity,\nnever transparent, so coordinate before running.\n\n- **Event 4662** (operation on a directory object) with the replication rights GUIDs:\n  - `1131f6aa-9c07-11d1-f79f-00c04fc2dcd2`: DS-Replication-Get-Changes\n  - `1131f6ad-9c07-11d1-f79f-00c04fc2dcd2`: DS-Replication-Get-Changes-All\n- **MDI**: \"Suspected DCSync attack (replication of directory services)\": a critical alert\n  in any competent SOC.\n- The source host in the DC logs is your machine's IP, not a real DC. That mismatch (a\n  non-DC requesting replication) is itself the detection.\n\n```bash\nsecretsdump.py corp.local/user:pass@dc01.corp.local -just-dc-user krbtgt\n```\n\n- **MITRE**: T1003.006 (OS Credential Dumping: DCSync).\n- **Defender watch**: 4662 with the Get-Changes GUIDs from any principal that is not a DC;\n  replication requests sourced from non-DC IPs.\n- **Remediation**: audit and minimize who holds Get-Changes / Get-Changes-All; alert on\n  replication from non-DC sources; tier-0 isolation.\n\n---\n\n## LSASS dumping: blocked by EDR\n\nDumping process memory of `lsass.exe` to extract credentials.\n\n- Modern EDR in blocking mode (CrowdStrike Falcon, SentinelOne, Defender for Endpoint)\n  intercepts `MiniDumpWriteDump` against lsass. The result is a blocked/empty dump, a\n  crashed process, or an immediate alert naming your tool.\n- **Event 4688** (process creation) plus EDR-specific handle-to-lsass telemetry.\n\n**Alternatives that avoid touching lsass live:**\n\n- SAM/SYSTEM/SECURITY registry hive dump (local admin) → offline parsing.\n- DPAPI offline extraction.\n- Volume Shadow Copy of the hive + offline parse.\n- gMSA / LAPS fetch over LDAP (no endpoint touch at all).\n\n```bash\n# Registry-hive route: avoids a live lsass handle\nsecretsdump.py -sam sam.save -system system.save LOCAL\n```\n\n- **MITRE**: T1003.001 (LSASS Memory).\n- **Defender watch**: process handles opened to lsass with read/VM-read access; EDR\n  memory-access alerts.\n- **Remediation**: Credential Guard; LSASS as a protected process (RunAsPPL); EDR in\n  blocking mode.\n\n---\n\n## BloodHound collection: a recognizable LDAP signature\n\n- Collector queries have well-known shapes: `(objectCategory=computer)` pulling dozens of\n  attributes, plus queries for `msDS-AllowedToDelegateTo`, delegation and ACL attributes in\n  bulk.\n- MDI and legacy ATA carry specific detection for BloodHound-style enumeration.\n- Quieter collection requests only the attributes it needs (never `*`) and spreads queries\n  over time instead of firing them all at connect.\n\n- **MITRE**: T1087 (Account Discovery), T1069 (Permission Groups Discovery).\n- **Defender watch**: a single principal issuing large attribute-heavy LDAP sweeps in a\n  short window.\n\n---\n\n## Lateral movement: telemetry by protocol\n\nWhen you need remote execution, the protocol you pick determines the noise. From loudest to\nquietest:\n\n| Protocol | Telemetry | OPSEC note |\n|---|---|---|\n| PsExec (SCM service install) | **Event 7045** service install — very visible, routinely EDR-blocked | Avoid when EDR is active |\n| WMI exec | **Event 4688** process create — MDE detects | Quieter than PsExec |\n| Scheduled task | **Event 4698/4702** task created — moderately visible | Acceptable |\n| WinRM / PSRemoting | Legitimate channel, but **Event 4624** logon type 3 + PowerShell logs | Preferred when available |\n| DCOM / MMC | Fewer known signatures | Best profile under EDR |\n\n- **MITRE**: T1021 (Remote Services) and subtechniques; T1569.002 (Service Execution);\n  T1053.005 (Scheduled Task); T1047 (WMI).\n- **Rule**: record which protocol you used and its profile in the report, so the client can\n  correlate with their endpoint logs.\n\n---\n\n## Coercion and NTLM relay: high-volume auth noise\n\n- Coercion (PetitPotam, PrinterBug, DFSCoerce) forces a target to authenticate to you,\n  producing inbound auth requests visible in SIEM. Coercing at scale generates hundreds of\n  auth events.\n- `ntlmrelayx` in automatic mode can capture credentials of real users in production, so\n  coordinate before running it against a live environment.\n\n- **MITRE**: T1187 (Forced Authentication), T1557.001 (LLMNR/NBT-NS Poisoning and SMB Relay).\n- **Defender watch**: spikes of inbound authentications to a non-standard host; EFSRPC /\n  spoolss / DFS RPC calls to unexpected destinations.\n- **Remediation**: SMB signing enforced; LDAP channel binding; EPA on AD CS web endpoints;\n  disable spooler on DCs.\n\n---\n\n## SMB null sessions: reconnaissance signal\n\n- Windows Server 2016+ disables null sessions by default; some SOCs alert on the attempt as\n  anonymous recon.\n- When you hold credentials, always use them. Null session is a last-resort fallback only,\n  and worth documenting when used.\n\n- **MITRE**: T1135 (Network Share Discovery), T1087.\n\n---\n\n## Actions that require explicit coordination\n\nShow a warning and get sign-off (or document that it ran) before any of these:\n\n| Action | Why |\n|---|---|\n| DCSync | Critical MDI alert; your IP visible in DC logs |\n| Password spraying | Risk of locking out real accounts |\n| ntlmrelayx (auto) | May capture real users' credentials in production |\n| Coercion at scale | Hundreds of auth requests, SIEM-visible |\n| Kerberoasting all accounts | MDI volume alert; document targeted accounts |\n| LSASS dump | EDR-detectable; risk of crashing the process |\n\n---\n\n## How to use this\n\nRunning a technique: check its row, warn the client about the events it will generate, and\nprefer the quieter equivalent when there is one (WMI over PsExec, one SPN over the whole\ndomain, registry-hive over live lsass). Writing the report: turn these tables into the\ndetection-and-remediation section so the defender can find every action you took and close\nthe gap that let it work.\n","tagline":"The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the DS-Replication-Get-Changes GUID, AS-REP roasting produces Event 4768 with no pre-","category":"design-creative","tags":["agent-skill"],"author":"ADScanPro","verified":false,"attribution":{"status":"registry_indexed","statusLabel":"Registry indexed","shortLabel":"REGISTRY INDEXED","sourceLabel":"github fast track","sourceDetail":"ADScanPro/Claude-AD","creatorName":"ADScanPro","creatorUrl":"https://github.com/ADScanPro","sourceUrl":"https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry","indexedBy":"OpenAgentSkill community index","claimUrl":"https://www.openagentskill.com/skills/adscanpro-ad-opsec-telemetry#claim-this-skill","claimCta":"Claim this skill","trustNote":"This listing was indexed from public sources and is not marked official until a maintainer claim is approved.","publicNote":"Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals."},"stats":{"stars":153,"forks":24,"verified_installs":0,"successful_runs":0,"total_outcomes":0,"rating":0,"review_count":0,"quality_score":38.41},"quality":{"score":68,"tier":"promising","label":"Promising","summary":"Useful candidate, but compare it with alternatives before adopting.","signals":[{"label":"GitHub stars","value":"153","tone":"neutral"},{"label":"Freshness","value":"12d ago","tone":"positive"},{"label":"Install ready","value":"Yes","tone":"positive"},{"label":"License","value":"MIT","tone":"neutral"}],"warnings":[]},"trust":{"version":"trust-score-v5","score":65,"base_score":73,"outcome_confidence":0,"tier":"review","label":"Sandbox only","summary":"Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.","recommendedAction":"Run only in a sandbox and compare close alternatives before using it for real work.","decision":{"install_policy":"human_review_before_install","auto_install_allowed":false,"human_review_required":true,"sandbox_first":true,"agent_action":"Compare alternatives before installing.","reasoning":["65/100 Trust Score v5","73/100 Trust Score v4 baseline","Needs more real agent outcomes before unattended install","Install path is available","Review before production"],"review_required_when":["The workspace contains production secrets, payments, private customer data, or irreversible actions.","The install command requests shell, network, credential, database, or broad filesystem access.","Outcome evidence is missing, recently failed, or required human review.","Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"]},"dimensions":[{"id":"github_adoption","label":"GitHub adoption","score":62,"weight":0.13,"status":"info","detail":"153 GitHub stars"},{"id":"repo_activity","label":"Stars/forks activity","score":57,"weight":0.08,"status":"warn","detail":"153 stars, 24 forks; issue activity unavailable in current metadata"},{"id":"maintenance","label":"Recent maintenance","score":100,"weight":0.14,"status":"pass","detail":"12d since push"},{"id":"license","label":"License clarity","score":86,"weight":0.09,"status":"pass","detail":"MIT"},{"id":"documentation","label":"README/SKILL.md completeness","score":86,"weight":0.14,"status":"pass","detail":"Metadata includes enough usage and workflow context"},{"id":"dependency_risk","label":"Dependency/runtime risk","score":46,"weight":0.12,"status":"warn","detail":"command execution surface, credential or environment access"},{"id":"installability","label":"Install availability","score":92,"weight":0.1,"status":"pass","detail":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry"},{"id":"install_safety","label":"Install command safety","score":92,"weight":0.1,"status":"pass","detail":"standard package or runtime install path"},{"id":"permission_surface","label":"Permission surface","score":22,"weight":0.07,"status":"fail","detail":"secrets or environment access, shell or command execution"},{"id":"repository","label":"Repository evidence","score":86,"weight":0.04,"status":"pass","detail":"https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry"},{"id":"review_status","label":"Review status","score":88,"weight":0.05,"status":"pass","detail":"AI review data available"},{"id":"agent_outcomes","label":"Agent Proven outcomes","score":54,"weight":0.13,"status":"info","detail":"No agent outcome data yet"}],"checks":[{"status":"info","label":"GitHub adoption","detail":"153 GitHub stars"},{"status":"warn","label":"Stars/forks activity","detail":"153 stars, 24 forks; issue activity unavailable in current metadata"},{"status":"pass","label":"Recent maintenance","detail":"12d since push"},{"status":"pass","label":"License clarity","detail":"MIT"},{"status":"pass","label":"README/SKILL.md completeness","detail":"Metadata includes enough usage and workflow context"},{"status":"warn","label":"Dependency/runtime risk","detail":"command execution surface, credential or environment access"},{"status":"pass","label":"Install availability","detail":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry"},{"status":"pass","label":"Install command safety","detail":"standard package or runtime install path"},{"status":"fail","label":"Permission surface","detail":"secrets or environment access, shell or command execution"},{"status":"pass","label":"Repository evidence","detail":"https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry"},{"status":"pass","label":"Review status","detail":"AI review data available"},{"status":"info","label":"Agent Proven outcomes","detail":"No agent outcome data yet"},{"status":"warn","label":"Ownership","detail":"No approved owner claim yet"},{"status":"info","label":"OpenAgentSkill usage","detail":"No local usage activity yet"},{"status":"info","label":"Agent outcomes","detail":"No agent outcome data yet"}],"strengths":["AI review approved","Install path is available","Repository evidence is available","Recently maintained repository","Install command has no obvious high-risk pattern","Outcome loop is ready but needs first real agent run"],"warnings":["Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","Stars/forks activity: 153 stars, 24 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution","No real agent outcome reports yet","Human review required before unattended installation"],"evidence":{"stars":"153 GitHub stars","repoActivity":"153 stars, 24 forks","lastPushed":"12d since push","license":"MIT","repository":"https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry","install":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry","installSafety":"standard package or runtime install path","permissionSurface":"secrets or environment access, shell or command execution","documentation":"Strong README/SKILL.md context","agentOutcomes":"No agent outcome data yet","agentProvenScore":0,"outcomeConfidence":"0%","installPolicy":"human_review_before_install"},"installReadiness":{"ready":true,"command":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry","policy":"human_review_before_install","label":"Human review before install","notes":["Install path is available","Repository evidence is available","License is declared","No Agent Proven outcome evidence yet","12d since push","Trust Score v5 requires review or sandbox-only use before install."]},"agentCompatibility":["Codex","Claude Code","Cursor","OpenAgentSkill CLI"],"riskSummary":{"level":"medium","label":"Review before production","notes":["Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","Stars/forks activity: 153 stars, 24 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"]},"outcomeEvidence":{"total":0,"successes":0,"failures":0,"notRelevant":0,"successRate":null,"installAttempts":0,"riskBlocked":0,"setupRequired":0,"installSuccessRate":null,"avgOutputQuality":null,"avgTimeToUsefulMs":null,"productionOutcomes":0,"humanReviewRequired":0,"recentSuccessRate":null,"recentFailureRate":null,"uniqueAgents":0,"agentProvenScore":0,"agentProvenLabel":"Needs first agent run","lastOutcomeAt":null,"label":"No agent outcome data yet"},"autoInstall":{"allowed":false,"sandboxRequired":true,"policy":"human_review_before_install","reason":"Compare alternatives before installing."},"outcome_loop":{"version":"openagentskill-agent-outcome-v4","required_after_install":true,"endpoint":"/api/agent/outcome","method":"POST","event_id_source":"feedback.event_id, install_receipt.resolve_event_id, or decision_packet.outcome_feedback.event_id","expected_outcomes":["success","failed","not_relevant","blocked_by_risk","setup_required"],"required_fields":["event_id","skill_slug","task"],"quality_fields":["task_success","output_quality","error_type","human_review_required","used_in_production","workspace","evidence_url","time_to_useful_ms","source_version"],"ranking_inputs_updated":["Trust Score v5 outcome confidence","Agent Proven Score","Resolve ranking task-fit evidence","Skill detail machine-readable metadata","Outcome leaderboard"]},"agent_contract":{"suited_tasks":["design-creative","agent-skill"],"suited_agents":["Codex","Claude Code","Cursor","OpenAgentSkill CLI"],"install_command":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry","trust_score":65,"trust_version":"trust-score-v5","risk_level":"medium","do_not_use_when":["Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"],"before_install":["Read the audit page and machine-readable metadata.","Confirm the install command, license, and permission surface fit the workspace.","Get explicit human approval or choose an alternative before installing."],"after_run":["Report the outcome to /api/agent/outcome using the resolve event id.","Include output_quality, workspace, human_review_required, and evidence_url when available.","Re-resolve before broad production rollout."]},"bestFor":["design-creative","agent-skill"],"doNotUseFor":["Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"],"knownRisks":["Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","Stars/forks activity: 153 stars, 24 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"],"backward_compatible":{"trust_score_v4":{"version":"trust-score-v4","score":73,"tier":"strong","label":"Strong shortlist","summary":"Good trust signals with a few areas worth checking before rollout."}}},"trust_score_v5":{"version":"trust-score-v5","score":65,"base_score":73,"outcome_confidence":0,"tier":"review","label":"Sandbox only","summary":"Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.","recommendedAction":"Run only in a sandbox and compare close alternatives before using it for real work.","decision":{"install_policy":"human_review_before_install","auto_install_allowed":false,"human_review_required":true,"sandbox_first":true,"agent_action":"Compare alternatives before installing.","reasoning":["65/100 Trust Score v5","73/100 Trust Score v4 baseline","Needs more real agent outcomes before unattended install","Install path is available","Review before production"],"review_required_when":["The workspace contains production secrets, payments, private customer data, or irreversible actions.","The install command requests shell, network, credential, database, or broad filesystem access.","Outcome evidence is missing, recently failed, or required human review.","Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"]},"dimensions":[{"id":"github_adoption","label":"GitHub adoption","score":62,"weight":0.13,"status":"info","detail":"153 GitHub stars"},{"id":"repo_activity","label":"Stars/forks activity","score":57,"weight":0.08,"status":"warn","detail":"153 stars, 24 forks; issue activity unavailable in current metadata"},{"id":"maintenance","label":"Recent maintenance","score":100,"weight":0.14,"status":"pass","detail":"12d since push"},{"id":"license","label":"License clarity","score":86,"weight":0.09,"status":"pass","detail":"MIT"},{"id":"documentation","label":"README/SKILL.md completeness","score":86,"weight":0.14,"status":"pass","detail":"Metadata includes enough usage and workflow context"},{"id":"dependency_risk","label":"Dependency/runtime risk","score":46,"weight":0.12,"status":"warn","detail":"command execution surface, credential or environment access"},{"id":"installability","label":"Install availability","score":92,"weight":0.1,"status":"pass","detail":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry"},{"id":"install_safety","label":"Install command safety","score":92,"weight":0.1,"status":"pass","detail":"standard package or runtime install path"},{"id":"permission_surface","label":"Permission surface","score":22,"weight":0.07,"status":"fail","detail":"secrets or environment access, shell or command execution"},{"id":"repository","label":"Repository evidence","score":86,"weight":0.04,"status":"pass","detail":"https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry"},{"id":"review_status","label":"Review status","score":88,"weight":0.05,"status":"pass","detail":"AI review data available"},{"id":"agent_outcomes","label":"Agent Proven outcomes","score":54,"weight":0.13,"status":"info","detail":"No agent outcome data yet"}],"checks":[{"status":"info","label":"GitHub adoption","detail":"153 GitHub stars"},{"status":"warn","label":"Stars/forks activity","detail":"153 stars, 24 forks; issue activity unavailable in current metadata"},{"status":"pass","label":"Recent maintenance","detail":"12d since push"},{"status":"pass","label":"License clarity","detail":"MIT"},{"status":"pass","label":"README/SKILL.md completeness","detail":"Metadata includes enough usage and workflow context"},{"status":"warn","label":"Dependency/runtime risk","detail":"command execution surface, credential or environment access"},{"status":"pass","label":"Install availability","detail":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry"},{"status":"pass","label":"Install command safety","detail":"standard package or runtime install path"},{"status":"fail","label":"Permission surface","detail":"secrets or environment access, shell or command execution"},{"status":"pass","label":"Repository evidence","detail":"https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry"},{"status":"pass","label":"Review status","detail":"AI review data available"},{"status":"info","label":"Agent Proven outcomes","detail":"No agent outcome data yet"},{"status":"warn","label":"Ownership","detail":"No approved owner claim yet"},{"status":"info","label":"OpenAgentSkill usage","detail":"No local usage activity yet"},{"status":"info","label":"Agent outcomes","detail":"No agent outcome data yet"}],"strengths":["AI review approved","Install path is available","Repository evidence is available","Recently maintained repository","Install command has no obvious high-risk pattern","Outcome loop is ready but needs first real agent run"],"warnings":["Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","Stars/forks activity: 153 stars, 24 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution","No real agent outcome reports yet","Human review required before unattended installation"],"evidence":{"stars":"153 GitHub stars","repoActivity":"153 stars, 24 forks","lastPushed":"12d since push","license":"MIT","repository":"https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry","install":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry","installSafety":"standard package or runtime install path","permissionSurface":"secrets or environment access, shell or command execution","documentation":"Strong README/SKILL.md context","agentOutcomes":"No agent outcome data yet","agentProvenScore":0,"outcomeConfidence":"0%","installPolicy":"human_review_before_install"},"installReadiness":{"ready":true,"command":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry","policy":"human_review_before_install","label":"Human review before install","notes":["Install path is available","Repository evidence is available","License is declared","No Agent Proven outcome evidence yet","12d since push","Trust Score v5 requires review or sandbox-only use before install."]},"agentCompatibility":["Codex","Claude Code","Cursor","OpenAgentSkill CLI"],"riskSummary":{"level":"medium","label":"Review before production","notes":["Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","Stars/forks activity: 153 stars, 24 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"]},"outcomeEvidence":{"total":0,"successes":0,"failures":0,"notRelevant":0,"successRate":null,"installAttempts":0,"riskBlocked":0,"setupRequired":0,"installSuccessRate":null,"avgOutputQuality":null,"avgTimeToUsefulMs":null,"productionOutcomes":0,"humanReviewRequired":0,"recentSuccessRate":null,"recentFailureRate":null,"uniqueAgents":0,"agentProvenScore":0,"agentProvenLabel":"Needs first agent run","lastOutcomeAt":null,"label":"No agent outcome data yet"},"autoInstall":{"allowed":false,"sandboxRequired":true,"policy":"human_review_before_install","reason":"Compare alternatives before installing."},"outcome_loop":{"version":"openagentskill-agent-outcome-v4","required_after_install":true,"endpoint":"/api/agent/outcome","method":"POST","event_id_source":"feedback.event_id, install_receipt.resolve_event_id, or decision_packet.outcome_feedback.event_id","expected_outcomes":["success","failed","not_relevant","blocked_by_risk","setup_required"],"required_fields":["event_id","skill_slug","task"],"quality_fields":["task_success","output_quality","error_type","human_review_required","used_in_production","workspace","evidence_url","time_to_useful_ms","source_version"],"ranking_inputs_updated":["Trust Score v5 outcome confidence","Agent Proven Score","Resolve ranking task-fit evidence","Skill detail machine-readable metadata","Outcome leaderboard"]},"agent_contract":{"suited_tasks":["design-creative","agent-skill"],"suited_agents":["Codex","Claude Code","Cursor","OpenAgentSkill CLI"],"install_command":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry","trust_score":65,"trust_version":"trust-score-v5","risk_level":"medium","do_not_use_when":["Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"],"before_install":["Read the audit page and machine-readable metadata.","Confirm the install command, license, and permission surface fit the workspace.","Get explicit human approval or choose an alternative before installing."],"after_run":["Report the outcome to /api/agent/outcome using the resolve event id.","Include output_quality, workspace, human_review_required, and evidence_url when available.","Re-resolve before broad production rollout."]},"bestFor":["design-creative","agent-skill"],"doNotUseFor":["Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"],"knownRisks":["Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","Stars/forks activity: 153 stars, 24 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"],"backward_compatible":{"trust_score_v4":{"version":"trust-score-v4","score":73,"tier":"strong","label":"Strong shortlist","summary":"Good trust signals with a few areas worth checking before rollout."}}},"trust_score_v4":{"version":"trust-score-v4","score":73,"tier":"strong","label":"Strong shortlist","summary":"Good trust signals with a few areas worth checking before rollout.","recommendedAction":"Test in a sandbox workflow and compare its install path with close alternatives.","dimensions":[{"id":"github_adoption","label":"GitHub adoption","score":62,"weight":0.13,"status":"info","detail":"153 GitHub stars"},{"id":"repo_activity","label":"Stars/forks activity","score":57,"weight":0.08,"status":"warn","detail":"153 stars, 24 forks; issue activity unavailable in current metadata"},{"id":"maintenance","label":"Recent maintenance","score":100,"weight":0.14,"status":"pass","detail":"12d since push"},{"id":"license","label":"License clarity","score":86,"weight":0.09,"status":"pass","detail":"MIT"},{"id":"documentation","label":"README/SKILL.md completeness","score":86,"weight":0.14,"status":"pass","detail":"Metadata includes enough usage and workflow context"},{"id":"dependency_risk","label":"Dependency/runtime risk","score":46,"weight":0.12,"status":"warn","detail":"command execution surface, credential or environment access"},{"id":"installability","label":"Install availability","score":92,"weight":0.1,"status":"pass","detail":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry"},{"id":"install_safety","label":"Install command safety","score":92,"weight":0.1,"status":"pass","detail":"standard package or runtime install path"},{"id":"permission_surface","label":"Permission surface","score":22,"weight":0.07,"status":"fail","detail":"secrets or environment access, shell or command execution"},{"id":"repository","label":"Repository evidence","score":86,"weight":0.04,"status":"pass","detail":"https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry"},{"id":"review_status","label":"Review status","score":88,"weight":0.05,"status":"pass","detail":"AI review data available"},{"id":"agent_outcomes","label":"Agent Proven outcomes","score":54,"weight":0.13,"status":"info","detail":"No agent outcome data yet"}],"checks":[{"status":"info","label":"GitHub adoption","detail":"153 GitHub stars"},{"status":"warn","label":"Stars/forks activity","detail":"153 stars, 24 forks; issue activity unavailable in current metadata"},{"status":"pass","label":"Recent maintenance","detail":"12d since push"},{"status":"pass","label":"License clarity","detail":"MIT"},{"status":"pass","label":"README/SKILL.md completeness","detail":"Metadata includes enough usage and workflow context"},{"status":"warn","label":"Dependency/runtime risk","detail":"command execution surface, credential or environment access"},{"status":"pass","label":"Install availability","detail":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry"},{"status":"pass","label":"Install command safety","detail":"standard package or runtime install path"},{"status":"fail","label":"Permission surface","detail":"secrets or environment access, shell or command execution"},{"status":"pass","label":"Repository evidence","detail":"https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry"},{"status":"pass","label":"Review status","detail":"AI review data available"},{"status":"info","label":"Agent Proven outcomes","detail":"No agent outcome data yet"},{"status":"warn","label":"Ownership","detail":"No approved owner claim yet"},{"status":"info","label":"OpenAgentSkill usage","detail":"No local usage activity yet"},{"status":"info","label":"Agent outcomes","detail":"No agent outcome data yet"}],"strengths":["AI review approved","Install path is available","Repository evidence is available","Recently maintained repository","Install command has no obvious high-risk pattern"],"warnings":["Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","Stars/forks activity: 153 stars, 24 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"],"evidence":{"stars":"153 GitHub stars","repoActivity":"153 stars, 24 forks","lastPushed":"12d since push","license":"MIT","repository":"https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry","install":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry","installSafety":"standard package or runtime install path","permissionSurface":"secrets or environment access, shell or command execution","documentation":"Strong README/SKILL.md context","agentOutcomes":"No agent outcome data yet"},"installReadiness":{"ready":true,"command":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry","policy":"human_review_before_install","label":"Human review before install","notes":["Install path is available","Repository evidence is available","License is declared","No Agent Proven outcome evidence yet","12d since push"]},"agentCompatibility":["Codex","Claude Code","Cursor","OpenAgentSkill CLI"],"riskSummary":{"level":"medium","label":"Review before production","notes":["Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","Stars/forks activity: 153 stars, 24 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"]},"outcomeEvidence":{"total":0,"successes":0,"failures":0,"notRelevant":0,"successRate":null,"installAttempts":0,"riskBlocked":0,"setupRequired":0,"installSuccessRate":null,"avgOutputQuality":null,"avgTimeToUsefulMs":null,"productionOutcomes":0,"humanReviewRequired":0,"recentSuccessRate":null,"recentFailureRate":null,"uniqueAgents":0,"agentProvenScore":0,"agentProvenLabel":"Needs first agent run","lastOutcomeAt":null,"label":"No agent outcome data yet"},"autoInstall":{"allowed":false,"sandboxRequired":true,"policy":"human_review_before_install","reason":"Human review or sandbox validation is required before automatic installation."},"bestFor":["design-creative","agent-skill"],"doNotUseFor":["Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"],"knownRisks":["Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","Stars/forks activity: 153 stars, 24 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"]},"agent_proven":{"version":"agent-proven-v1","score":0,"tier":"unproven","label":"Needs first agent run","summary":"No agent outcome reports yet. Use Resolve, run one narrow sandbox task, then report the result.","metrics":{"totalOutcomes":0,"successfulOutcomes":0,"failedOutcomes":0,"installAttempts":0,"installSuccessRate":null,"successRate":null,"recentSuccessRate":null,"recentFailureRate":null,"riskBlocked":0,"setupRequired":0,"notRelevant":0,"avgOutputQuality":null,"avgTimeToUsefulMs":null,"productionOutcomes":0,"humanReviewRequired":0,"uniqueAgents":0,"lastOutcomeAt":null},"signals":[],"penalties":["No real agent outcome evidence yet"]},"outcome_stats":null,"safety":{"score":38,"level":"avoid_auto_install","label":"Avoid automatic install","safety_tier":{"tier":"blocked","label":"Blocked for auto-install","badge":"BLOCKED","summary":"This skill should not be selected by an agent without explicit human security review.","recommended_action":"Do not auto-install. Inspect the source, dependencies, and permission surface first.","auto_install_policy":"block","reasons":["Metadata combines secrets access with shell or command execution","High-risk permission hints: Shell or command execution, Secrets or environment access"]},"auto_install_allowed":false,"human_review_required":true,"blocked":true,"audit_risk":"needs_review","permission_hints":[{"id":"shell","label":"Shell or command execution","reason":"Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.","severity":"high"},{"id":"network","label":"Network access","reason":"Skill likely fetches remote pages, APIs, repositories, or external services.","severity":"medium"},{"id":"filesystem","label":"Filesystem access","reason":"Skill may read or write project files, documents, generated artifacts, or local workspace state.","severity":"medium"},{"id":"secrets","label":"Secrets or environment access","reason":"Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.","severity":"high"}],"policy_warnings":["High-risk permission hints: Shell or command execution, Secrets or environment access","Dependency or permission surface needs review"],"constraints_applied":{"max_risk":"medium","needs_install_command":true,"min_stars":0}},"safety_gate":{"tier":"blocked","label":"Blocked for auto-install","badge":"BLOCKED","auto_install_policy":"block","auto_install_allowed":false,"blocked":true,"human_review_required":true,"recommended_action":"Do not auto-install. Inspect the source, dependencies, and permission surface first.","reasons":["Metadata combines secrets access with shell or command execution","High-risk permission hints: Shell or command execution, Secrets or environment access"]},"eval":{"version":"openagentskill-skill-eval-v1","status":"failed","score":67,"risk_level":"high","decision":{"recommendation":"do_not_auto_install","reason":"Agent safety gate: This skill should not be selected by an agent without explicit human security review.","auto_install_allowed":false,"policy":"block","human_review_required":true},"blockers":["Agent safety gate: This skill should not be selected by an agent without explicit human security review.","Permission surface: secrets or environment access, shell or command execution"],"warnings":["Trust score: Good trust signals with a few areas worth checking before rollout.","Audit score: Needs review","High-risk permission hints: Shell or command execution, Secrets or environment access","Dependency or permission surface needs review","Permission surface may require sandboxing","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","Stars/forks activity: 153 stars, 24 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"],"validation_plan":["Inspect repository, README/SKILL.md, license, and recent commits before production use.","Install in an isolated workspace or sandbox with no production secrets available.","Run the smallest representative task and record files touched, commands run, network access, and outputs.","Compare the selected skill against at least one alternative when the eval status is review or failed.","Promote only after the agent reports a successful verification result and unresolved warnings are accepted."],"checks":[{"id":"task_fit","label":"Task fit","status":"pass","score":84,"required_for_auto_install":true,"detail":"Task wording matches this skill metadata.","evidence":["Evaluate ad-opsec-telemetry before installing it in an agent workflow","design-creative","Document processing workflows; Claude Code teams; builders willing to evaluate younger projects"]},{"id":"install_path","label":"Install path","status":"pass","score":92,"required_for_auto_install":true,"detail":"Install handoff is available.","evidence":["npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry"]},{"id":"install_safety","label":"Install command safety","status":"pass","score":92,"required_for_auto_install":true,"detail":"standard package or runtime install path","evidence":["npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry"]},{"id":"trust_score","label":"Trust score","status":"warn","score":73,"required_for_auto_install":true,"detail":"Good trust signals with a few areas worth checking before rollout.","evidence":["Strong shortlist","153 GitHub stars","MIT"]},{"id":"audit_score","label":"Audit score","status":"warn","score":78,"required_for_auto_install":true,"detail":"Needs review","evidence":["Dependency or permission surface needs review"]},{"id":"agent_safety_gate","label":"Agent safety gate","status":"fail","score":38,"required_for_auto_install":true,"detail":"This skill should not be selected by an agent without explicit human security review.","evidence":["Do not auto-install. Inspect the source, dependencies, and permission surface first.","Metadata combines secrets access with shell or command execution"]},{"id":"readme_skillmd_completeness","label":"README/SKILL.md completeness","status":"pass","score":86,"required_for_auto_install":false,"detail":"Metadata includes enough usage and workflow context","evidence":["Strong README/SKILL.md context"]},{"id":"license_clarity","label":"License clarity","status":"pass","score":86,"required_for_auto_install":true,"detail":"MIT","evidence":["MIT"]},{"id":"recent_maintenance","label":"Recent maintenance","status":"pass","score":100,"required_for_auto_install":false,"detail":"12d since push","evidence":["12d since push"]},{"id":"permission_surface","label":"Permission surface","status":"fail","score":22,"required_for_auto_install":true,"detail":"secrets or environment access, shell or command execution","evidence":["Shell or command execution: high","Network access: medium","Filesystem access: medium"]},{"id":"alternatives","label":"Alternatives available","status":"info","score":55,"required_for_auto_install":false,"detail":"No close alternatives were found in the current shortlist.","evidence":[]}],"endpoints":{"web":"https://www.openagentskill.com/skills/adscanpro-ad-opsec-telemetry/evals","api":"/api/agent/evals?slug=adscanpro-ad-opsec-telemetry","text":"/api/agent/evals?slug=adscanpro-ad-opsec-telemetry&format=text"}},"agent_readable_metadata":{"version":"openagentskill-agent-metadata-v2","skill":{"slug":"adscanpro-ad-opsec-telemetry","name":"ad-opsec-telemetry","description":"The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the DS-Replication-Get-Changes GUID, AS-REP roasting produces Event 4768 with no pre-auth, LSASS dumping is blocked by EDR, plus a lateral-movement telemetry table by protocol (SMB/WMI/WinRM/RDP/DCOM). Use this whenever you run or plan an offensive AD technique and need to know what noise it makes, when writing the engagement's detection notes, or when a defender wants to know what to monitor. Teaches red teamers what is loud and blue teamers what to watch. Standard-tooling knowledge, no vendor engine.","category":"design-creative","url":"https://www.openagentskill.com/skills/adscanpro-ad-opsec-telemetry","repository":"https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry","github_repo":"ADScanPro/Claude-AD"},"suited_tasks":["Document processing workflows","Claude Code teams","builders willing to evaluate younger projects","Read uploaded files","Extract structured fields","Prepare clean context for downstream agents","Navigate pages","Click and type safely"],"suited_agents":["Codex","Claude Code","Cursor","OpenAgentSkill CLI","CLI"],"install":{"command":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry","ready":true,"targets":[{"id":"openagentskill-cli","label":"CLI","kind":"command","value":"npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.3.0/openagentskill-0.3.0.tgz add adscanpro-ad-opsec-telemetry"},{"id":"codex","label":"Codex","kind":"agent-prompt","value":"Install the \"ad-opsec-telemetry\" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the DS-Replication-Get-Changes GUID, AS-REP roasting produces Event 4768 with no pre-auth, LSASS dumping is blocked by EDR, plus a lateral-movement telemetry table by protocol (SMB/WMI/WinRM/RDP/DCOM). Use this whenever you run or plan an offensive AD technique and need to know what noise it makes, when writing the engagement's detection notes, or when a defender wants to know what to monitor. Teaches red teamers what is loud and blue teamers what to watch. Standard-tooling knowledge, no vendor engine. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"adscanpro-ad-opsec-telemetry\",\"task\":\"Install ad-opsec-telemetry\",\"agent\":\"codex\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes."},{"id":"claude-code","label":"Claude Code","kind":"agent-prompt","value":"Add \"ad-opsec-telemetry\" as a Claude Code skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry. Inspect the skill instructions, place the reusable skill files in the appropriate local skills location for this project, and report the activation steps. Skill purpose: The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the DS-Replication-Get-Changes GUID, AS-REP roasting produces Event 4768 with no pre-auth, LSASS dumping is blocked by EDR, plus a lateral-movement telemetry table by protocol (SMB/WMI/WinRM/RDP/DCOM). Use this whenever you run or plan an offensive AD technique and need to know what noise it makes, when writing the engagement's detection notes, or when a defender wants to know what to monitor. Teaches red teamers what is loud and blue teamers what to watch. Standard-tooling knowledge, no vendor engine. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"adscanpro-ad-opsec-telemetry\",\"task\":\"Install ad-opsec-telemetry\",\"agent\":\"claude-code\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes."},{"id":"cursor","label":"Cursor","kind":"agent-prompt","value":"Turn \"ad-opsec-telemetry\" from https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry into a reusable Cursor project rule or agent instruction. Preserve the core workflow, adapt paths to this repo, and keep the rule scoped to tasks where it is relevant. Skill purpose: The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the DS-Replication-Get-Changes GUID, AS-REP roasting produces Event 4768 with no pre-auth, LSASS dumping is blocked by EDR, plus a lateral-movement telemetry table by protocol (SMB/WMI/WinRM/RDP/DCOM). Use this whenever you run or plan an offensive AD technique and need to know what noise it makes, when writing the engagement's detection notes, or when a defender wants to know what to monitor. Teaches red teamers what is loud and blue teamers what to watch. Standard-tooling knowledge, no vendor engine. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"adscanpro-ad-opsec-telemetry\",\"task\":\"Install ad-opsec-telemetry\",\"agent\":\"cursor\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes."}],"handoff_url":"https://www.openagentskill.com/api/skills/adscanpro-ad-opsec-telemetry/install","manifest_url":"https://www.openagentskill.com/api/registry/manifest/adscanpro-ad-opsec-telemetry"},"trust":{"score":73,"label":"Strong shortlist","version":"trust-score-v4","install_policy":"human_review_before_install","evidence":{"stars":"153 GitHub stars","repoActivity":"153 stars, 24 forks","lastPushed":"12d since push","license":"MIT","repository":"https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry","install":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry","installSafety":"standard package or runtime install path","permissionSurface":"secrets or environment access, shell or command execution","documentation":"Strong README/SKILL.md context","agentOutcomes":"No agent outcome data yet"},"outcome_evidence":{"total":0,"successes":0,"failures":0,"not_relevant":0,"success_rate":null,"recent_success_rate":null,"recent_failure_rate":null,"install_attempts":0,"install_success_rate":null,"risk_blocked":0,"setup_required":0,"avg_output_quality":null,"production_outcomes":0,"last_outcome_at":null,"label":"No agent outcome data yet"},"auto_install":{"allowed":false,"sandbox_required":true,"reason":"Human review or sandbox validation is required before automatic installation."},"best_for":["design-creative","agent-skill"],"known_risks":["Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","Stars/forks activity: 153 stars, 24 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"]},"agent_proven":{"version":"agent-proven-v1","score":0,"tier":"unproven","label":"Needs first agent run","summary":"No agent outcome reports yet. Use Resolve, run one narrow sandbox task, then report the result.","metrics":{"totalOutcomes":0,"successfulOutcomes":0,"failedOutcomes":0,"installAttempts":0,"installSuccessRate":null,"successRate":null,"recentSuccessRate":null,"recentFailureRate":null,"riskBlocked":0,"setupRequired":0,"notRelevant":0,"avgOutputQuality":null,"avgTimeToUsefulMs":null,"productionOutcomes":0,"humanReviewRequired":0,"uniqueAgents":0,"lastOutcomeAt":null},"signals":[],"penalties":["No real agent outcome evidence yet"]},"audit":{"score":78,"risk_level":"needs_review","risk_label":"Needs review","warnings":["Dependency or permission surface needs review","Permission surface may require sandboxing","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","Stars/forks activity: 153 stars, 24 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"]},"safety_gate":{"tier":"blocked","label":"Blocked for auto-install","auto_install_policy":"block","auto_install_allowed":false,"human_review_required":true,"blocked":true,"recommended_action":"Do not auto-install. Inspect the source, dependencies, and permission surface first."},"quality":{"score":68,"label":"Promising"},"supply":{"track":"Coding and developer agents","scenario":"GitHub automation","maintenance":"12d since push","risk":"Needs review"},"alternative_skills":[],"do_not_use_when":["teams that need a vendor-supported SLA","high-compliance environments without internal security review","No OpenAgentSkill engagement data yet","High-risk permission hints: Shell or command execution, Secrets or environment access","Dependency or permission surface needs review","Permission surface may require sandboxing","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution"],"agent_contract":{"task_input":"Use ad-opsec-telemetry in an agent workflow","recommended_action":"Do not auto-install. Inspect the source, dependencies, and permission surface first.","install_policy":"block","minimum_review_before_use":["Trust: 73/100 Strong shortlist","Audit: 78/100 Needs review","Safety: 38/100 Avoid automatic install","Review repository, license, install command, and permission surface before production use."],"expected_agent_output":{"selected_skill":"adscanpro-ad-opsec-telemetry (ad-opsec-telemetry)","install_command":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry","risk_summary":"Needs review; Blocked for auto-install; Review before production","verification_result":"Report the smallest successful task, files touched, warnings, and any missing setup."}},"outcome_feedback":{"endpoint":"https://www.openagentskill.com/api/agent/outcome","method":"POST","requires_resolve_event_id":true,"event_id_source":"Use install_receipt.outcome_feedback.event_id or feedback.event_id returned by /api/agent/resolve for the current task.","expected_outcomes":["success","failed","not_relevant","blocked_by_risk","setup_required"],"payload_template":{"event_id":"<install_receipt.outcome_feedback.event_id or feedback.event_id from /api/agent/resolve>","skill_slug":"adscanpro-ad-opsec-telemetry","task":"Use ad-opsec-telemetry in an agent workflow","agent":"codex","outcome":"success","install_used":true,"risk_blocked":false,"setup_required":false,"task_success":true,"output_quality":4,"error_type":null,"human_review_required":false,"workspace":"sandbox","time_to_useful_ms":120000,"notes":"Report the smallest successful task, setup friction, files touched, and risk notes."}},"endpoints":{"web":"https://www.openagentskill.com/skills/adscanpro-ad-opsec-telemetry","api":"https://www.openagentskill.com/api/agent/skills/adscanpro-ad-opsec-telemetry","audit":"https://www.openagentskill.com/skills/adscanpro-ad-opsec-telemetry/audit","eval":"https://www.openagentskill.com/api/agent/evals?slug=adscanpro-ad-opsec-telemetry&task=Use%20ad-opsec-telemetry%20in%20an%20agent%20workflow&max_risk=medium","resolve":"https://www.openagentskill.com/api/agent/resolve?task=Use%20ad-opsec-telemetry%20in%20an%20agent%20workflow&agent=codex&max_risk=medium","receipt":"https://www.openagentskill.com/api/agent/receipt?task=Use%20ad-opsec-telemetry%20in%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text","install":"https://www.openagentskill.com/api/skills/adscanpro-ad-opsec-telemetry/install","manifest":"https://www.openagentskill.com/api/registry/manifest/adscanpro-ad-opsec-telemetry"}},"machine_metadata":{"version":"openagentskill-agent-metadata-v2","skill":{"slug":"adscanpro-ad-opsec-telemetry","name":"ad-opsec-telemetry","description":"The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the DS-Replication-Get-Changes GUID, AS-REP roasting produces Event 4768 with no pre-auth, LSASS dumping is blocked by EDR, plus a lateral-movement telemetry table by protocol (SMB/WMI/WinRM/RDP/DCOM). Use this whenever you run or plan an offensive AD technique and need to know what noise it makes, when writing the engagement's detection notes, or when a defender wants to know what to monitor. Teaches red teamers what is loud and blue teamers what to watch. Standard-tooling knowledge, no vendor engine.","category":"design-creative","url":"https://www.openagentskill.com/skills/adscanpro-ad-opsec-telemetry","repository":"https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry","github_repo":"ADScanPro/Claude-AD"},"suited_tasks":["Document processing workflows","Claude Code teams","builders willing to evaluate younger projects","Read uploaded files","Extract structured fields","Prepare clean context for downstream agents","Navigate pages","Click and type safely"],"suited_agents":["Codex","Claude Code","Cursor","OpenAgentSkill CLI","CLI"],"install":{"command":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry","ready":true,"targets":[{"id":"openagentskill-cli","label":"CLI","kind":"command","value":"npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.3.0/openagentskill-0.3.0.tgz add adscanpro-ad-opsec-telemetry"},{"id":"codex","label":"Codex","kind":"agent-prompt","value":"Install the \"ad-opsec-telemetry\" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the DS-Replication-Get-Changes GUID, AS-REP roasting produces Event 4768 with no pre-auth, LSASS dumping is blocked by EDR, plus a lateral-movement telemetry table by protocol (SMB/WMI/WinRM/RDP/DCOM). Use this whenever you run or plan an offensive AD technique and need to know what noise it makes, when writing the engagement's detection notes, or when a defender wants to know what to monitor. Teaches red teamers what is loud and blue teamers what to watch. Standard-tooling knowledge, no vendor engine. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"adscanpro-ad-opsec-telemetry\",\"task\":\"Install ad-opsec-telemetry\",\"agent\":\"codex\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes."},{"id":"claude-code","label":"Claude Code","kind":"agent-prompt","value":"Add \"ad-opsec-telemetry\" as a Claude Code skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry. Inspect the skill instructions, place the reusable skill files in the appropriate local skills location for this project, and report the activation steps. Skill purpose: The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the DS-Replication-Get-Changes GUID, AS-REP roasting produces Event 4768 with no pre-auth, LSASS dumping is blocked by EDR, plus a lateral-movement telemetry table by protocol (SMB/WMI/WinRM/RDP/DCOM). Use this whenever you run or plan an offensive AD technique and need to know what noise it makes, when writing the engagement's detection notes, or when a defender wants to know what to monitor. Teaches red teamers what is loud and blue teamers what to watch. Standard-tooling knowledge, no vendor engine. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"adscanpro-ad-opsec-telemetry\",\"task\":\"Install ad-opsec-telemetry\",\"agent\":\"claude-code\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes."},{"id":"cursor","label":"Cursor","kind":"agent-prompt","value":"Turn \"ad-opsec-telemetry\" from https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry into a reusable Cursor project rule or agent instruction. Preserve the core workflow, adapt paths to this repo, and keep the rule scoped to tasks where it is relevant. Skill purpose: The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the DS-Replication-Get-Changes GUID, AS-REP roasting produces Event 4768 with no pre-auth, LSASS dumping is blocked by EDR, plus a lateral-movement telemetry table by protocol (SMB/WMI/WinRM/RDP/DCOM). Use this whenever you run or plan an offensive AD technique and need to know what noise it makes, when writing the engagement's detection notes, or when a defender wants to know what to monitor. Teaches red teamers what is loud and blue teamers what to watch. Standard-tooling knowledge, no vendor engine. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"adscanpro-ad-opsec-telemetry\",\"task\":\"Install ad-opsec-telemetry\",\"agent\":\"cursor\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes."}],"handoff_url":"https://www.openagentskill.com/api/skills/adscanpro-ad-opsec-telemetry/install","manifest_url":"https://www.openagentskill.com/api/registry/manifest/adscanpro-ad-opsec-telemetry"},"trust":{"score":73,"label":"Strong shortlist","version":"trust-score-v4","install_policy":"human_review_before_install","evidence":{"stars":"153 GitHub stars","repoActivity":"153 stars, 24 forks","lastPushed":"12d since push","license":"MIT","repository":"https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry","install":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry","installSafety":"standard package or runtime install path","permissionSurface":"secrets or environment access, shell or command execution","documentation":"Strong README/SKILL.md context","agentOutcomes":"No agent outcome data yet"},"outcome_evidence":{"total":0,"successes":0,"failures":0,"not_relevant":0,"success_rate":null,"recent_success_rate":null,"recent_failure_rate":null,"install_attempts":0,"install_success_rate":null,"risk_blocked":0,"setup_required":0,"avg_output_quality":null,"production_outcomes":0,"last_outcome_at":null,"label":"No agent outcome data yet"},"auto_install":{"allowed":false,"sandbox_required":true,"reason":"Human review or sandbox validation is required before automatic installation."},"best_for":["design-creative","agent-skill"],"known_risks":["Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","Stars/forks activity: 153 stars, 24 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"]},"agent_proven":{"version":"agent-proven-v1","score":0,"tier":"unproven","label":"Needs first agent run","summary":"No agent outcome reports yet. Use Resolve, run one narrow sandbox task, then report the result.","metrics":{"totalOutcomes":0,"successfulOutcomes":0,"failedOutcomes":0,"installAttempts":0,"installSuccessRate":null,"successRate":null,"recentSuccessRate":null,"recentFailureRate":null,"riskBlocked":0,"setupRequired":0,"notRelevant":0,"avgOutputQuality":null,"avgTimeToUsefulMs":null,"productionOutcomes":0,"humanReviewRequired":0,"uniqueAgents":0,"lastOutcomeAt":null},"signals":[],"penalties":["No real agent outcome evidence yet"]},"audit":{"score":78,"risk_level":"needs_review","risk_label":"Needs review","warnings":["Dependency or permission surface needs review","Permission surface may require sandboxing","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","Stars/forks activity: 153 stars, 24 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"]},"safety_gate":{"tier":"blocked","label":"Blocked for auto-install","auto_install_policy":"block","auto_install_allowed":false,"human_review_required":true,"blocked":true,"recommended_action":"Do not auto-install. Inspect the source, dependencies, and permission surface first."},"quality":{"score":68,"label":"Promising"},"supply":{"track":"Coding and developer agents","scenario":"GitHub automation","maintenance":"12d since push","risk":"Needs review"},"alternative_skills":[],"do_not_use_when":["teams that need a vendor-supported SLA","high-compliance environments without internal security review","No OpenAgentSkill engagement data yet","High-risk permission hints: Shell or command execution, Secrets or environment access","Dependency or permission surface needs review","Permission surface may require sandboxing","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution"],"agent_contract":{"task_input":"Use ad-opsec-telemetry in an agent workflow","recommended_action":"Do not auto-install. Inspect the source, dependencies, and permission surface first.","install_policy":"block","minimum_review_before_use":["Trust: 73/100 Strong shortlist","Audit: 78/100 Needs review","Safety: 38/100 Avoid automatic install","Review repository, license, install command, and permission surface before production use."],"expected_agent_output":{"selected_skill":"adscanpro-ad-opsec-telemetry (ad-opsec-telemetry)","install_command":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry","risk_summary":"Needs review; Blocked for auto-install; Review before production","verification_result":"Report the smallest successful task, files touched, warnings, and any missing setup."}},"outcome_feedback":{"endpoint":"https://www.openagentskill.com/api/agent/outcome","method":"POST","requires_resolve_event_id":true,"event_id_source":"Use install_receipt.outcome_feedback.event_id or feedback.event_id returned by /api/agent/resolve for the current task.","expected_outcomes":["success","failed","not_relevant","blocked_by_risk","setup_required"],"payload_template":{"event_id":"<install_receipt.outcome_feedback.event_id or feedback.event_id from /api/agent/resolve>","skill_slug":"adscanpro-ad-opsec-telemetry","task":"Use ad-opsec-telemetry in an agent workflow","agent":"codex","outcome":"success","install_used":true,"risk_blocked":false,"setup_required":false,"task_success":true,"output_quality":4,"error_type":null,"human_review_required":false,"workspace":"sandbox","time_to_useful_ms":120000,"notes":"Report the smallest successful task, setup friction, files touched, and risk notes."}},"endpoints":{"web":"https://www.openagentskill.com/skills/adscanpro-ad-opsec-telemetry","api":"https://www.openagentskill.com/api/agent/skills/adscanpro-ad-opsec-telemetry","audit":"https://www.openagentskill.com/skills/adscanpro-ad-opsec-telemetry/audit","eval":"https://www.openagentskill.com/api/agent/evals?slug=adscanpro-ad-opsec-telemetry&task=Use%20ad-opsec-telemetry%20in%20an%20agent%20workflow&max_risk=medium","resolve":"https://www.openagentskill.com/api/agent/resolve?task=Use%20ad-opsec-telemetry%20in%20an%20agent%20workflow&agent=codex&max_risk=medium","receipt":"https://www.openagentskill.com/api/agent/receipt?task=Use%20ad-opsec-telemetry%20in%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text","install":"https://www.openagentskill.com/api/skills/adscanpro-ad-opsec-telemetry/install","manifest":"https://www.openagentskill.com/api/registry/manifest/adscanpro-ad-opsec-telemetry"}},"supply_profile":{"track":{"slug":"coding","label":"Coding and developer agents","shortLabel":"Coding","description":"Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills."},"scenario":{"label":"GitHub automation","description":"I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.","useCases":[{"slug":"document-processing","title":"Document processing"},{"slug":"browser-automation","title":"Browser automation"},{"slug":"workflow-automation","title":"Workflow automation"}]},"applicableAgents":["Claude Code","CLI","Codex","Cursor"],"install":{"ready":true,"command":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry","primaryTarget":"CLI","targetCount":4},"githubQuality":{"stars":153,"starsLabel":"153","forks":24,"license":"MIT","qualityScore":68,"trustScore":73,"auditScore":78},"maintenance":{"status":"fresh","label":"12d since push","daysSincePush":12,"lastPushedAt":"2026-08-24T18:14:38+00:00"},"risk":{"level":"needs_review","label":"Needs review","requiresReview":true,"notes":["Dependency or permission surface needs review","Permission surface may require sandboxing","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","Stars/forks activity: 153 stars, 24 forks; issue activity unavailable in current metadata"]},"coverageTags":["Coding","GitHub automation","design-creative","agent-skill"]},"audit":{"audit_score":78,"risk_level":"needs_review","risk_label":"Needs review","quality_score":68,"trust_score":73,"maintenance_score":100,"security_score":76,"install_score":92,"warnings":["Dependency or permission surface needs review","Permission surface may require sandboxing","Quality score needs review","Permission surface needs review: secrets or environment access, shell or command execution","Stars/forks activity: 153 stars, 24 forks; issue activity unavailable in current metadata","Dependency/runtime risk: command execution surface, credential or environment access","Permission surface: secrets or environment access, shell or command execution"]},"quality_signals":{"model":"v2","star_score":15.31,"usage_score":0,"review_score":5.1,"metadata_score":3,"freshness_score":15},"platforms":["Claude Code"],"use_cases":[{"slug":"document-processing","title":"Document processing","url":"https://www.openagentskill.com/use-cases/document-processing"},{"slug":"browser-automation","title":"Browser automation","url":"https://www.openagentskill.com/use-cases/browser-automation"},{"slug":"workflow-automation","title":"Workflow automation","url":"https://www.openagentskill.com/use-cases/workflow-automation"},{"slug":"github-automation","title":"GitHub automation","url":"https://www.openagentskill.com/use-cases/github-automation"}],"stacks":[{"slug":"browser-qa-agent","title":"Browser QA agent","url":"https://www.openagentskill.com/collections/browser-qa-agent"},{"slug":"frontend-product-ui","title":"Frontend and UI","url":"https://www.openagentskill.com/collections/frontend-product-ui"},{"slug":"rag-knowledge-base","title":"RAG knowledge base","url":"https://www.openagentskill.com/collections/rag-knowledge-base"}],"install":"npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry","install_targets":[{"id":"openagentskill-cli","label":"CLI","title":"OpenAgentSkill CLI","kind":"command","value":"npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.3.0/openagentskill-0.3.0.tgz add adscanpro-ad-opsec-telemetry","description":"Resolve policy, run the source installer safely, and report a verified install receipt.","copyLabel":"Copy command"},{"id":"codex","label":"Codex","title":"Codex install prompt","kind":"agent-prompt","value":"Install the \"ad-opsec-telemetry\" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the DS-Replication-Get-Changes GUID, AS-REP roasting produces Event 4768 with no pre-auth, LSASS dumping is blocked by EDR, plus a lateral-movement telemetry table by protocol (SMB/WMI/WinRM/RDP/DCOM). Use this whenever you run or plan an offensive AD technique and need to know what noise it makes, when writing the engagement's detection notes, or when a defender wants to know what to monitor. Teaches red teamers what is loud and blue teamers what to watch. Standard-tooling knowledge, no vendor engine. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"adscanpro-ad-opsec-telemetry\",\"task\":\"Install ad-opsec-telemetry\",\"agent\":\"codex\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.","description":"Give Codex a repo-aware install prompt when the skill is not available through a local CLI.","copyLabel":"Copy prompt"},{"id":"claude-code","label":"Claude Code","title":"Claude Code skill prompt","kind":"agent-prompt","value":"Add \"ad-opsec-telemetry\" as a Claude Code skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry. Inspect the skill instructions, place the reusable skill files in the appropriate local skills location for this project, and report the activation steps. Skill purpose: The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the DS-Replication-Get-Changes GUID, AS-REP roasting produces Event 4768 with no pre-auth, LSASS dumping is blocked by EDR, plus a lateral-movement telemetry table by protocol (SMB/WMI/WinRM/RDP/DCOM). Use this whenever you run or plan an offensive AD technique and need to know what noise it makes, when writing the engagement's detection notes, or when a defender wants to know what to monitor. Teaches red teamers what is loud and blue teamers what to watch. Standard-tooling knowledge, no vendor engine. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"adscanpro-ad-opsec-telemetry\",\"task\":\"Install ad-opsec-telemetry\",\"agent\":\"claude-code\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.","description":"Use this prompt to ask Claude Code to add the skill and explain the local activation steps.","copyLabel":"Copy prompt"},{"id":"cursor","label":"Cursor","title":"Cursor rule prompt","kind":"agent-prompt","value":"Turn \"ad-opsec-telemetry\" from https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry into a reusable Cursor project rule or agent instruction. Preserve the core workflow, adapt paths to this repo, and keep the rule scoped to tasks where it is relevant. Skill purpose: The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the DS-Replication-Get-Changes GUID, AS-REP roasting produces Event 4768 with no pre-auth, LSASS dumping is blocked by EDR, plus a lateral-movement telemetry table by protocol (SMB/WMI/WinRM/RDP/DCOM). Use this whenever you run or plan an offensive AD technique and need to know what noise it makes, when writing the engagement's detection notes, or when a defender wants to know what to monitor. Teaches red teamers what is loud and blue teamers what to watch. Standard-tooling knowledge, no vendor engine. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"adscanpro-ad-opsec-telemetry\",\"task\":\"Install ad-opsec-telemetry\",\"agent\":\"cursor\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.","description":"Use this when installing as Cursor project rules or reusable agent instructions.","copyLabel":"Copy prompt"}],"repository":"https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry","github_repo":"ADScanPro/Claude-AD","version":"1.0.0","license":"MIT","urls":{"web":"https://www.openagentskill.com/skills/adscanpro-ad-opsec-telemetry","repository":"https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry","api":"/api/agent/skills/adscanpro-ad-opsec-telemetry","install_api":"/api/skills/adscanpro-ad-opsec-telemetry/install"},"meta":{"created_at":"2026-09-04T11:11:14.693166+00:00","updated_at":"2026-09-04T11:11:14.804816+00:00","agent_friendly":true}}