OpenAgentSkill Registry Manifest Skill: ad-opsec-telemetry Slug: adscanpro-ad-opsec-telemetry Category: design-creative Description: The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the DS-Replication-Get-Changes GUID, AS-REP roasting produces Event 4768 with no pre-auth, LSASS dumping is blocked by EDR, plus a lateral-movement telemetry table by protocol (SMB/WMI/WinRM/RDP/DCOM). Use this whenever you run or plan an offensive AD technique and need to know what noise it makes, when writing the engagement's detection notes, or when a defender wants to know what to monitor. Teaches red teamers what is loud and blue teamers what to watch. Standard-tooling knowledge, no vendor engine. Agent fit: - Decision: 67/100 Prototype first - Primary fit: Document processing - Role: Fallback candidate Supply profile: - Track: Coding and developer agents - Scenario: GitHub automation - Applicable agents: Claude Code, CLI, Codex, Cursor - Maintenance: 12d since push - Risk: Needs review Trust: - Trust score: 73/100 Strong shortlist - Audit: 78/100 Needs review Attribution: - Status: Registry indexed - Source: github fast track - Creator: ADScanPro - Claim URL: https://www.openagentskill.com/skills/adscanpro-ad-opsec-telemetry#claim-this-skill Install: npx skills add ADScanPro/Claude-AD --skill ad-opsec-telemetry URLs: - Web: https://www.openagentskill.com/skills/adscanpro-ad-opsec-telemetry - API: https://www.openagentskill.com/api/agent/skills/adscanpro-ad-opsec-telemetry - Install API: https://www.openagentskill.com/api/skills/adscanpro-ad-opsec-telemetry/install - Repository: https://github.com/ADScanPro/Claude-AD/tree/main/skills/ad-opsec-telemetry