Ad Enum — Development skill for Claude Code
Active Directory enumeration on: $ARGUMENTS.
How to install Ad Enum
Installs to ~/.claude/commands/h3nr1-d14z-ai-redteam-toolkit-ad-enum.md
mkdir -p ~/.claude/commands && curl -fsSL https://raw.githubusercontent.com/h3nr1-d14z/ai-redteam-toolkit/HEAD/.claude/commands/ad-enum.md -o ~/.claude/commands/h3nr1-d14z-ai-redteam-toolkit-ad-enum.md Restart Claude Code, or start a new session, for it to be picked up.
What Ad Enum does
Active Directory enumeration on: $ARGUMENTS
Pre-flight
- Confirm AD environment is in scope for enumeration
- Determine access level: unauthenticated, low-privilege domain user, or admin
- Identify Domain Controller IP(s) and domain name
- Verify network connectivity to DC (ports 88, 389, 445, 636)
Phase 1: Unauthenticated Enumeration
- Kerbrute user enum:
kerbrute userenum -d --dc users.txt - Null session SMB:
crackmapexec smb --shares -u '' -p ''
Alternatives in Development
- Project-Level Skills — This directory contains skills for developing and maintaining the claude-mem project itself, not skills that a 39.3k ★
- Agent.Extras.Workdir Structure — File structure of working directory {{folder}} 19k ★
- Claude Plugins Official — Anthropic-managed directory of high quality Claude Code Plugins 14.9k ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Ext Recon
Launch the ext-enumerator agent to run passive+active recon and service/web enumeration against the in-scope t
Claude Md Init All
Update all CLAUDE.md files and create missing ones across the repository starting from $ARGUMENTS (default: cu
Ad Scope
Define and record the scope of an authorized Active Directory engagement (domain(s), DC IP, initial credential
Slash Cron
Claude Code slash command (/cron) shows all active in-memory cron jobs running in Claude Code (even outside of
Directory
List every active agent session on this machine and its working directory.
Ad Whois
Quick Active Directory user lookup — resolve a name / sAMAccountName / UPN / mail to a user and present key fi
Related Agents
Active Directory
Active Directory and Windows domain attack specialist. Use for Kerberoasting, AS-REP roasting, DCSync, BloodHo
Ad Attacker
Delegates to this agent when the user wants to perform Active Directory attacks, run BloodHound analysis, use
Subdomain Enumeration
subfinder -d {domain} -silent sort -u subs.txt amass enum -passive -d {domain} subs.txt sort -u subs.txt -o su