Claude Skills · Legal

Compliance Mapping

ADScanPro/Claude-AD

A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch. Kerberoasting relates to authentication and logging, so it brushes ENS op.acc.5 / op.exp.8, NIS2 Art.21(2)(h), DORA RTS Art.9 / Art.21. Use this when a reader wants to understand which regulatory control an AD finding relates to, or to add an orientation note to a technical finding. This is a conceptual, orientative mapping only; it is NOT an auditor-defensible, curated, ID-by-ID control matrix. Covers ENS (op.acc.*, op.exp.*), NIS2 (Directive 2022/2555 Art.21), and DORA (RTS 2024/177...

★ 137 Synced 1 hour ago View SKILL.md

At a glance

Legal Plugin install Auth required Actively maintained

This skill is for Legal and helps you map ad attack techniques to compliance controls, identify regulatory requirements for security findings, and add compliance context to technical vulnerabilities.

Setup, runtime and requirements describe ADScanPro/Claude-AD, the repo this skill ships in.

active-directoryCompliance MappingEnsNis2DoraRegulatory Controls

Also in ADScanPro/Claude-AD

View the repo
Acl Abuse DevOps & Infrastructure

Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, Wr...

Adcs Attacks DevOps & Infrastructure

Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k). Use when the tar...

Ad Environment Constraints DevOps & Infrastructure

Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KD...

The order of operations for an Active Directory penetration test: setup, collection, exploitation, post-processing. Use this whenever you ar...

The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0...

Coercion Ntlm Relay DevOps & Infrastructure

Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LD...

Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstr...

Other Legal skills

Brand Guidelines anthropics/skills

Applies Anthropic's official brand colors and typography to any sort of artifact that may benefit from having Anthropic's look-and-feel. Use...

Code Review mattpocock/skills

Review the changes since a fixed point (commit, branch, tag, or merge-base) along two axes — Standards (does the code follow this repo's doc...

Meeting Notes nexu-io/open-design

Meeting notes page — title bar with attendees, agenda checklist, decisions block, action items table with owners + dates, and a "next meetin...

Magazine Poster nexu-io/open-design

An editorial-style poster — newsprint paper, dateline, oversized serif headline with a struck-through word and italic accent, a 2-column bod...

Pricing Page nexu-io/open-design

A standalone pricing page — header, plan tiers, feature comparison table, and an FAQ. Use when the brief asks for "pricing", "plans", "subsc...

Apple Hig nexu-io/open-design

Apple Human Interface Guidelines as 14 agent skills covering platforms, foundations, components, patterns, inputs, and technologies for iOS,...