competition-identity-windows

Community

Trace identity flows and Windows pivot chains

Authorxjtu-wang
Version1.0.0
Installs0

System Documentation

What problem does it solve?

Helps security analysts trace identity flows, tickets, and Windows host artifacts within a sandboxed environment, linking credential material and lateral-movement chains to provide reproducible investigations.

Core Features & Use Cases

  • Trace principal origin, sync path, token or ticket minting, claims transformation, group resolution, and accepting service in Active Directory and Kerberos contexts.
  • Correlate Windows host artifacts (SAM, SECURITY, SYSTEM, NTDS, DPAPI, LSA secrets) with enterprise messaging events (mailbox rules, consent logs) to build end-to-end pivot chains.
  • Reproduce pivot chains across sandbox-linked nodes by documenting the edge-by-edge sequence from foothold to privilege elevation.
  • Preserve exact evidence blocks: SIDs, SPNs, ticket fields, event IDs, mailbox-rule changes, and pivot hosts for consistent timelines.

Quick Start

Map the identity chain and correlate host and mailbox evidence to reproduce the access path.

Dependency Matrix

Required Modules

None required

Components

references

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: competition-identity-windows
Download link: https://github.com/xjtu-wang/DigAgent/archive/main.zip#competition-identity-windows

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.