What problem does it solve? CTF challenges involving Active Directory, Kerberos tickets, Windows host artifacts, and enterprise mail often drown solvers in disconnected evidence. This Skill provides a structured methodology to trace identity flows, correlate host and mail evidence on one timeline, and prove lateral-movement chains instead of guessing at privilege. ## Core Features & Use Cases - Identity and AD Tracing: Maps principal origin, ticket minting, claims transformation, delegation modes, and the service that actually accepts a credential. - Windows Host Pivot Analysis: Correlates SAM, NTDS, DPAPI, LSA secrets, Sysmon, WMI, WinRM, SMB, and RDP artifacts into a single pivot graph with a concrete foothold-to-privilege chain. - Enterprise Messaging Correlation: Ties phishing lures, consent logs, mailbox rules, and identity-provider events together so mail paths and privilege paths stay connected. - Use Case: During a CTF, you recover a Kerberos ticket from a compromised host. Use this Skill to record the ticket type, SPN, and delegation mode, then reproduce the exact replay path to the pivot host that accepts it. ## Quick Start Ask the assistant to trace the Kerberos ticket and lateral-movement chain across the sandbox hosts after the ctf-sandbox-orchestrator has established the scenario.