Skip to content

opentidehq/opentide-detection-skills

v1.0.0EUPL-1.2

Detection engineering skills for OpenTide — TVM, DOM, and MDR authoring, hunt-to-rule workflows, MITRE ATT&CK, platform query languages, and defensive internals — with the OpenTide MCP server.

active-directory

Active Directory internals for detection engineering — Kerberos authentication flow (AS-REQ/TGT/TGS/service ticket), NTLM challenge-response mechanics, AD replication protocol (DRS/DCSync), trust types and delegation abuse (constrained/unconstrained/RBCD), Group Policy processing, AD Certificate Services attack paths (ESC1-ESC13), SPN mechanics and Kerberoasting, LDAP reconnaissance patterns, and the telemetry each operation produces. Use when authoring detections for credential access, lateral movement, privilege escalation, or persistence that involves Active Directory.

Read SKILL.md at the source

Pinned to revision 591443442d56, so it is the text this page describes rather than whatever the author pushed since.

Files

Every link opens the file at its source, pinned to the revision this page describes.