competition-identity-windows
zhaoxuya520/reverse-skill
This specialized skill is designed for deep forensic analysis in complex Windows environments, crucial for CTF and red teaming. It traces identity flows, including Active Directory (AD) origins, Kerberos ticket lifecycles, and OAuth authorization claims. Use it to correlate host artifacts (LSA, DPAPI, Sysmon) with identity evidence to map complete lateral movement and privilege escalation chains.