| name | cyber-performing-active-directory-compromise-investigation |
| description | Investigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateral movement paths. |
| hide | true |
YURI skill adapter
Authoritative source: .claude/skills/cyber-performing-active-directory-compromise-investigation/SKILL.md
Authoritative source SHA-256: 89253b3a17bd7a14020ab63e11180bbff99be1f0aea037278c4635a525a515ef
Source class: cyber-armed
Before acting, read the authoritative source file above completely from beginning to end. If the governed source is absent, run node _SYSTEM/Scripts/skill-recall.mjs --show cyber-performing-active-directory-compromise-investigation and read its complete verified output. Follow that source as the skill body; this adapter is a non-authoritative metadata-and-pointer projection.