competition-identity-windowslisted
Install: claude install-skill Saprophytic-seattle561/reverse-skill
# Competition Identity Windows
Use this skill only as a downstream specialization after `$ctf-sandbox-orchestrator` is already active and has established sandbox assumptions, node ownership, and evidence priorities. If that has not happened yet, return to `$ctf-sandbox-orchestrator` first.
Use this skill when the challenge revolves around identity flow, replayable credentials, Windows host artifacts, enterprise mail, or lateral movement.
Reply in Simplified Chinese unless the user explicitly requests English.
## Quick Start
1. Map the identity or pivot chain before diving into every host artifact.
2. Separate credential possession from accepted privilege.
3. Correlate identity evidence, host evidence, and mail evidence on one timeline.
4. Keep tickets, SIDs, event IDs, mailbox rules, and pivot hosts in compact evidence blocks.
5. Reproduce the privilege edge or mail effect from the smallest viable chain.
## Workflow
### 1. Identity And AD
- Trace principal origin, sync path, token or ticket minting, claims transformation, group resolution, and accepting service.
- When Kerberos matters, record ticket type, SPN, delegation mode, PAC or group data, encryption type, and cache location.
### 2. Windows Host And Pivoting
- Correlate SAM, SECURITY, SYSTEM, NTDS, DPAPI, LSA secrets, ETW, Sysmon, PowerShell, services, tasks, WMI, WinRM, SMB, and RDP as one pivot graph.
- Express movement as a concrete chain: foothold -> recovered artifact -> replay path -> pivot host -> resu