{"enrichment":{"faq":[{"a":"Windows Discovery maps privilege escalation vectors on compromised Windows hosts through systematic enumeration of system configuration, user context, services, and misconfigurations. It gathers baseline OS details, token privileges, and group memberships to identify immediate escalation paths, then reports findings to the orchestrator without crossing into exploitation.","q":"What does Windows Discovery do?"},{"a":"Yes. Windows Discovery is designed to discover and enumerate Windows hosts on a network as a primary function. It identifies active Windows systems and collects detailed configuration data to support security assessment and infrastructure mapping workflows.","q":"Can Windows Discovery enumerate windows hosts on a network?"},{"a":"Windows Discovery identifies active Windows systems for security assessment by enumerating system configuration, user context, services, and misconfigurations. It gathers OS details and token privileges to detect which systems are present and active on the network.","q":"How does Windows Discovery identify active Windows systems?"},{"a":"Windows Discovery is released under the GPL-3.0 license, which permits use, modification, and distribution under the terms of the GNU General Public License version 3.","q":"What license does Windows Discovery use?"},{"a":"Yes. Windows Discovery maps Windows infrastructure and assets by systematically enumerating hosts, their configurations, user contexts, and group memberships. This enables comprehensive asset discovery and infrastructure visibility for security and operational purposes.","q":"Does Windows Discovery map Windows infrastructure?"},{"a":"Windows Discovery collects baseline OS details, token privileges, group memberships, system configuration data, user context information, services, and misconfigurations. It reports these findings to identify privilege escalation vectors and security assessment opportunities.","q":"What information does Windows Discovery collect?"}],"shadow_tags":["network-reconnaissance","host-enumeration","asset-discovery","windows-inventory","infrastructure-mapping"],"summary_rewrite":"Windows Discovery maps privilege escalation vectors on compromised Windows hosts through systematic enumeration of system configuration, user context, services, and misconfigurations. It gathers baseline OS details, token privileges, and group memberships to identify immediate escalation paths, then reports findings to the orchestrator without crossing into exploitation."},"gist":{"api_url":"https://skillfed.io/api/skills/blacklanternsecurity/red-run/windows-discovery.json","as_of":"2026-04-01","description":"Windows Discovery enumerates Windows systems for local privilege escalation vectors and attack surface.","install":{"manual":["git clone https://github.com/blacklanternsecurity/red-run","cp -r red-run ~/.claude/skills/windows-discovery"],"primary":"npx skillfed install blacklanternsecurity/red-run/windows-discovery","version":"3d41ab8f"},"kind":"skill","mirror_url":"https://skillfed.io/blacklanternsecurity/red-run/windows-discovery.md","similar":[{"id":"yaklang/hack-skills/windows-privilege-escalation","name":"windows-privilege-escalation","publisher":"yaklang/hack-skills","url":"https://skillfed.io/yaklang/hack-skills/windows-privilege-escalation"},{"id":"blacklanternsecurity/red-run/windows-credential-harvesting","name":"Windows Credential Harvesting","publisher":"blacklanternsecurity/red-run","url":"https://skillfed.io/blacklanternsecurity/red-run/windows-credential-harvesting"},{"id":"hypnguyen1209/offensive-claude/privesc-windows","name":"privesc-windows","publisher":"hypnguyen1209/offensive-claude","url":"https://skillfed.io/hypnguyen1209/offensive-claude/privesc-windows"},{"id":"blacklanternsecurity/red-run/windows-token-impersonation","name":"Windows Token Impersonation","publisher":"blacklanternsecurity/red-run","url":"https://skillfed.io/blacklanternsecurity/red-run/windows-token-impersonation"}],"title":"Windows Discovery by blacklanternsecurity \u2014 SkillFed","use":{"when":["Yes.","Windows Discovery identifies active Windows systems for security assessment by enumerating system configuration, user context, services."]},"what":{"lead":"Windows Discovery enumerates Windows systems for local privilege escalation vectors and attack surface mapping.","rest":"Windows Discovery maps privilege escalation vectors on compromised Windows hosts through systematic enumeration of system configuration, user context, services, and misconfigurations. It gathers baseline OS details, token privileges, and group memberships to identify immediate escalation paths, then reports findings to the orchestrator without crossing into exploitation."}},"id":"blacklanternsecurity/red-run/windows-discovery","install":{"mode":"external","repo":"https://github.com/blacklanternsecurity/red-run"},"links":{"html":"https://skillfed.io/blacklanternsecurity/red-run/windows-discovery","md":"https://skillfed.io/blacklanternsecurity/red-run/windows-discovery.md","repo":"https://github.com/blacklanternsecurity/red-run"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":34,"language":"Python","last_updated":"2026-04-01","license":"GPL-3.0","name":"Windows Discovery","publisher":"blacklanternsecurity","stars":241},"relations":{"similar":[{"id":"zebbern/claude-code-guide/windows-privilege-escalation"},{"id":"yaklang/hack-skills/windows-privilege-escalation"},{"id":"blacklanternsecurity/red-run/windows-uac-bypass"},{"id":"blacklanternsecurity/red-run/windows-credential-harvesting"},{"id":"hypnguyen1209/offensive-claude/privesc-windows"},{"id":"hypnguyen1209/offensive-claude/red-team-ops"},{"id":"blacklanternsecurity/red-run/windows-service-dll-abuse"},{"id":"blacklanternsecurity/red-run/windows-token-impersonation"},{"id":"Aradotso/security-skills/fsecure-internet-security-malware-distribution"},{"id":"BagelHole/DevOps-Security-Agent-Skills/windows-hardening"}]},"slug":{"owner":"blacklanternsecurity","repo":"red-run","skill":"windows-discovery"},"version":"3d41ab8f"}
