Rmagent So

The Security Observatory — the witness-question half of the RMAgent security observatory. Pull-based, allowlisted named questions over WinRM :5985 tracking Administrator and SYSTEM: attest (with blind_check — can this witness actually see?), sketch, edges, explain, netedges, pslogs, kernring, attackmap, flowstats, deepwindow. Cross-witness correlation joins the answers (cross-host-account, lateral-hop, shared-logonid); baseline drift flags new admins and witness blindness as critical. Use for identity-led compromise, lateral movement, living-off-the-land, silent hosts, and honest root-cause on Windows boxes you administer. Watch-only, capped at 32 KB, holes instead of dumps — no lake, no agent install.

DrOlu feadbaf 40 files · 259.1 KB Updated

File contents

DrOlu/agent-skills/tree/main/skills/rmagent-so commit feadbaf838

Frequently asked questions

npx skillmds@latest add drolu/rmagent-so