Rmagent Windows

Pull-based remote-witness habit for a Windows estate — the "RMAgent" knock. Ask two workgroup Windows servers (WS1/WS2) eight allowlisted named questions (attest, sketch, edges, explain, netedges, pslogs, kernring, attackmap) over pywinrm/WinRM :5985, tracking the Administrator and SYSTEM accounts. Use for identity-led compromise, lateral movement, living-off-the-land, silent hosts, and honest root-cause on Windows boxes you administer — without building a log lake and without switching off the EDR. Phase 0 is watch only; there is no actuate. Does NOT replace CrowdStrike/Defender. Prefer this skill for the two-box estate and Administrator/SYSTEM tracking; use the parent `security-observatory` skill for multi-plane (identity, cloud, network) hunts.

DrOlu 3dcadbf 73 files · 416.9 KB Updated

File contents

DrOlu/agent-skills/tree/main/skills/rmagent-windows commit 3dcadbfa15

Frequently asked questions

npx skillmds@latest add drolu/rmagent-windows