State-aware AD attack orchestration in Go — initial access through cloud pillage. Wraps nxc, impacket, certipy, BloodHound, TeamsPhisher, GraphRunner, AADInternals, TokenTactics.
-
Updated
Jun 1, 2026 - Go
8000
State-aware AD attack orchestration in Go — initial access through cloud pillage. Wraps nxc, impacket, certipy, BloodHound, TeamsPhisher, GraphRunner, AADInternals, TokenTactics.
PowerShell toolkit for assessing DES/RC4 Kerberos encryption in Active Directory. Detects weak encryption across domain controllers, trusts, and event logs. Built for the January 2026 update and July 2026 RC4 removal deadlines.
Audit Active Directory for unconstrained, constrained, and resource-based Kerberos delegation using only built-in .NET, with no AD module or admin rights required.
Windows service that monitors Active Directory in real time and alerts on 8 live attack techniques — Kerberoasting, Pass-the-Hash, DCSync, Golden Ticket, LDAP Recon, AS-REP Roasting, Skeleton Key, and Audit Log tampering. Built in Python using Windows Security Event Log analysis.
post-exploitation tool for computer object takeover via Resource-Based Constrained Delegation modify msDS-AllowedToActOnBehalfOfOtherIdentity attributes to abuse Kerberos delegation and escalate privileges in Active Directory.
Transforms BloodHound attack paths into attacker capability analysis, privilege escalation reasoning, and operator-focused walkthroughs.
Modern, kapsamlı Active Directory güvenlik analizi ve raporlama aracı. PowerShell AD kontrollerini Python'a dönüştürür ve güzel HTML raporları oluşturur.
https://securitree.xyz - deep dive into cybersec with well-structured notes.
Audit Active Directory for AS-REP roastable accounts (Kerberos pre-authentication disabled) using only built-in .NET, with no AD module or admin rights required.
AD April ’26 Check0r is a read-only PowerShell tool to assess on-prem AD for the April 2026 Kerberos RC4→AES change. It inventories SPN accounts, flags risky msDS-SupportedEncryptionTypes/KDC overrides, and collects DC System readiness events (201–209) to predict breakage and guide fixes.
post-exploitation tool for computer object takeover via Resource-Based Constrained Delegation modify msDS-AllowedToActOnBehalfOfOtherIdentity attributes to abuse Kerberos delegation and escalate privileges in Active Directory.
Audit Active Directory for Kerberoastable service accounts (users with SPNs) using only built-in .NET, with no AD module or admin rights required.
Computer object takeover through Resource-Based Constrained Delegation msDS-AllowedToActOnBehalfOfOtherIdentity
PowerShell script for cybersecurity professionals to identify Active Directory accounts with Password Never Expires flag, analyze password age and logon patterns, and export comprehensive security audit reports to CSV.
AttackPathCanvas — Visualize Identity Attack Paths in Active Directory
This script will scan your AD and Export a CSV list of Pcs that have not had activity, prior to your set number of days tolerance you input.
PowerShell-first Active Directory security posture auditor for privileged access, Kerberos, Windows LAPS, Group Policy, ACLs, and offline drift analysis.
Active Directory LDAP Security Auditor with AI-Powered Analysis - By Ayi NEDJIMI
Active Directory assessment collector
GitHub profile README for Benjamin Iheukumere
Add a description, image, and links to the ad-security topic page so that developers can more easily learn about it.
To associate your repository with the ad-security topic, visit your repo's landing page and select "manage topics."