
Powershell tool to automate Active Directory enumeration.
Comprehensive Active Directory security assessment — zero dependencies, single file, ready to go.
adPEAS is a PowerShell-based security assessment tool that identifies misconfigurations, vulnerabilities, and privilege escalation paths in Active Directory environments. It is designed for penetration testers, security auditors, and red teams who need a reliable, self-contained tool that works on any Windows system — no RSAT, no ActiveDirectory module, no third-party dependencies.
adPEAS v2 is a complete rewrite of adPEAS v1. It replaces the legacy DirectoryEntry/DirectorySearcher approach with a unified System.DirectoryServices.Protocols.LdapConnection architecture and adds native Kerberos authentication, advanced reporting, and offensive operations — all in pure PowerShell.
New to adPEAS? Check the Quick-Start Guide or read the blog series on blog.sekurity.de for a deep dive into architecture, authentication, and internals.
| Category | Highlights |
|---|---|
| Authentication | Credentials, PKINIT, Pass-the-Cert, NT-Hash, AES keys, Windows auth, Kerberos-first with automatic fallback |
| Security Checks | Domain config, Kerberoast, ASREPRoast, ACLs, DCSync, delegation, AD CS escalation paths, GPO abuse, LAPS, BitLocker recovery keys, outdated systems |
| Reporting | Console (color-coded), plain text, interactive HTML, JSON export |
| Offensive Ops | Kerberoasting, AS-REP Roasting, Golden/Silver/Diamond Tickets, RBCD, Shadow Credentials, Pass-the-Ticket |
| BloodHound | Built-in BloodHound CE collector (ZIP export) |
| OPSEC Mode | Skip active testing (Kerberoast, ASREPRoast, BloodHound) |
| Deployment | Single .ps1 file, no RSAT, no external modules, works offline and air-gapped |
No ActiveDirectory module, RSAT, or external PowerShell modules required.
| File | Size | Use Case |
|---|---|---|
adPEAS.ps1 | ~4.5 MB | Development, debugging, code review |
adPEAS_min.ps1 | ~3-4 MB | Regular use with smaller footprint |
adPEAS_ultra.ps1 | ~3 MB | Minimal size, no comments |
adPEAS_obf.ps1 | <1 MB | Smallest size, obfuscated for transfer |
All four versions are functionally identical. Choose based on your deployment scenario.
# Clone the repository
git clone https://github.com/61106960/adPEAS.git
cd adPEAS
The main branch contains only source files (src/). Release builds are attached to each GitHub Release. If you want to build from the latest source, use the included build script:
git clone https://github.com/61106960/adPEAS.git
cd adPEAS
.\Build-Release.ps1
This produces all four variants (adPEAS.ps1, adPEAS_min.ps1, adPEAS_ultra.ps1, adPEAS_obf.ps1) in the repository root. Requires Windows PowerShell 5.1 and no additional dependencies.
# Option 1: Import as module (recommended)
Import-Module .\adPEAS.ps1
# Option 2: Dot-sourcing
. .\adPEAS.ps1
# Option 3: Read and execute in memory
Get-Content -Raw .\adPEAS.ps1 | Invoke-Expression
# Option 4: Load directly from GitHub into memory (no file on disk)
Invoke-Expression (Invoke-WebRequest -Uri "https://raw.githubusercontent.com/61106960/adPEAS/main/adPEAS_obf.ps1" -UseBasicParsing).Content
# Domain-joined machine (current user)
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth
# With credentials
Invoke-adPEAS -Domain "contoso.com" -Username "john.doe" -Password "P@ssw0rd!"
# OPSEC mode (skip Kerberoast, ASREPRoast, BloodHound)
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth -OPSEC
# Connect once
Connect-adPEAS -Domain "contoso.com" -UseWindowsAuth
# Run full scan
Invoke-adPEAS
# Or run individual checks
Get-KerberoastableAccounts
Get-ADCSVulnerabilities
Get-DangerousACLs
# Disconnect when done
Disconnect-adPEAS
# Credentials
Connect-adPEAS -Domain "contoso.com" -Credential (Get-Credential)
# Overpass-the-Hash (NT-Hash)
Connect-adPEAS -Domain "contoso.com" -Username "admin" -NTHash "32ED87BDB5FDC5E9CBA88547376818D4"
# Pass-the-Key (AES256)
Connect-adPEAS -Domain "contoso.com" -Username "admin" -AES256Key "4a3b2c1d5e6f..."
# PKINIT (Certificate)
Connect-adPEAS -Domain "contoso.com" -Certificate "user.pfx"
# Pass-the-Cert / Schannel (LDAPS, no Kerberos)
Connect-adPEAS -Domain "contoso.com" -Certificate "user.pfx" -PassTheCert
# LDAPS
Connect-adPEAS -Domain "contoso.com" -UseWindowsAuth -UseLDAPS
# All formats (default) — creates .txt, .html, and .json
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth -Outputfile .\report
# HTML only
Invoke-adPEAS -Domain "contoso.com" -UseWindowsAuth -Outputfile .\report -Format HTML
# Offline report conversion from JSON
Convert-adPEASReport -InputJson ".\report.json" -OutputPath ".\new_report"
# Compare two scans (diff report)
Compare-adPEASReport -Baseline ".\scan_q1.json" -Current ".\scan_q2.json" -OutputPath ".\diff"