Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
AD-Attack-Defense — Attack and defend active directory using modern post exploitation adversary tradecraft activity | Kitploit
Tools/GitHubGitHub/infosecn1nja/ad-attack-defense
Defensive ToolsPrivilege EscalationReconnaissancePersistence MechanismsLateral MovementPost-ExploitationPenetration TestingLearning & EducationRed TeamingCurated ResourcesTop in Curated Resources #20
4.8k1.1k321 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHubinfosecn1nja/ad-attack-defense

AD-Attack-Defense

Attack and defend active directory using modern post exploitation adversary tradecraft activity

View Repository
Share

Active Directory Kill Chain Attack & Defense

image

Summary

This document was designed to be a useful, informational asset for those looking to understand the specific tactics, techniques, and procedures (TTPs) attackers are leveraging to compromise active directory and guidance to mitigation, detection, and prevention. And understand Active Directory Kill Chain Attack and Modern Post Exploitation Adversary Tradecraft Activity.

Table of Contents

  • Discovery
  • Privilege Escalation
  • Defense Evasion
  • Credential Dumping
  • Lateral Movement
  • Persistence
  • Defense & Detection

Discovery

SPN Scanning

  • SPN Scanning – Service Discovery without Network Port Scanning
  • Active Directory: PowerShell script to list all SPNs used
  • Discovering Service Accounts Without Using Privileges

Data Mining

  • A Data Hunting Overview
  • Push it, Push it Real Good
  • Finding Sensitive Data on Domain SQL Servers using PowerUpSQL
  • Sensitive Data Discovery in Email with MailSniper
  • Remotely Searching for Sensitive Files
  • I Hunt Sysadmins - harmj0y

User Hunting

  • Hidden Administrative Accounts: BloodHound to the Rescue
  • Active Directory Recon Without Admin Rights
  • Gathering AD Data with the Active Directory PowerShell Module
  • Using ActiveDirectory module for Domain Enumeration from PowerShell Constrained Language Mode
  • PowerUpSQL Active Directory Recon Functions
  • Derivative Local Admin
  • Automated Derivative Administrator Search
  • Dumping Active Directory Domain Info – with PowerUpSQL!
  • Local Group Enumeration
  • Attack Mapping With Bloodhound
  • Situational Awareness
  • Commands for Domain Network Compromise
  • A Pentester’s Guide to Group Scoping

LAPS

  • Microsoft LAPS Security & Active Directory LAPS Configuration Recon
  • Running LAPS with PowerView
  • RastaMouse LAPS Part 1 & 2

AppLocker

  • Enumerating AppLocker Config

Active Directory Federation Services

  • 118 Attacking ADFS Endpoints with PowerShell Karl Fosaaen
  • Using PowerShell to Identify Federated Domains
  • LyncSniper: A tool for penetration testing Skype for Business and Lync deployments
  • Troopers 19 - I am AD FS and So Can You

Privilege Escalation

BadSuccessor

  • BadSuccessor: Abusing dMSA to Escalate Privileges in Active Directory
  • Operationalizing the BadSuccessor: Abusing dMSA for Domain Privilege Escalation

sAMAccountName Spoofing

  • sAMAccountName spoofing
  • CVE-2021-42287/CVE-2021-42278 Weaponisation

Abusing Active Directory Certificate Services

  • Certified Pre-Owned
  • AD CS Domain Escalation

PetitPotam

  • PetitPotam
  • From Stranger to DA // Using PetitPotam to NTLM relay to Domain Administrator

Zerologon

  • Cobalt Strike ZeroLogon-BOF
  • CVE-2020-1472 POC
  • Zerologon: instantly become domain admin by subverting Netlogon cryptography (CVE-2020-1472)

Passwords in SYSVOL & Group Policy Preferences

  • Finding Passwords in SYSVOL & Exploiting Group Policy Preferences
  • Pentesting in the Real World: Group Policy Pwnage

MS14-068 Kerberos Vulnerability

  • MS14-068: Vulnerability in (Active Directory) Kerberos Could Allow Elevation of Privilege
  • Digging into MS14-068, Exploitation and Defence
  • From MS14-068 to Full Compromise – Step by Step

DNSAdmins

  • Abusing DNSAdmins privilege for escalation in Active Directory
  • From DNSAdmins to Domain Admin, When DNSAdmins is More than Just DNS Administration

Kerberos Delegation

  • Constructing Kerberos Attacks with Delegation Primitives
  • No Shells Required - a Walkthrough on Using Impacket and Kerberos to Delegate Your Way to DA
  • CVE-2020-17049: Kerberos Bronze Bit Attack – Overview
Download Tool