Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ad-autopwn — Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow Credentials, RBCD, DCSync, and Synacktiv 2026 reflection exploits. Authorized pentesting only. | Kitploit
Tools/GitHubGitHub/jonaslejon/ad-autopwn
Privilege EscalationReconnaissanceVulnerability ScannersExploitationLateral MovementPost-ExploitationPenetration TestingCommand and ControlRed TeamingPayload Development
GitHub
376275 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
jonaslejon/ad-autopwn

ad-autopwn

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow Credentials, RBCD, DCSync, and Synacktiv 2026 reflection exploits. Authorized pentesting only.

View Repository

AD AutoPwn

Zero-Auth to Domain Admin — Automated Active Directory Attack Chain

A fully automated penetration testing tool that chains 25+ attack techniques to compromise Active Directory environments. Designed for authorized security assessments.

       _   ___      _       _       ___
      /_\ |   \    /_\ _  _| |_ ___| _ \__ __ ___ _
     / _ \| |) |  / _ \ || |  _/ _ \  _/\ V  V / ' \
    /_/ \_\___/  /_/ \_\_,_|\__\___/_|   \_/\_/|_||_|

    ⚡ Zero-Auth to Domain Admin — Attack Chain
    Discover | Sniff | ARP | WPAD | WSUS | PXE | AD CS | SCCM | Roast
    BloodHound | Reflect | Loot | RBCD+KCD | DCSync | DPAPI

Features

Pre-auth username & credential discovery (zero creds)

  • kerbrute KRB-AS-REQ user enumeration (lockout-safe)
  • CLDAP NetLogon ping username enumeration (lockout-safe)
  • AS-REP roast of all candidates (free hashes for accounts with DONT_REQ_PREAUTH)
  • pre2k auto-test (Windows 2000 compatibility default-password machines)
  • Single-password spray (lockout-aware, opt-in via --spray-password)

Layer-2 / passive zero-auth attacks

  • Passive network sniffing — WPAD, WSUS, PXE, LLMNR, DHCPv6, TFTP, SCCM ProxyDHCP detection
  • ARP spoof + NTLM relay — capture and crack NTLMv2 hashes
  • WPAD poisoning — mitm6 / Responder IPv6 DNS hijack
  • WSUS relay — intercept Windows Update NTLM auth (port 8530/8531)
  • PXE boot credential theft — extract creds from boot images via TFTP/WIM
  • NTLM theft file drops — .library-ms / .theme / .url files on writable shares
  • WebDAV coercion — WebClient HTTP → LDAP relay (bypasses SMB signing)
  • DHCP coercion — DHCP server machine account relay

Authentication-reflection bypass (Synacktiv 2026)

  • CVE-2025-58726 ghost-SPN Kerberos AP-REQ reflection (auto-fired by BloodHound auto-action)
  • CVE-2026-24294 LPE — SMB-on-arbitrary-tcpport reflection (Win11 24H2 / Server 2025 pre-March-2026)
  • CVE-2026-26128 LPE — Kerberos loopback via Unicode SPN
  • Unicode-SPN fallback when CVE-2025-33073 path is patched

Credential harvesting (post-auth)

  • Kerberoasting — extract and auto-crack SPN hashes (hashcat mode 13100/19700)
  • AS-REP Roasting — crack accounts without pre-auth (hashcat mode 18200)
  • Timeroast — SNTP-MS hashes from any domain-joined machine (hashcat mode 31300)
  • LAPS password recovery + userPassword LDAP attribute + description-leaked passwords (mined from nxc enrichment battery)
  • SCCM NAA theft — extract Network Access Account credentials via sccmhunter

Graph-driven attack chains (BloodHound)

  • bloodhound-python -c All collection + ZIP analysis
  • High-value findings — Domain/Enterprise/Schema Admins, Kerberoastable, AS-REP roastable, unconstrained delegation, RBCD inbound, LAPS, AdminCount
  • Actionable-edge analysis — controlled-principal closure (you + transitive group memberships) → ACE edges where you are the principal: WriteSPN, AddKeyCredentialLink, GenericAll/Write, WriteDacl/Owner, WriteAccountRestrictions, AddAllowedToAct, ForceChangePassword
  • Auto-action chain — automatically fires matching primitives:
    • WriteSPN → ghost-SPN upgrade (CVE-2025-58726)
    • AddKeyCredentialLink → shadow credentials → PKINIT → NT hash
    • GenericAll / WriteAccountRestrictions on Computer → RBCD chain → admin TGS

Privilege escalation primitives

  • AD CS exploitation — ESC1-ESC16 via certipy (auto-enum + exploit)
    • ESC8 (web-enrollment relay)
    • ESC9/ESC10 UPN-swap (CVE-2022-26923 bypass)
    • ESC4 template modify+exploit+restore (cwd-safe)
    • Certihound enumeration with certipy fallback (NT-hash auth)
  • Shadow Credentials — msDS-KeyCredentialLink via ntlmrelayx or pywhisker
  • RBCD abuse — Resource-Based Constrained Delegation (addcomputer + S4U2Self + S4U2Proxy)
  • RBCD+KCD chain orchestrator — full WriteSPN → ghost-SPN → RBCD → S4U2Proxy → -altservice rewrite, in one phase
  • TGS sname rewrite (tgssub-style KCD protocol-transition bypass) — standalone or inline via -altservice
  • Dollar Ticket — KDC's automatic $-suffix retry on principal lookup → TGT for Linux user via auto-created <user>$ machine account → GSSAPI SSH
  • GPO abuse — pyGPOAbuse scheduled task as SYSTEM

Domain compromise

  • DCSync — full domain hash dump via impacket-secretsdump
  • DPAPI backup key — extract domain DPAPI key for offline credential decryption
  • AppLocker bypass — LOLBins (mshta, certutil, regsvr32, etc.) + WSUS signed delivery
  • WSUS update injection — push malicious Windows Updates via wsuks

Post-exploitation loot

  • Process command-line harvest — Get-CimInstance Win32_Process via nxc -x; regex-greps for passwords in mysql/sqlcmd/runas/KeePass/--password style flags
  • KeePass vault discovery + crack — find *.kdbx in C:\Users, download via smbclient, keepass2john | hashcat -m 13400

Usage

# Fully automated — zero-cred chain (auto-discovers everything)
sudo ./ad-autopwn.py

# With credentials — full chain
./ad-autopwn.py -u jsmith -p 'P@ss123' -d corp.local --dc-ip 10.0.0.1

# AWS / VPC labs (Layer 2 attacks blocked) — auto-discovery still works
sudo ./ad-autopwn.py --no-arp --no-wpad

# Pre-auth credential discovery (lockout-safe)
sudo ./ad-autopwn.py --phase discover --no-arp --no-wpad

# BloodHound graph collection + automatic high-value analysis
./ad-autopwn.py --phase bloodhound -u user -p pass -d corp.local \
                --dc-ip 10.0.0.1 --dc-fqdn dc01.corp.local

# Dollar Ticket — TGT for 'root' via auto-created root$ machine acct
./ad-autopwn.py -u user -p pass -d corp.local --dc-ip 10.0.0.1 \
                --phase dollar-ticket --target-user root

# RBCD+KCD chain — full ghost-SPN + RBCD + altservice rewrite, one shot
./ad-autopwn.py -u user -p pass -d corp.local --dc-ip 10.0.0.1 \
                --phase rbcd-kcd -T VHAGAR$ --alt-spn HTTP/vhagar.corp.local

# AppLocker bypass
./ad-autopwn.py -u user -p pass --applocker --lolbin mshta --custom-cmd "whoami"

# Dry run (print every command, run nothing — even background processes)
./ad-autopwn.py --dry-run -u user -p pass -d corp.local --dc-ip 10.0.0.1

Available phases

Download Tool