All-Rust Active Directory exploitation framework: LDAP/SMB/Kerberos enumeration, attack-graph pathfinding, Kerberoasting, NTLM relay, ticket forging, DCSync, and reporting in one static binary.
Active Directory Exploitation Framework.
Every throne falls. Overthrone makes sure of it.
What is this · Install · Wordlists · Commands · Wizard Usage · Architecture · Features · Examples · FAQ
You know how in medieval warfare, taking a castle required siege engineers, scouts, cavalry, archers, sappers, and someone to open the gate from inside? Active Directory pentesting is exactly that, except the castle is a Fortune 500 company, the gate is a misconfigured Group Policy, and the "someone inside" is a service account with Password123! that hasn't been rotated since Windows Server 2008 was considered modern.
Overthrone is a full-spectrum AD red team framework that handles the entire kill chain - from "I have network access and a dream" to "I own every domain in this forest and here's a 47-page PDF proving it." Built in Rust because C2 frameworks deserve memory safety too, and because debugging use-after-free bugs during an engagement is how you develop trust issues (both the Active Directory kind and the personal kind).
This is not a scanner. This is not a "run Mimikatz but in Rust" tool. This is not another Python wrapper that breaks when you look at it funny. This is the whole siege engine. One binary. Minimal runtime dependencies*. All regret (for the blue team).
Shorthand: Every command works with both
overthroneandovt. Because life is too short to type 10 characters when 3 will do.ovt wizard=overthrone wizard. Same war crimes against Active Directory, fewer keystrokes.
⚠️ Deprecation notice: The
ovt auto-pwncommand from earlier betas has been removed and replaced byovt wizard. If your muscle memory still typesauto-pwn, don't worry - your fingers will adapt. The wizard is what auto-pwn always wanted to be when it grew up: interactive, resumable, Q-learning-optimized, and with per-stage pause/approve so you don't accidentally DCSync during a demo.
*The binary is statically linked with ~35 Rust crates (Tokio, ldap3, kerberos_asn1, etc.) - no Python, no .NET, no JVM. SMB file operations, the smbclient-style shell (ovt smb shell), RPC (ovt rpc, rpcclient command set) and remote execution all run on the built-in pure-Rust SMB2 client; the external smbclient binary is only used as a last-resort fallback on hosts where the built-in client cannot negotiate.
sequenceDiagram
participant Op as Operator
participant CLI as overthrone-cli
participant PILOT as overthrone-pilot
participant REAPER as overthrone-reaper
participant HUNTER as overthrone-hunter
participant FORGE as overthrone-forge
participant CORE as overthrone-core
participant DC as Domain Controller
Note over Op,DC: Phase 0: Initial Access (T1078)
Op->>CLI: ovt enum / scan / kerberos commands
CLI->>CORE: TCP/TLS connect to target
Note over CLI,DC: Phase 1: Discovery & Enumeration (T1087, T1069, T1482)
CLI->>REAPER: enum_all(target, domain, credentials)
REAPER->>CORE: LDAP bind + paginated search
CORE->>DC: LDAP query (port 389/636)
DC-->>CORE: RootDSE + namingContexts
CORE->>DC: Search base DN: users, groups, computers
DC-->>CORE: LDAP entries with attributes
CORE-->>REAPER: Structured ADData
Note over REAPER: Enrich: LAPS v1/v2 decrypt, GPP decrypt,<br/>Snaffler share crawl, ADCS template scan
REAPER-->>CLI: ADData { users, groups, trusts, ACLs,<br/>GPOs, LAPS, SPNs, delegations }
Note over CLI,DC: Phase 2: Attack Graph Analysis (TA0007)
CLI->>CORE: build_graph(ADData)
CORE->>CORE: petgraph DiGraph construction<br/>30+ edge types with weighted costs
CORE->>CORE: Reverse Dijkstra from Domain Admins
CORE-->>CLI: AttackGraph + shortest paths to goal
Note over CLI: Output: Path from current position to DA,<br/>broken down hop-by-hop with technique