Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Overthrone — All-Rust Active Directory exploitation framework: LDAP/SMB/Kerberos enumeration, attack-graph pathfinding, Kerberoasting, NTLM relay, ticket forging, DCSync, and reporting in one static binary. | Kitploit
Tools/GitHubGitHub/karmanya03/overthrone
Penetration Testing FrameworksPrivilege EscalationExploit FrameworksPassword AttacksPersistence MechanismsLateral MovementInformation GatheringPost-ExploitationCommand and ControlRed TeamingPayload Development
201518 days agoReviewed by Kitploit
GitHubkarmanya03/overthrone

Overthrone

All-Rust Active Directory exploitation framework: LDAP/SMB/Kerberos enumeration, attack-graph pathfinding, Kerberoasting, NTLM relay, ticket forging, DCSync, and reporting in one static binary.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

overthrone banner

Overthrone

Active Directory Exploitation Framework.
Every throne falls. Overthrone makes sure of it.

release license version rust AD

protocols graph pth ptt persistence relay reports smb2 signing kerberos spnego edr crawler

no mimikatz no python no dotnet no wine credguard dpapi no neo4j no impacket no hashcat ovt shorthand config tests


What is this  ·  Install  ·  Wordlists  ·  Commands  ·  Wizard Usage  ·  Architecture  ·  Features  ·  Examples  ·  FAQ


What is this?

You know how in medieval warfare, taking a castle required siege engineers, scouts, cavalry, archers, sappers, and someone to open the gate from inside? Active Directory pentesting is exactly that, except the castle is a Fortune 500 company, the gate is a misconfigured Group Policy, and the "someone inside" is a service account with Password123! that hasn't been rotated since Windows Server 2008 was considered modern.

Overthrone is a full-spectrum AD red team framework that handles the entire kill chain - from "I have network access and a dream" to "I own every domain in this forest and here's a 47-page PDF proving it." Built in Rust because C2 frameworks deserve memory safety too, and because debugging use-after-free bugs during an engagement is how you develop trust issues (both the Active Directory kind and the personal kind).

This is not a scanner. This is not a "run Mimikatz but in Rust" tool. This is not another Python wrapper that breaks when you look at it funny. This is the whole siege engine. One binary. Minimal runtime dependencies*. All regret (for the blue team).

Shorthand: Every command works with both overthrone and ovt. Because life is too short to type 10 characters when 3 will do. ovt wizard = overthrone wizard. Same war crimes against Active Directory, fewer keystrokes.

⚠️ Deprecation notice: The ovt auto-pwn command from earlier betas has been removed and replaced by ovt wizard. If your muscle memory still types auto-pwn, don't worry - your fingers will adapt. The wizard is what auto-pwn always wanted to be when it grew up: interactive, resumable, Q-learning-optimized, and with per-stage pause/approve so you don't accidentally DCSync during a demo.

*The binary is statically linked with ~35 Rust crates (Tokio, ldap3, kerberos_asn1, etc.) - no Python, no .NET, no JVM. SMB file operations, the smbclient-style shell (ovt smb shell), RPC (ovt rpc, rpcclient command set) and remote execution all run on the built-in pure-Rust SMB2 client; the external smbclient binary is only used as a last-resort fallback on hosts where the built-in client cannot negotiate.

The Kill Chain

sequenceDiagram
    participant Op as Operator
    participant CLI as overthrone-cli
    participant PILOT as overthrone-pilot
    participant REAPER as overthrone-reaper
    participant HUNTER as overthrone-hunter
    participant FORGE as overthrone-forge
    participant CORE as overthrone-core
    participant DC as Domain Controller

    Note over Op,DC: Phase 0: Initial Access (T1078)
    Op->>CLI: ovt enum / scan / kerberos commands
    CLI->>CORE: TCP/TLS connect to target

    Note over CLI,DC: Phase 1: Discovery & Enumeration (T1087, T1069, T1482)
    CLI->>REAPER: enum_all(target, domain, credentials)
    REAPER->>CORE: LDAP bind + paginated search
    CORE->>DC: LDAP query (port 389/636)
    DC-->>CORE: RootDSE + namingContexts
    CORE->>DC: Search base DN: users, groups, computers
    DC-->>CORE: LDAP entries with attributes
    CORE-->>REAPER: Structured ADData
    Note over REAPER: Enrich: LAPS v1/v2 decrypt, GPP decrypt,<br/>Snaffler share crawl, ADCS template scan
    REAPER-->>CLI: ADData { users, groups, trusts, ACLs,<br/>GPOs, LAPS, SPNs, delegations }

    Note over CLI,DC: Phase 2: Attack Graph Analysis (TA0007)
    CLI->>CORE: build_graph(ADData)
    CORE->>CORE: petgraph DiGraph construction<br/>30+ edge types with weighted costs
    CORE->>CORE: Reverse Dijkstra from Domain Admins
    CORE-->>CLI: AttackGraph + shortest paths to goal
    Note over CLI: Output: Path from current position to DA,<br/>broken down hop-by-hop with technique
Download Tool