Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
tanuki — Tactical Identity Operator for Linux & Hybrid Active Directory | Kitploit
Tools/GitHubGitHub/mafifrizi/tanuki
Defensive ToolsIdentity ManagementInformation GatheringPenetration TestingUtilities & FrameworksAuthenticationRed TeamingIncident ResponseAI Security
GitHubmafifrizi/tanuki

tanuki

Tactical Identity Operator for Linux & Hybrid Active Directory

154102 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
Share

Tanuki Logo

Tanuki

Linux Active Directory triage for AI coding agents. Protocol-first, zero noise.

Version 1.2.1 Rust 1.75+ Python 3.10+ Zero Dependencies RFC 4120 License: MIT OR Apache-2.0 Demo Video

Quick Start • Dual-Engine Architecture • Live Lab Validation • Demo Video • Decision Ladder • Before & After • Tooling & Usage • Agent Setup • Lineage & Credits


Quick Start (1-Line Universal Install)

Tanuki is 100% plug-and-play. One command installs the unified CLI and configures AI Agent Skills for Claude Code, Cursor, and Google Antigravity:

Linux & macOS

curl -sSL https://raw.githubusercontent.com/Mafifrizi/tanuki/main/install.sh | bash

Windows (PowerShell)

irm https://raw.githubusercontent.com/Mafifrizi/tanuki/main/install.ps1 | iex

Via Pipx / Pip / Cargo

# Pipx (Isolated CLI environment)
pipx install git+https://github.com/Mafifrizi/tanuki.git

# Local repository install
pip install .

# Note for Linux (Kali, Debian, Ubuntu): If ~/.local/bin is not in your PATH:
export PATH="$HOME/.local/bin:$PATH"

# Rust binary install
cargo install --path crates/tanuki-cli

Verify your installation:

# Direct CLI binary or universal Python module
tanuki --version
python3 -m tanuki --version

tanuki doctor
tanuki ladder
tanuki triage KRB_AP_ERR_SKEW

Dual-Engine Architecture

Tanuki ships two complementary implementations:

  1. Rust Systems Core (crates/tanuki-cli): The primary high-performance engine for operator workstations, CI/CD security validation pipelines, and standalone deployment. It compiles into a single static binary with #![forbid(unsafe_code)], zero external dependencies, and execution times under 2 milliseconds.
  2. Python Fallback Engine (scripts/): A zero-dependency script suite using only the Python standard library (struct, io, sys). It operates directly on remote target systems where dropping compiled binaries is prohibited or monitored by endpoint detection.

Both engines share an identical JSON schema and parsing specification.


Live Lab Empirical Validation

All protocol parsers, diagnostics, and CLI workflows are empirically validated across live virtualized lab environments:

  • Active Directory Domain Controller: Windows Server 2022 (DC01.lab.local, IP: 192.168.56.106)
  • Operator Workstation: Kali Linux 2024 (kraii@kraiiandreyy, IP: 192.168.56.105)

Full-Stack End-to-End Walkthrough (Live Lab Validation)

📺 Watch Demo Video: youtu.be/wqZRYmEn0eY - Full-stack operational walkthrough across live domain infrastructure.

Visual verification of the complete 3-act operational lifecycle across live domain infrastructure:

ActEnvironmentObjectives & Validated Primitives
Act 1: Domain Controller SetupWindows Server 2022 (DC01)Domain discovery (nltest), SPN audit (setspn), and RFC 4120 AES-256 binary keytab export (ktpass, KVNO 9).
Act 2: Unprivileged Linux OperatorKali Linux 2024 (Naga)Passive diagnostic (tanuki doctor), RFC 4120 tree audit (tanuki keytab), zero-root config synthesis (tanuki config), native ctypes TGT acquisition (tanuki auth), ticket health pass (tanuki doctor), and protocol triage (tanuki triage).
Act 3: Closed-Loop VerificationWindows Server 2022 (DC01)Domain Controller Security Event ID 4768 Audit Success for tanuki-nhi originating from client IP 192.168.56.105.

Act 1: Domain Controller Service Setup & Keytab Provisioning (DC01)

Official RFC 4120 binary keytab export on the Domain Controller for service account LAB\tanuki-nhi with modern AES-256 (aes256-cts-hmac-sha1-96, KVNO 9):

Act 1: Windows Server DC01 Setup and ktpass Export

Act 2: Unprivileged Linux Operator Session & Health Validation (Naga)

1. Pre-Flight Health Diagnostic Baseline (tanuki doctor)

Passive, zero-packet pre-flight health diagnostic executing in 0.96 ms, accurately detecting unconfigured state, missing keytabs, and inactive ticket caches:

Act 2.1: Pre-Flight Doctor Baseline

2. RFC 4120 Keytab Ingestion & Tree Audit (tanuki keytab)

Parses binary keytab structures, extracts AES-256 principals, displays hierarchical principal trees, verifies KVNO 9, and provides automated kinit guidance:

Act 2.2: RFC 4120 Keytab Tree Hierarchy

3. Zero-DNS Kerberos Configuration Generator (tanuki config)

Generates a local Kerberos configuration file (/tmp/lab_krb5.conf) enforcing RFC 4120 § 6.1 uppercase realm conventions, zero-DNS direct KDC IP routing, and hypervisor clock-skew tolerance:

Act 2.3: Zero-DNS Configuration Generator

4. Unprivileged Native TGT Acquisition (tanuki auth)

Acquires a Kerberos Ticket Granting Ticket (TGT) directly from the Domain Controller using Python standard library ctypes (libkrb5.so.3) without requiring root privileges, kinit binary on PATH, or external dependencies:

Act 2.4: Unprivileged TGT Acquisition via ctypes

5. Post-Authentication Health Diagnostic Pass (tanuki doctor)
Download Tool