Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
dc-sonar — Analyzing AD domains for security risks related to user accounts | Kitploit
Tools/GitHubGitHub/st1lly/dc-sonar
Password CrackingVulnerability AnalysisLearning & Education
GitHubst1lly/dc-sonar

dc-sonar

Analyzing AD domains for security risks related to user accounts

View RepositoryWebsite
649113 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

DC Sonar Community

Repositories

The project consists of repositories:

  • dc-sonar-frontend
  • dc-sonar-user-layer
  • dc-sonar-workers-layer
  • ntlm-scrutinizer

Disclaimer

It's only for education purposes.

Avoid using it on the production Active Directory (AD) domain.

Neither contributor incur any responsibility for any using it.

Social media

Check out our Red Team community Telegram channel

Content

  1. Description
    1. Architecture
    2. Functionallity
  2. Installation
    1. Docker
    2. Manually using dpkg
  3. Style guide
  4. Deployment for development
    1. Docker
    2. Manually using Windows host and Ubuntu Server guest
      1. Set up the virtual machine
      2. Config Window
      3. Set shared folders
      4. Config Ubuntu Server
      5. Layers

Description

Architecture

For the visual descriptions, open the diagram files using the diagrams.net tool.

The app consists of:

  • The dc-sonar-frontend is the fronted part of the user web interface bases on:
    • Angular
    • Angular Material
  • The dc-sonar-user-layer is the backend part of the web app bases on:
    • Python 3.10
    • Django
    • Django ORM
    • Django REST framework
    • Celery
    • RabbitMQ
    • PostgreSQL
  • The dc-sonar-workers-layer is the logic layer that performs and runs analyzing processes which base on:
    • Python 3.10
    • SQLAlchemy
    • Alembic
    • APScheduler
    • RabbitMQ
    • PostgreSQL
  • The ntlm-scrutinizer is the NTLM hashes performer with REST API based on:
    • Python 3.10
    • FastAPI
    • hashcat
    • impacket

Functionallity

The DC Sonar Community provides functionality for analyzing AD domains for security risks related to accounts:

  • Register analyzing AD domain in the app

    register_ad

  • See the statuses of domain analyzing processes

    domains_analyze_statuses

  • Dump and brute NTLM hashes from set AD domains to list accounts with weak and vulnerable passwords

    weak_passwords

  • Analyze AD domain accounts to list ones with never expire passwords

    no_expired_passwords

  • Analyze AD domain accounts by their NTLM password hashes to determine accounts and domains where passwords repeat

    reused_passwords

Installation

Docker

In progress ...

Manually using dpkg

It is assumed that you have a clean Ubuntu Server 22.04 and account with the username "user".

The app will install to /home/user/dc-sonar.

The next releases maybe will have a more flexible installation.

Download dc_sonar_NNNN.N.NN-N_amd64.tar.gz from the last distributive to the server.

Create a folder for extracting files:

mkdir dc_sonar_NNNN.N.NN-N_amd64

Extract the downloaded archive:

tar -xvf dc_sonar_NNNN.N.NN-N_amd64.tar.gz -C dc_sonar_NNNN.N.NN-N_amd64

Go to the folder with the extracted files:

cd dc_sonar_NNNN.N.NN-N_amd64/

Install PostgreSQL:

sudo bash install_postgresql.sh

Install RabbitMQ:

sudo bash install_rabbitmq.sh

Install dependencies:

sudo bash install_dependencies.sh

It will ask for confirmation of adding the ppa:deadsnakes/ppa repository. Press Enter.

Install dc-sonar itself:

sudo dpkg -i dc_sonar_NNNN.N.NN-N_amd64.deb

It will ask for information for creating a Django admin user. Provide username, mail and password.

It will ask for information for creating a self-signed SSL certificate twice. Provide required information.

Open: https://localhost

Enter Django admin user credentials set during the installation process before.

Style guide

See the information in STYLE_GUIDE.md

Deployment for development

Docker

In progress ...

Manually using Windows host and Ubuntu Server guest

In this case, we will set up the environment for editing code on the Windows host while running Python code on the Ubuntu guest.

Set up the virtual machine

Create a virtual machine with 2 CPU, 2048 MB RAM, 10GB SSD using Ubuntu Server 22.04 iso in VirtualBox.

If Ubuntu installer asks for updating ubuntu installer before VM's installation - agree.

Choose to install OpenSSH Server.

VirtualBox Port Forwarding Rules:

NameProtocolHost IPHost PortGuest IPGuest Port
SSHTCP127.0.0.1222210.0.2.1522
RabbitMQ management consoleTCP127.0.0.11567210.0.2.1515672
Django ServerTCP127.0.0.1800010.0.2.158000
NTLM ScrutinizerTCP127.0.0.1500010.0.2.155000
PostgreSQLTCP127.0.0.12543210.0.2.155432

Config Window

Download and install Python 3.10.5.

Create a folder for the DC Sonar project.

Go to the project folder using Git for Windows:

cd '{PATH_TO_FOLDER}'

Make Windows installation steps for dc-sonar-user-layer.

Make Windows installation steps for dc-sonar-workers-layer.

Make Windows installation steps for ntlm-scrutinizer.

Make Windows installation steps for dc-sonar-frontend.

Set shared folders

Download Tool