Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

FeedsContatoPrivacidade© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
Kestrel — Low-observability Active Directory security enumeration tool using native ADSI/COM interfaces. Enumerates ACLs, delegation, trusts, ADCS, Kerberoast targets, and attack paths without .NET or PowerShell, producing BloodHound-compatible output. | Kitploit
Ferramentas/GitHubGitHub/ssteelfactor-oss/kestrel
Defensive ToolsPrivilege EscalationReconnaissanceVulnerability AnalysisInformation GatheringPost-ExploitationPenetration TestingRed Teaming
GitHubssteelfactor-oss/kestrel

Kestrel

Low-observability Active Directory security enumeration tool using native ADSI/COM interfaces. Enumerates ACLs, delegation, trusts, ADCS, Kerberoast targets, and attack paths without .NET or PowerShell, producing BloodHound-compatible output.

95934há 13 diasRevisado pelo Kitploit

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Ver Repositório
Compartilhar
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

Kestrel

build license language dependencies

BloodHound shows you the path. Kestrel shows you what's already inside.

Everyone maps the same thing: the attack path - who can reach Domain Admin. It's the right question, and the tools that answer it are excellent. But a graph of "who can reach whom" is blind to an entire class of problem, because some of the worst things in an Active Directory aren't a path at all.

They're a backdoor welded into an attribute. A certificate that keeps authenticating long after the password is reset. A permission stamped into the schema itself, so every object created from now on inherits it silently. A deleted account someone quietly kept the right to bring back. An object hidden from enumeration by a single deny-read ACE.

None of that is an edge in a graph. All of it is sitting in your directory right now. Kestrel reads it - with native Windows calls, ordinary domain-user rights, no server, no Python, no agent, and a footprint on the domain controller so restrained it's documented event-by-event.

One .exe. One command. Everything below.


You've been looking the wrong way

The offensive AD ecosystem - SharpHound, impacket, Certipy, and the graph behind them - is superb, and it all looks at the same surface: reachability. Kestrel looks at the three dimensions that surface can't express.

  • Time. A graph is a snapshot. Kestrel reads replication metadata - when a Tier-0 attribute changed and which DC originated it. A DCSync right granted last night is not the same finding as one that's been there for years, and only one of them means you're being attacked right now.
  • Persistence in an attribute, not an edge. Shadow credentials, SID history, reanimate-tombstones, schema defaultSecurityDescriptor backdoors, hidden objects, OWNER RIGHTS deny-ACEs, AD FS DKM keys. The graph tools don't collect these because there's no edge to draw.
  • Defensive posture, inverted. Not "who can attack," but "what isn't protected" - the Tier-0 account outside its silo, the sync account with a random RID that nobody tagged, the lockout policy that never throttles a spray.

It's not that Kestrel is faster than a graph. It answers questions the graph can't ask.


Every AD sin, in one native exe

SinWhat Kestrel findsFlag(s)
Replication & delegationDCSync rights (who can replicate - without ever replicating), unconstrained / constrained / RBCD / S4U delegation--acl · --delegation
Certificate abuseAD CS ESC1–5/9, rogue CA in the NTAuth store, long-lived cert persistence, AD FS DKM key ACL - the Golden SAML precondition--adcs · --adfs
Persistence in attributesShadow credentials, SID history injection, tombstone-reanimation rights, hidden objects, schema defaultSecurityDescriptor backdoors, orphaned adminCount--shadowcreds · --sidhistory · --acl · --schema · --adminsdholder
Cleartext & crackable credsGPP cpassword, unattend/sysprep secrets and script passwords across SYSVOL, Kerberoastable and AS-REP-roastable accounts, LAPS coverage gaps--gpp · --roast · --laps
Cross-domain & hybridForeign principals in privileged groups, Entra Connect sync accounts tagged Tier-0, trust posture, machine accounts created via MachineAccountQuota (mS-DS-CreatorSID)--groups · --trust · --machines
Posture & reconPassword / PSO policy, krbtgt age, LLMNR / NBT-NS / WDigest / NTLMv1 GPO settings, gMSA readers, stale computers, delegation topology--pwdpolicy · --policy · --gmsa · --stale
ArchaeologyOrphaned dangerous ACEs (a right held by a deleted principal - the SID resolves to nobody), stale privileged accounts (forgotten, over-privileged, ancient password)--archaeology
Domain hardeningdSHeuristics anonymous-LDAP / AdminSDHolder-exclusion flags, Pre-Windows 2000 Compatible Access broad membership--hardening
Service posture (read from AD, no packet to the service)Exchange-to-DA escalation & EOL, SCCM container takeover & site map, ADIDNS zone poisoning (Authenticated Users can create records)--exchange · --sccm · --dns

Two dozen-plus checks that are usually spread across a dozen scripts and two languages. Here they're one binary - and they end in a single, severity-sorted verdict.


One line

Kestrel.exe --all --report audit.html

Run everything. Get the full HTML report. And, at the very end of the console, the part that matters:

═══ Kestrel - Prioritized Findings ═══

  CRITICAL  DCSync         CORP\svc_sql - non-default principal can replicate directory changes (DCSync)
                          → fix: remove GetChanges/GetChangesAll from the principal on the domain head (dsacls) unless it is a DC
  CRITICAL  AD FS          CN=... - read access to the DKM key (Golden SAML precondition)
                          → fix: remove non-default read ACEs on the DKM object (dsacls) and rotate the token-signing certificate
  HIGH      Persistence    CN=... - object hidden from enumeration via a broad deny-read ACE
                          → fix: inspect the hidden object and remove the broad deny-read ACE (dsacls)

  [=] 2 critical · 1 high · 0 medium · 0 low

Not a wall of output. The findings that matter, ranked, each with the command to close it.


One exe. Red, blue, purple.

  • Red / grey - enumerate persistence and delegation the graph misses, export straight to BloodHound CE OpenGraph (--opengraph) to fuse with your existing collection, or pivot from any principal (--from).
  • Blue - a prioritized, remediated findings list; a --diff against last week's snapshot to catch what changed; and a tool whose exact detection footprint is published so you can whitelist it and tune your own alerting around it.
  • Purple - one artifact both sides read the same way. Red finds it, blue fixes it, everyone points at the same line number.

Detectable by design

Kestrel is read-only. It never writes to the directory, never replicates, never needs SeSecurityPrivilege, never touches the cloud. Reading who can DCSync looks nothing, on the wire, like doing DCSync - no DRSUAPI, no replication-signature 4662. Every query it runs and every event it can (and cannot) generate is catalogued in FOOTPRINT.md. An auditor that tells the defender exactly how to catch it isn't a contradiction - it's the whole point.


Quick start

Grab a build. Every green CI run publishes a Kestrel.exe artifact - download it from the Actions tab, no toolchain required.

Or build it yourself. Visual Studio (v143+) or MSBuild:

git clone https://github.com/ssteelfactor-oss/Kestrel.git
cd Kestrel
msbuild Kestrel.vcxproj /p:Configuration=Release /p:Platform=x64

Pure C, zero third-party dependencies. Build /MT and it's a single self-contained executable - drop it on a domain-joined host, run as any ordinary user.

Run it.

Baixar ferramenta