21+ Active Directory capabilities. One authorized run.
Enumerate, coerce, roast, relay, escalate, forge, and pivot — with native transports, lockout-aware throttling, and proof-graded evidence in every finding.
Coverage
- Enumeration: anonymous LDAP / SMB, Kerbrute (lockout-aware), SAM / LSA dumps, GPO abuse, cross-forest trust mapping.
- Credential access: AS-REP Roasting, Kerberoasting, LDAP spray, DCSync, LAPS / gMSA read, NTLM capture / coercion (PrinterBug, PetitPotam) / relay / downgrade, shadow credentials, hash cracking.
- Escalation: ADCS ESC1–ESC15, unconstrained / constrained / RBCD delegation abuse, Golden / Silver / Diamond / Sapphire ticket forging, Zerologon and noPac (destructive classes default-deny).
- Lateral movement (no impacket): DCERPC SCMR (psexec), WMI (wmiexec), DCOM, AtSvc (atexec), WSMan (winrm), pass-the-hash across every transport, SCCM attack chain.