Skip to content

ADscan is a pentesting tool focused on automating collection, enumeration and common attack paths in Active Directory. It provides an interactive CLI with a wide range of commands to streamline internal audits and AD-focused pentests.

License

Notifications You must be signed in to change notification settings

ADScanPro/adscan

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

59 Commits
Β 
Β 
Β 
Β 

Repository files navigation

adscan_wordmark_horizontal_transparent_cropped

Version downloads License: BSL 1.1 Platform Discord

Automate Active Directory pentesting. From DNS to Domain Admin.

Docs | Discord | Website


🎬 Demo

asciicast

Auto-pwns HTB Forest in ~3 minutes


πŸš€ Quick Start

pip install adscan
adscan install
adscan start

Full installation guide & docs at adscanpro.com/docs


✨ Features

LITE (Free, Source Available)

Everything a pentester could do manually, 10x faster:

  • βœ… Three operation modes (automatic/semi-auto/manual)
  • βœ… DNS, LDAP, SMB, Kerberos enumeration
  • βœ… AS-REP Roasting & Kerberoasting
  • βœ… Password spraying
  • βœ… BloodHound collection & analysis
  • βœ… Credential harvesting (SAM, LSA, DCSync)
  • βœ… ADCS detection & template enumeration
  • βœ… GPP passwords & CVE enumeration
  • βœ… Export to TXT/JSON
  • βœ… Workspace & evidence management

PRO

What nobody can do manually in reasonable time:

  • 🎯 Algorithmic attack graph generation
  • 🎯 Auto-exploitation chains (DNS to DA)
  • 🎯 ADCS ESC1-13 auto-exploitation
  • 🎯 MITRE-mapped Word/PDF reports
  • 🎯 Multi-domain trust spidering
  • 🎯 Advanced privilege escalation chains
  • 🎯 Priority enterprise support

Full comparison | Learn more


πŸ“‹ Requirements

OS Linux (Debian/Ubuntu/Kali)
Docker Docker Engine + Compose
Privileges docker group or sudo
Network Internet (pull images) + target network

πŸ“œ License

Source available under the Business Source License 1.1.

  • Use freely for pentesting (personal or paid engagements)
  • Read, modify, and redistribute the source code
  • Cannot create a competing commercial product
  • Converts to Apache 2.0 on 2029-02-01

πŸ’¬ Community

Discord GitHub Issues

Enterprise support: hello@adscanpro.com


(c) 2024-2026 Yeray Martin Dominguez | adscanpro.com

About

ADscan is a pentesting tool focused on automating collection, enumeration and common attack paths in Active Directory. It provides an interactive CLI with a wide range of commands to streamline internal audits and AD-focused pentests.

Topics

Resources

License

Stars

Watchers

Forks

Packages

No packages published