awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

Active Directory Pentesting Labs

Ranking updated Jun 30, 2026

For an Active Directory attack toolkit, the strongest matches are specterops/bloodhound (BloodHound is a graph-based attack path analyzer for Active), byt3bl33d3r/crackmapexec (CrackMapExec is a comprehensive Active Directory penetration testing framework) and secureauthcorp/impacket (Impacket is a foundational Python toolkit for Active Directory). adaptivethreat/bloodhound is also worth a look. Each is ranked by relevance to your query, popularity and recent activity.

Discover open-source frameworks and vulnerable environments designed for practicing Active Directory exploitation and security assessment techniques.

Active Directory Pentesting Labs

Find the best repos with AI.We'll search the best matching repositories with AI.
  • specterops/bloodhoundSpecterOps avatar

    SpecterOps/BloodHound

    2,789View on GitHub↗

    BloodHound is an identity risk management platform and graph-based attack path analyzer used to map identity relationships and permissions in Active Directory. It functions as a security tool for auditing directory services, uncovering unintended privilege relationships, and visualizing sequences of permissions that can lead to domain compromise. The project differentiates itself as a comprehensive adversary emulation framework that coordinates remote agents and executes post-exploitation commands. It includes a reverse proxy for bypassing multi-factor authentication via real-time session hij

    BloodHound is a graph-based attack path analyzer for Active Directory that maps identity relationships and permissions, making it a core reconnaissance tool for AD vulnerabilities, but it does not directly perform exploitation actions like Kerberoasting or DCSync.

    GoAutomated Kerberos AttacksCredential Memory DumpingActive Directory Enumeration
    View on GitHub↗2,789
  • byt3bl33d3r/crackmapexecbyt3bl33d3r avatar

    byt3bl33d3r/CrackMapExec

    9,144View on GitHub↗

    CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security postures across large IP ranges. It functions as a multi-protocol security scanner and network protocol auditor used to identify vulnerabilities and misconfigurations. The tool provides capabilities for Active Directory auditing to enumerate users and permissions, as well as post-exploitation enumeration to gather system metadata and discover lateral movement paths. It includes a framework for credential spraying and harvesting across various network services. The system utilize

    CrackMapExec is a comprehensive Active Directory penetration testing framework that covers LDAP enumeration, Kerberos attacks, SMB/RDP/WinRM exploitation, credential spraying, and many post-exploitation techniques, making it a strong fit for mapping and exploiting AD vulnerabilities in a lab—though it lacks built-in graph visualization like BloodHound.

    PythonPenetration Testing FrameworksPenetration Testing SuitesActive Directory Security
    View on GitHub↗9,144
  • secureauthcorp/impacketSecureAuthCorp avatar

    SecureAuthCorp/impacket

    15,850View on GitHub↗

    Impacket is a Python network protocol library and packet crafting framework used for constructing, modifying, and sending raw network packets. It functions as a network protocol manipulation toolkit that allows for the implementation of communication protocols through structured object models. The project provides a Windows network security toolkit specifically designed for interacting with Active Directory and SMB services. It enables network security testing and auditing of Windows environments by executing authentication sequences using passwords, hashes, tickets, or security keys. The li

    Impacket is a foundational Python toolkit for Active Directory exploitation and reconnaissance, providing scripts for LDAP enumeration, Kerberos attacks (AS-REP roasting, Kerberoasting), SMB/RDP/WinRM access, DCSync, ACL abuse, and credential dumping—covering nearly all the attack techniques you listed, though it does not include BloodHound-style graph visualization.

    PythonPacket Manipulation ToolkitsNetwork Protocol ImplementationsPacket Construction
    View on GitHub↗15,850
  • adaptivethreat/bloodhoundadaptivethreat avatar

    adaptivethreat/Bloodhound

    10,552View on GitHub↗

    Bloodhound is an Active Directory attack path mapper and security auditor designed to visualize trust relationships and permission chains. It serves as an attack surface management tool that identifies paths to domain administrator and other high-privileged accounts. The project uses a graph database analyzer to map complex identity and access relationships. It quantifies the risk of privilege escalation by identifying misconfigured permissions and trust links within Windows domains. The system provides capabilities for Active Directory security analysis, identity and access auditing, and ne

    BloodHound is the definitive Active Directory attack path mapper, providing graph-based visualization of trust relationships and privilege escalation paths—it delivers the reconnaissance and analysis side of this search directly, though you would need companion tools (like Impacket or Rubeus) for the actual Kerberos attacks, NTLM relay, and exploitation steps the full feature list describes.

    PowerShellActive Directory Security ToolsAccess AuditingAttack Path Graphs
    View on GitHub↗10,552

Related searches

  • an Active Directory path mapper
  • a post-exploitation toolkit
  • an adversary emulation toolkit
  • an SMB and LDAP enumeration tool
  • a privilege escalation enumeration tool
  • an open source penetration testing framework
  • a tool for subdomain enumeration and reconnaissance
  • an osint toolkit for reconnaissance and enumeration