awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com

Active Directory Pentesting Labs

Ranking updated Jun 30, 2026

For an Active Directory attack toolkit, the first results are specterops/bloodhound (BloodHound is a graph-based attack path analyzer for Active Directory that maps identity relationships and permissions, making it a core reconnaissance tool for AD vulnerabilities, but it does not directly perform exploitation actions like Kerberoasting or DCSync), byt3bl33d3r/crackmapexec and secureauthcorp/impacket. adaptivethreat/bloodhound and lgandx/responder round out the shortlist. Compare the match explanations and check the project documentation against your requirements.

Discover open-source frameworks and vulnerable environments designed for practicing Active Directory exploitation and security assessment techniques.

Active Directory Pentesting Labs

Find the best repos with AI.We'll search the best matching repositories with AI.
  • specterops/bloodhoundSpecterOps avatar

    SpecterOps/BloodHound

    2,789View on GitHub↗

    BloodHound is an identity risk management platform and graph-based attack path analyzer used to map identity relationships and permissions in Active Directory. It functions as a security tool for auditing directory services, uncovering unintended privilege relationships, and visualizing sequences of permissions that can lead to domain compromise. The project differentiates itself as a comprehensive adversary emulation framework that coordinates remote agents and executes post-exploitation commands. It includes a reverse proxy for bypassing multi-factor authentication via real-time session hij

    BloodHound is a graph-based attack path analyzer for Active Directory that maps identity relationships and permissions, making it a core reconnaissance tool for AD vulnerabilities, but it does not directly perform exploitation actions like Kerberoasting or DCSync.

    GoAutomated Kerberos AttacksCredential Memory DumpingActive Directory Enumeration
    View on GitHub↗2,789
  • byt3bl33d3r/crackmapexecbyt3bl33d3r avatar

    byt3bl33d3r/CrackMapExec

    9,144View on GitHub↗

    CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security postures across large IP ranges. It functions as a multi-protocol security scanner and network protocol auditor used to identify vulnerabilities and misconfigurations. The tool provides capabilities for Active Directory auditing to enumerate users and permissions, as well as post-exploitation enumeration to gather system metadata and discover lateral movement paths. It includes a framework for credential spraying and harvesting across various network services. The system utilize

    CrackMapExec is a comprehensive Active Directory penetration testing framework that covers LDAP enumeration, Kerberos attacks, SMB/RDP/WinRM exploitation, credential spraying, and many post-exploitation techniques, making it a strong fit for mapping and exploiting AD vulnerabilities in a lab—though it lacks built-in graph visualization like BloodHound.

    PythonPenetration Testing FrameworksPenetration Testing SuitesActive Directory Security
    View on GitHub↗9,144
  • secureauthcorp/impacketSecureAuthCorp avatar

    SecureAuthCorp/impacket

    15,850View on GitHub↗

    Impacket is a Python network protocol library and packet crafting framework used for constructing, modifying, and sending raw network packets. It functions as a network protocol manipulation toolkit that allows for the implementation of communication protocols through structured object models. The project provides a Windows network security toolkit specifically designed for interacting with Active Directory and SMB services. It enables network security testing and auditing of Windows environments by executing authentication sequences using passwords, hashes, tickets, or security keys. The li

    Impacket is a foundational Python toolkit for Active Directory exploitation and reconnaissance, providing scripts for LDAP enumeration, Kerberos attacks (AS-REP roasting, Kerberoasting), SMB/RDP/WinRM access, DCSync, ACL abuse, and credential dumping—covering nearly all the attack techniques you listed, though it does not include BloodHound-style graph visualization.

    PythonPacket Manipulation ToolkitsNetwork Protocol ImplementationsPacket Construction
    View on GitHub↗15,850
  • adaptivethreat/bloodhoundadaptivethreat avatar

    adaptivethreat/Bloodhound

    10,552View on GitHub↗

    Bloodhound is an Active Directory attack path mapper and security auditor designed to visualize trust relationships and permission chains. It serves as an attack surface management tool that identifies paths to domain administrator and other high-privileged accounts. The project uses a graph database analyzer to map complex identity and access relationships. It quantifies the risk of privilege escalation by identifying misconfigured permissions and trust links within Windows domains. The system provides capabilities for Active Directory security analysis, identity and access auditing, and ne

    BloodHound is the definitive Active Directory attack path mapper, providing graph-based visualization of trust relationships and privilege escalation paths—it delivers the reconnaissance and analysis side of this search directly, though you would need companion tools (like Impacket or Rubeus) for the actual Kerberos attacks, NTLM relay, and exploitation steps the full feature list describes.

    PowerShellActive Directory Security ToolsAccess AuditingAttack Path Graphs
    View on GitHub↗10,552
  • lgandx/responderlgandx avatar

    lgandx/Responder

    6,335View on GitHub↗

    Responder is a network penetration testing tool that intercepts and spoofs link-local name resolution queries, including LLMNR, NBT-NS, and mDNS, to redirect traffic to an attacker-controlled host. It hosts rogue protocol servers for over 15 protocols, capturing authentication credentials during challenge-response handshakes, and stores captured hashes and cleartext credentials in a SQLite database for structured offline analysis. The tool distinguishes itself through its ability to relay captured NTLM authentication challenges to target services for lateral movement without cracking the hash

    Responder is a focused credential interception and NTLM relay tool for penetration testing, not a comprehensive AD reconnaissance or exploitation toolkit—it lacks LDAP enumeration, BloodHound-like visualization, and broader attack features like DCSync or GPO abuse.

    PythonKerberos AS-REP Hash CapturersKerberos Hash CapturersNTLM Authentication Relays
    View on GitHub↗6,335
  • parrotsec/mimikatzParrotSec avatar

    ParrotSec/mimikatz

    2,536View on GitHub↗

    Mimikatz is a Windows post-exploitation framework designed for extracting plaintext passwords, hashes, PIN codes, and security tokens from system memory and the registry. It functions as a credential extraction tool that targets the Local Security Authority Subsystem Service to retrieve cached credentials and sensitive account data. The project provides specialized capabilities for Active Directory penetration testing, including the simulation of domain controllers to replicate directory secrets. It features a Kerberos ticket manipulator capable of exporting, injecting, and forging authentica

    Mimikatz is a specialized post-exploitation tool for credential extraction and Kerberos ticket attacks, but it does not provide the broader AD reconnaissance, LDAP enumeration, BloodHound-like visualization, or multi-protocol exploitation features the visitor is looking for.

    YARACredential DumpingCredential Memory Dumping
    View on GitHub↗2,536
  • barbarisch/forkatzBarbarisch avatar

    Barbarisch/forkatz

    123View on GitHub↗

    credential dump using forshaw technique using SeTrustedCredmanAccessPrivilege

    This is a narrow credential dumping tool using a specific technique (Forshaw/SeTrustedCredmanAccessPrivilege), not a comprehensive AD attack and reconnaissance toolkit covering enumeration, Kerberos attacks, graph visualization, or the broad exploitation features you need.

    C++Credential Dumping
    View on GitHub↗123
  • edermi/f8b143b11dc020b854178d3809cf91b5E

    edermi/f8b143b11dc020b854178d3809cf91b5

    0View on GitHub↗

    Based on the single tag "Credential Dumping," this repository appears to be a tool focused on credential extraction, but with no description or other evidence, it cannot be confirmed as a comprehensive Active Directory attack and reconnaissance toolkit covering the requested features like LDAP enumeration, Kerberos attacks, or graph visualization.

    Credential Dumping
    View on GitHub↗0
  • eladshamir/internal-monologueeladshamir avatar

    eladshamir/Internal-Monologue

    1,673View on GitHub↗

    Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

    Internal Monologue is a single-purpose tool for retrieving NTLM hashes without touching LSASS, but it is not a comprehensive AD reconnaissance and exploitation toolkit covering enumeration, Kerberos attacks, graph visualization, or the other features you seek.

    C#Credential Dumping
    View on GitHub↗1,673
  • ghostpack/keethiefGhostPack avatar

    GhostPack/KeeThief

    956View on GitHub↗

    Allows for the extraction of KeePass 2.X key material from memory, as well as the backdooring and enumeration of the KeePass trigger system.

    Keethief extracts KeePass key material from memory, which can be useful during Active Directory credential stealing, but it is a narrow single-purpose tool rather than a comprehensive AD attack and reconnaissance toolkit covering LDAP enumeration, Kerberos attacks, graph visualization, and the other features you listed.

    C#Credential Dumping
    View on GitHub↗956
  • ghostpack/kohGhostPack avatar

    GhostPack/Koh

    523View on GitHub↗

    Koh is a C# and Beacon Object File (BOF) toolset that allows for the capture of user credential material via purposeful token/logon session leakage.

    Koh is a targeted credential-dumping tool for capturing token/session material, not a comprehensive Active Directory attack and reconnaissance toolkit that maps relationships and supports LDAP, Kerberos, or relay attacks.

    C#Credential Dumping
    View on GitHub↗523
  • alessandroz/lazagneAlessandroZ avatar

    AlessandroZ/LaZagne

    10,867View on GitHub↗

    LaZagne is a cross-platform credential recovery tool designed to extract passwords and secrets from operating systems, browsers, and applications. It functions as a security utility for retrieving stored credentials from compromised systems during penetration testing. The tool provides capabilities for decrypting domain credentials and extracting sensitive data from system storage, including memory dumps, credential managers, keychains, and password hashes. It recovers stored passwords from common software by accessing plaintext files, APIs, and local databases. The project supports digital

    LaZagne recovers credentials from local systems, which is useful in post-exploitation but lacks the AD enumeration, Kerberos attacks, and graph visualization central to an Active Directory attack and reconnaissance toolkit.

    PythonCredential Dumping
    View on GitHub↗10,867
Compare the top 10 at a glance
RepositoryStarsLanguageLicenseLast push
specterops/bloodhound2.8KGoapache-2.0Feb 19, 2026
byt3bl33d3r/crackmapexec9.1KPythonBSD-2-ClauseDec 6, 2023
secureauthcorp/impacket
15.9K
Python
NOASSERTION
Jun 19, 2026
adaptivethreat/bloodhound10.6KPowerShellGPL-3.0Mar 2, 2026
lgandx/responder6.3KPythongpl-3.0Jan 26, 2026
parrotsec/mimikatz2.5KYARA—Jun 28, 2024
barbarisch/forkatz123C++—May 22, 2021
edermi/f8b143b11dc020b854178d3809cf91b50———
eladshamir/internal-monologue1.7KC#—Oct 11, 2018
ghostpack/keethief956C#BSD-3-ClauseNov 18, 2020

Related searches

  • an Active Directory path mapper
  • a post-exploitation toolkit
  • an adversary emulation toolkit
  • an SMB and LDAP enumeration tool
  • a privilege escalation enumeration tool
  • an open source penetration testing framework
  • a tool for subdomain enumeration and reconnaissance
  • an osint toolkit for reconnaissance and enumeration