How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.
PowerShell toolkit for auditing Active Directory Certificate Services (AD CS).
DONT USE GROUPER ANY MORE. USE GROUPER2! https://github.com/l0ss/Grouper2
BloodHound is a graph-based security analysis tool designed to map trust relationships and attack vectors within Active Directory environments. It functions as an attack path mapper and risk assessment system that uses graph theory to identify hidden relationships and paths leading to high-privilege accounts. The tool specializes in network attack surface mapping and privilege escalation pathfinding. It quantifies security risks by measuring the reliability of attack paths to critical targets, allowing for the prioritization of vulnerability elimination. The system provides capabilities for
Stormspotter creates an “attack graph” of the resources in an Azure subscription. It enables red teams and pentesters to visualize the attack surface and pivot opportunities within a tenant, and supercharges your defenders to quickly orient and prioritize incident response work.
Identify the attack paths in BloodHound breaking your AD tiering
The main features of improsec/improhound are: Domain Situational Awareness, Security Tooling.
Open-source alternatives to improsec/improhound include: l0ss/grouper — DONT USE GROUPER ANY MORE. USE GROUPER2! https://github.com/l0ss/Grouper2. bloodhoundad/bloodhound — BloodHound is a graph-based security analysis tool designed to map trust relationships and attack vectors within… ghostpack/pspkiaudit — PowerShell toolkit for auditing Active Directory Certificate Services (AD CS). azure/stormspotter — Stormspotter creates an “attack graph” of the resources in an Azure subscription. It enables red teams and pentesters… byt3bl33d3r/crackmapexec — CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security… bats3c/adcspwn — A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts…