🛡️ Active Directory & Internal Pentest
This category focuses on Active Directory domain enumeration, lateral movement, Kerberos authentication attacks, and internal protocol poisoning.
Tool Catalog
BloodHound & SharpHound
Active Directory relationship mapping engine using graph databases to trace permission vectors.
Impacket Suite
A collection of Python classes for working with network protocols (SMB, Kerberos, LDAP, WMI).
CrackMapExec
A swiss-army knife for pentesting networks, designed to automate post-exploitation tasks on large Active Directory environments.
Kerbrute / Rubeus
Utilities to brute-force usernames/passwords via Kerberos and perform ticket operations (AS-REP Roasting, Kerberoasting).
Responder / ntlmrelayx
Protocol poisoning (LLMNR/NBT-NS) and relay tools to intercept and replay Windows hash credentials.