Skip to content
ADscan Docs

ADscan Documentation

Active Directory exposure management — from assessment to client deliverable in one command.

ADscan

Active Directory exposure management for pentesters, MSSPs, and CISOs.

One command runs the assessment. On an engagement workspace it writes the client report by itself. No tool-hopping.

Current version: 10.1.0 LITE

Three tiers

TierWhat it isWho uses it
LITEFree CLI engine — community-maintained scan corePentesters, red teamers, students
PROLITE plus the Client Deliverable Kit — three PDFs, the ATT&CK Navigator bundle, and a ZIPMSSPs, consultancies billing engagements
EnterpriseContinuous CTEM/BAS web service with weekly digestCISOs operating their own AD posture

Compare tiers

Three paths to start

What ADscan does

  • Active Directory enumeration — DNS, LDAP, SMB, Kerberos, ADCS, trust spidering, native graph collection.
  • Attack execution — Kerberoasting, AS-REP roasting, ACL abuse, GPP, GPO abuse, constrained-delegation SPN-jacking (SPNJack), DCSync, ADCS ESC1-16.
  • A report you did not ask for — on an audit workspace, ADscan writes a client-ready exposure report (HTML and PDF) the moment the scan finishes. Free tier, no command. It carries the posture score, the findings, the validated attack paths with each step's honest status, the choke-point ranking, and a disclosure of every change ADscan made to the directory.
  • Client Deliverable Kit (PRO) — Security Assessment Report, AD Hardening Playbook, AD Control Coverage Report, plus the interactive MITRE ATT&CK Navigator bundle, generated in about 90 seconds with adscan deliver.

Reference

Community & support

Find this useful?
Pass it to the next pentester running an AD engagement
Running 2+ AD engagements/year?
Get PRO free — beta access·Free in exchange for feedback
Automated PDF reports. Save ≥1 day per engagement.

ADscan — AD pentest automation for security consultants

ADscan Documentation | ADscan