AdStrike by capture0x

AdStrike for AI-guided Active Directory operations.

A terminal Active Directory attack framework with an AI operator mode, MCP tool server, Smart Analyst, and session-aware evidence workflow for authorized assessments.

Python 3.10+Ollama / Claude agent53 MCP tools52 executable toolsSmart AnalystLive Markdown reports
AdStrike logo
AdStrikeAI operator and MCP toolbox for AD assessments
main menu
AdStrike terminal main menu
52 modules58 entries9 groups

Engagement workspace

Session-aware modules for AD operations.

AdStrike stores target, domain, credential, Kerberos, finding, command, BloodHound, and runtime state in one workspace. Its modules and AI paths reuse that context instead of forcing repeated operator input.

58menu entries52attack modules53MCP tools9kill-chain groups

Capabilities

Scrub through what AdStrike handles during an assessment.

These capabilities summarize how AdStrike connects discovery, identity analysis, AI assistance, execution paths, and reporting into one assessment workflow.

01

Engagement workspace

Keep target, domain, username, password or NT hash, Kerberos ccache, findings, command history, BloodHound data, and runtime artifacts in one reusable session.

Session context reuseCredential and ticket stateOrganized evidence

Module map

Coverage from recon through reporting.

AdStrike groups its menu into nine kill-chain phases plus utilities, covering no-credential surface checks, identity abuse, lateral movement, credential access, persistence, cloud and hybrid paths, reporting, Smart Analyst, and the AI agent.

Reconnaissance

DNS, OSINT, nmap, masscan, IPv6, surface discovery

Initial access

NTLM capture, relay paths, CVE checks, AMSI/EDR/UAC workflows

Enumeration

LDAP, SMB, GPO, DNS, BloodHound, NetExec/NXC, user hunting

Privilege escalation

Kerberos, ADCS, ACL abuse, RBCD, Shadow Credentials, RODC

Lateral movement

PSExec, WMIExec, SMBExec, DCOM, WinRM, MSSQL

Credential access

LSASS, SAM, NTDS, DPAPI, DCSync, shadow copies

Persistence

Tickets, AdminSDHolder, GPO, DNSAdmins, trusts, local persistence

Cloud and hybrid

Azure AD, Entra hybrid, ADFS, Golden SAML, M365, Teams

Advanced operations

Exploit chains, C2 integration, loot parsing, AD playbooks, AI agent

MCP integration

No API key required for the MCP path.

AdStrike can be connected to MCP-capable AI clients so the client supplies the model while AdStrike provides structured actions for the assessment.

01

Configure the engagement once

Store the domain controller, domain, identity, and authentication method once, then reuse that context across the assessment without repeating sensitive values in every request.

claude mcp add adstrike -- /path/to/AdStrike/venv/bin/python3 /path/to/AdStrike/mcp_server.py
02

Use 53 structured actions

The MCP path exposes the same assessment capabilities used by the standalone AI operator, including discovery, identity analysis, Kerberos workflows, execution paths, planning, and reporting.

Engagement setupNmap scanningLDAP enumerationBloodHound collectionADCS scanningACL reviewKerberoastingAS-REP roastingWinRM accessChain planningReport export

Screenshots

Terminal views for enumeration, BloodHound, agent, and analyst workflows.

AD enumeration
AdStrike AD enumeration screenshot
BloodHound helper
AdStrike BloodHound helper screenshot
AdStrike Agent
AdStrike AdStrike Agent screenshot
Smart Analyst
AdStrike Smart Analyst screenshot

Quick start

Install locally, configure the session, then run the framework.

adstrike

$ git clone https://github.com/capture0x/AdStrike.git

$ cd AdStrike

$ chmod +x install.sh run.sh

$ bash install.sh

$ source venv/bin/activate

$ bash run.sh

$ python3 main.py --check

Analyst and reports

AI guidance, artifact parsing, and exportable evidence.

The agent can run full-auto or plan-only with Ollama or Claude. Smart Analyst then reads collected artifacts and reports turn findings, command history, and attack-chain reasoning into reviewable output.

01

AI operator loop

Run with Ollama local models or Claude API models, choose full-auto execution or plan-only mode, and select loud, normal, or stealth OPSEC behavior.

02

Smart Analyst parsing

Smart Analyst reads BloodHound JSON, LDAP enumeration files, session findings, agent logs, Kerberos artifacts, hashes, and collected evidence before building a prioritized attack plan.

03

Live reporting

Agent runs write round-by-round Markdown logs, recorded tool commands, sanitized results, mission summaries, captured-hash placeholders, findings, and attack-chain plans.

FAQ

Common questions about AdStrike.

What is AdStrike built for?

AdStrike is built for authorized Active Directory assessments where the operator needs discovery, identity analysis, Kerberos workflows, execution paths, evidence handling, and reporting in one terminal workflow.

Does AdStrike require an AI model?

No. The manual console and modules can be used directly. AI-assisted operation is available for users who want planning, full-auto workflows, or MCP-driven operation.

What does the MCP integration add?

It lets an MCP-capable AI client call structured AdStrike actions while AdStrike keeps the engagement context and assessment output organized.

Is this only for labs?

No. It supports lab and professional assessment workflows, but it must only be used on systems you own or have explicit written authorization to test.

What outputs does AdStrike create?

AdStrike can preserve command history, findings, collected artifacts, live agent notes, and reports in HTML, Markdown, and JSON formats.

Which systems does it target?

The workflows focus on Active Directory environments, including Windows domain services, Kerberos, LDAP, SMB, ADCS, BloodHound data, WinRM, MSSQL, cloud and hybrid identity paths.

AdStrike is intended only for lawful administration, research, and security testing on systems you own or have explicit written authorization to assess.