AI Operator
Run an assisted assessment flow with local Ollama models or Claude. The operator can work in full-auto mode or generate a plan first, with OPSEC behavior selected for the engagement style.
AdStrikeFeatures
The framework combines operator-driven modules, AI assistance, MCP access, evidence handling, and reporting in a single terminal workflow.
Run an assisted assessment flow with local Ollama models or Claude. The operator can work in full-auto mode or generate a plan first, with OPSEC behavior selected for the engagement style.
Connect AdStrike to MCP-capable clients so the AI client supplies reasoning while AdStrike provides structured, session-aware security actions.
Map hosts, ports, domain services, LDAP reachability, SMB shares, WinRM access, ADCS exposure, MSSQL hints, and no-credential entry points.
Review users, groups, computers, ACLs, GPOs, delegation, gMSA, RBCD, Shadow Credentials, ADCS, RODC, trusts, LAPS, and BloodHound data.
Handle AS-REP roasting, Kerberoasting, ticket requests, ccache-driven access, PKINIT, PassTheCert, UnPAC, and NTLM-disabled environments.
Use WinRM, PSExec, WMIExec, MSSQL command execution, credential testing, post-shell collection, DCSync, and shadow-copy workflows during authorized assessments.
Parse collected artifacts, session findings, BloodHound data, LDAP output, hashes, and logs, then turn them into prioritized next steps.
Generate HTML, Markdown, and JSON reports, plus live round-by-round agent notes with commands, sanitized results, findings, summaries, and attack-chain plans.
Workflow
AdStrike is strongest when the operator needs a consistent path from initial discovery to evidence-backed action. The site content stays broad, but the workflow maps to the actual coverage: discovery, identity analysis, execution, credential access, persistence, and reporting.
Use discovery and no-credential checks to understand reachable services before committing to an identity path. This keeps early work grounded in what the environment actually exposes.
Combine LDAP, BloodHound, ACL, GPO, delegation, ADCS, and Kerberos signals so the next step is selected from evidence instead of guesswork.
Credentials, tickets, command history, findings, and reports stay tied to the same engagement context, which reduces repeated setup and makes later review cleaner.
Operating modes
Use the numbered modules directly when you want full control over every action.
Let the assisted workflow reason over findings and choose next steps within the selected mode.
Review collected artifacts and turn them into prioritized paths and report-ready findings.
Connect an external AI client while AdStrike keeps the assessment action layer structured.