Features

AdStrike capabilities for AD assessments.

The framework combines operator-driven modules, AI assistance, MCP access, evidence handling, and reporting in a single terminal workflow.

AI Operator

Run an assisted assessment flow with local Ollama models or Claude. The operator can work in full-auto mode or generate a plan first, with OPSEC behavior selected for the engagement style.

MCP Integration

Connect AdStrike to MCP-capable clients so the AI client supplies reasoning while AdStrike provides structured, session-aware security actions.

Discovery

Map hosts, ports, domain services, LDAP reachability, SMB shares, WinRM access, ADCS exposure, MSSQL hints, and no-credential entry points.

Identity Paths

Review users, groups, computers, ACLs, GPOs, delegation, gMSA, RBCD, Shadow Credentials, ADCS, RODC, trusts, LAPS, and BloodHound data.

Kerberos Workflows

Handle AS-REP roasting, Kerberoasting, ticket requests, ccache-driven access, PKINIT, PassTheCert, UnPAC, and NTLM-disabled environments.

Execution Paths

Use WinRM, PSExec, WMIExec, MSSQL command execution, credential testing, post-shell collection, DCSync, and shadow-copy workflows during authorized assessments.

Smart Analyst

Parse collected artifacts, session findings, BloodHound data, LDAP output, hashes, and logs, then turn them into prioritized next steps.

Reporting

Generate HTML, Markdown, and JSON reports, plus live round-by-round agent notes with commands, sanitized results, findings, summaries, and attack-chain plans.

Workflow

Built around repeatable AD assessment flow.

AdStrike is strongest when the operator needs a consistent path from initial discovery to evidence-backed action. The site content stays broad, but the workflow maps to the actual coverage: discovery, identity analysis, execution, credential access, persistence, and reporting.

01

Start from the domain edge

Use discovery and no-credential checks to understand reachable services before committing to an identity path. This keeps early work grounded in what the environment actually exposes.

02

Move into identity evidence

Combine LDAP, BloodHound, ACL, GPO, delegation, ADCS, and Kerberos signals so the next step is selected from evidence instead of guesswork.

03

Preserve operational context

Credentials, tickets, command history, findings, and reports stay tied to the same engagement context, which reduces repeated setup and makes later review cleaner.

Operating modes

Different ways to use the same assessment surface.

Manual console

Use the numbered modules directly when you want full control over every action.

AI operator

Let the assisted workflow reason over findings and choose next steps within the selected mode.

Smart Analyst

Review collected artifacts and turn them into prioritized paths and report-ready findings.

MCP workflow

Connect an external AI client while AdStrike keeps the assessment action layer structured.