MCP

AdStrike as an AI-ready assessment toolbox.

Connect AdStrike to MCP-capable clients so the assistant can call structured actions while the framework keeps engagement context and evidence organized.

Setup

Register AdStrike with your MCP client.

Use the Python environment from your local AdStrike installation. The AI client handles model access; AdStrike handles the assessment action layer.

claude mcp add adstrike -- /path/to/AdStrike/venv/bin/python3 /path/to/AdStrike/mcp_server.py

AI client driven

The MCP host supplies the model and reasoning. AdStrike supplies the assessment actions, state handling, and output workflow.

One engagement context

Configure the target and authentication context once, then reuse it across discovery, identity analysis, Kerberos, execution, planning, and reporting actions.

Structured coverage

The MCP path exposes 53 structured actions covering the same operational surface as the standalone AI operator.

Controlled workflow

Use the integration for authorized testing workflows where the operator wants AI assistance without rewriting commands by hand.

Flow

How the MCP workflow should feel.

The integration is meant to keep the AI client focused on decisions while AdStrike handles the assessment actions, context reuse, and evidence structure.

01

Register the local tool

Point your MCP client at the AdStrike Python environment so the client can discover available actions.

02

Set assessment context

Provide the domain controller, domain, identity, and authentication mode once at the beginning of the session.

03

Run structured actions

Use discovery, LDAP, BloodHound, Kerberos, ADCS, WinRM, planning, and reporting actions without asking the model to invent command syntax.

04

Review evidence

Keep findings, command history, and generated reports tied to the same engagement workflow.

Coverage

Action groups exposed through the AI client.

Discovery

Nmap, no-credential checks, LDAP, SMB shares, WinRM discovery, MSSQL hints, and BloodHound collection.

Identity abuse

ACL review, Shadow Credentials, RBCD, ADCS, gMSA, trusts, RODC, LAPS, delegation, and certificate paths.

Credential and Kerberos

Roasting, ticket requests, ccache-aware access, PassTheCert, UnPAC, DCSync, shadow copies, and credential validation.

Reporting and planning

Attack-chain planning, Smart Analyst output, HTML/Markdown/JSON reports, and structured findings.