AUTOATTACK
Deploy

Active Directory takeover, start to Domain Admin.

Point AutoAttack at a Windows forest with Domain Admin as the objective, and it returns the path it walked: which misconfigurations chained, which credentials it pulled, and the captured evidence behind every one.

Deploy

proven

every step proved Every hop on the report is an action it carried out, with the captured output behind it.

the Active Directory attack path

  1. crack a way in Where an account allows it, AutoAttack requests a Kerberos ticket and cracks it offline, no password needed to start. Weak and reused credentials fall the same way.
  2. read the directory With one credential it enumerates the domain and finds passwords left in account descriptions, login scripts, and shares (the misconfigurations every directory accumulates over time).
  3. reuse across domains A service-account password pulled from one host unlocks another. Across a trust, the same account is often Domain Admin in the next domain.
  4. replicate everything It replicates the credential database the way a domain controller would, and a forged ticket carrying the trust key crosses domain boundaries, until the forest-root account hands over the rest.

related

See the full benchmark