Skip to content
ADscan Docs

ADscan Documentation

Active Directory exposure management — from assessment to client deliverable in one command.

ADscan

Active Directory exposure management for pentesters, MSSPs, and CISOs.

One command runs the assessment. Another delivers four client-ready PDFs. No tool-hopping.

Current version: 9.1.1 LITE

Three tiers

TierWhat it isWho uses it
LITEFree CLI engine — community-maintained scan corePentesters, red teamers, students
PROLITE + Client Deliverable Kit (4 PDFs + ZIP)MSSPs, consultancies billing engagements
EnterpriseContinuous CTEM/BAS web service with weekly digestCISOs operating their own AD posture

Compare tiers

Three paths to start

What ADscan does

  • Active Directory enumeration — DNS, LDAP, SMB, Kerberos, ADCS, trust spidering, native graph collection.
  • Attack execution — Kerberoasting, AS-REP roasting, ACL abuse, GPP, GPO abuse, constrained-delegation SPN-jacking (SPNJack), DCSync, ADCS ESC1-16.
  • Client Deliverable Kit (PRO) — Executive Assessment Report, AD Hardening Playbook, MITRE Remediation Checklist, Coverage Matrix — generated in 90 seconds with adscan deliver.

Reference

Community & support

Find this useful?
Pass it to the next pentester running an AD engagement
Running 2+ AD engagements/year?
Get PRO free — beta access·Free in exchange for feedback
Automated PDF reports. Save ≥1 day per engagement.

ADscan — AD pentest automation for security consultants

ADscan Documentation | ADscan