📚 Guides
Comprehensive guides for using ADscan professionally
Welcome to the ADscan guides section. Whether you’re practicing labs or running authorized internal assessments, these pages are designed to help you get reliable results with less setup and less context switching.
Available Guides
CTF Labs & Walkthroughs
Auto-pwn retired HTB machines with step-by-step guides
Best Practices
Professional guidelines for security assessments and pentests
Troubleshooting
Common issues and solutions for ADscan usage
GPO Abuse — Immediate Scheduled Task
Plant SYSTEM-level tasks via writable GPOs, with automatic SYSVOL/LDAP rollback
SPNJack — SPN-Jacking + Constrained Delegation
Deterministically take over a computer (or DC) by relocating a delegation SPN onto it — no password crack
Quick Navigation
For CTF Players
Start with the CTF Labs to see ADscan's full automation in action. These guides show you how to:
- Configure ADscan for HTB/VulnHub labs
- Use automatic mode for fast enumeration
- Let ADscan chain attacks autonomously
- Capture flags in minutes
Recommended workflow:
- 🎯 CTF Labs - Auto-pwn HTB machines
- 🔍 Command Reference - Learn individual commands
- ❓ Troubleshooting - Fix common issues
For Security Professionals
Start with Best Practices for professional usage guidelines:
- Pre-engagement planning and authorization
- Operational security considerations
- Secure credential handling
- Data protection and compliance
- Post-engagement cleanup
Recommended workflow:
- 📚 Best Practices - Professional guidelines
- 🔍 Command Reference - Master all commands
- 🛠️ Scanning Commands - Deep dive into scanning
- ❓ Troubleshooting - Handle edge cases
Having Issues?
Check the Troubleshooting guide for solutions to common problems:
- Installation failures
- Network connectivity issues
- Authentication problems
- BloodHound integration
- Performance optimization
Guide Categories
Practical Walkthroughs
- Complete demonstrations of ADscan's capabilities
- Real attack chains from unauthenticated to Domain Admin
- HTB Forest, Active, and Cicada (auto-pwn in minutes)
- Step-by-step explanations of each attack stage
Professional Usage
- Pre-engagement planning and scope verification
- Workspace organization strategies
- Secure credential management
- Data protection and encryption
- Legal and compliance considerations
- Post-engagement cleanup procedures
Problem Solving
- Installation and dependency issues
- Network and connectivity problems
- Authentication and credential errors
- BloodHound integration troubleshooting
- Performance optimization tips
- Common error messages and fixes
Learning Paths
Beginner Path
- Complete Quick Start
- Follow CTF Labs - Start with HTB Active
- Review Command Reference
- Keep Troubleshooting handy
Intermediate Path
- Master all Commands
- Read Best Practices
- Practice on GOAD lab or similar AD environment
- Experiment with both auto modes
Advanced Path
- Study Best Practices thoroughly
- Master Workspace Management
- Deep dive into Credential Management
- Contribute to community with #adscan tag
Additional Resources
External Labs
Practice ADscan on these Active Directory labs:
- ADscan CTF Labs - Step-by-step walkthroughs for HTB machines
- GOAD - Game of Active Directory lab
- HackTheBox - Retired AD machines
- VulnHub - Free AD vulnerable VMs
- TryHackMe - AD learning paths
Related Documentation
- Command Reference - Complete command documentation
- System Requirements - Platform compatibility
- Installation - Setup instructions
Community Resources
- Discord: discord.com/invite/fXBR3P8H74
- GitHub: github.com/ADscanPro/adscan
- Website: adscanpro.com
Contributing to Guides
Have a suggestion for improving these guides? Found an error or unclear section?
- Open an issue on GitHub
- Join the discussion on Discord
- Share your ADscan success stories with #adscan
Enterprise CTEM
Need continuous AD monitoring for your security team? ADscan Enterprise is an on-prem CTEM platform with scheduled scans, compliance reports, and a web dashboard. We run a free live assessment in your environment so you see it in action before committing.
What's Next?
Choose your path:
- New to ADscan? Start with CTF Labs - Try HTB Active
- Professional assessment? Read Best Practices
- Having issues? Check Troubleshooting
- Want to dive deep? Explore Command Reference