Skip to content
ADscan Docs

📚 Guides

Comprehensive guides for using ADscan professionally

Welcome to the ADscan guides section. Whether you’re practicing labs or running authorized internal assessments, these pages are designed to help you get reliable results with less setup and less context switching.

Available Guides

Quick Navigation

For CTF Players

Start with the CTF Labs to see ADscan's full automation in action. These guides show you how to:

  • Configure ADscan for HTB/VulnHub labs
  • Use automatic mode for fast enumeration
  • Let ADscan chain attacks autonomously
  • Capture flags in minutes

Recommended workflow:

  1. 🎯 CTF Labs - Auto-pwn HTB machines
  2. 🔍 Command Reference - Learn individual commands
  3. Troubleshooting - Fix common issues

For Security Professionals

Start with Best Practices for professional usage guidelines:

  • Pre-engagement planning and authorization
  • Operational security considerations
  • Secure credential handling
  • Data protection and compliance
  • Post-engagement cleanup

Recommended workflow:

  1. 📚 Best Practices - Professional guidelines
  2. 🔍 Command Reference - Master all commands
  3. 🛠️ Scanning Commands - Deep dive into scanning
  4. Troubleshooting - Handle edge cases

Having Issues?

Check the Troubleshooting guide for solutions to common problems:

  • Installation failures
  • Network connectivity issues
  • Authentication problems
  • BloodHound integration
  • Performance optimization

Guide Categories

Practical Walkthroughs

CTF Labs & Walkthroughs

  • Complete demonstrations of ADscan's capabilities
  • Real attack chains from unauthenticated to Domain Admin
  • HTB Forest, Active, and Cicada (auto-pwn in minutes)
  • Step-by-step explanations of each attack stage

Professional Usage

Best Practices

  • Pre-engagement planning and scope verification
  • Workspace organization strategies
  • Secure credential management
  • Data protection and encryption
  • Legal and compliance considerations
  • Post-engagement cleanup procedures

Problem Solving

Troubleshooting

  • Installation and dependency issues
  • Network and connectivity problems
  • Authentication and credential errors
  • BloodHound integration troubleshooting
  • Performance optimization tips
  • Common error messages and fixes

Learning Paths

Beginner Path

  1. Complete Quick Start
  2. Follow CTF Labs - Start with HTB Active
  3. Review Command Reference
  4. Keep Troubleshooting handy

Intermediate Path

  1. Master all Commands
  2. Read Best Practices
  3. Practice on GOAD lab or similar AD environment
  4. Experiment with both auto modes

Advanced Path

  1. Study Best Practices thoroughly
  2. Master Workspace Management
  3. Deep dive into Credential Management
  4. Contribute to community with #adscan tag

Additional Resources

External Labs

Practice ADscan on these Active Directory labs:

Community Resources

Contributing to Guides

Have a suggestion for improving these guides? Found an error or unclear section?

  1. Open an issue on GitHub
  2. Join the discussion on Discord
  3. Share your ADscan success stories with #adscan

Enterprise CTEM

Need continuous AD monitoring for your security team? ADscan Enterprise is an on-prem CTEM platform with scheduled scans, compliance reports, and a web dashboard. We run a free live assessment in your environment so you see it in action before committing.

👉 Request free Enterprise assessment

What's Next?

Choose your path:

Find this useful?
Pass it to the next pentester running an AD engagement
Running 2+ AD engagements/year?
Get PRO free — beta access·Free in exchange for feedback
Automated PDF reports. Save ≥1 day per engagement.

ADscan — AD pentest automation for security consultants

📚 Guides | ADscan