Skip to content
ADscan Docs

Guides

Operating guidance for ADscan — engagement practice, hardening detection, and the two attack techniques that need their own page.

The command reference tells you what each verb does. These pages cover the things a reference cannot: how to run an engagement without creating problems for the client, how ADscan adapts to their existing hardening, and the two techniques whose mechanics and rollback story need explaining before you run them.

Where to start

Before your first client engagement, read Best practices. It covers the things that are expensive to learn the hard way: getting the authorization in writing, agreeing the scope, which techniques generate telemetry the client's SOC will see, and how to hand back a clean environment.

Learning the attack chains, take a lab walkthrough end to end rather than reading the command reference top to bottom. Forest is the shortest.

Practising against something bigger than a single box, stand up GOAD — a multi-domain forest with real trusts, which is where the trust-walking and cross-domain paths become visible.

Enterprise CTEM

Need continuous AD monitoring rather than point-in-time assessment? ADscan Enterprise is an on-prem CTEM platform with scheduled scans, compliance reporting, and a web dashboard. We run a free live assessment in your environment first.

Request a free Enterprise assessment

Improving these pages

Found something wrong or unclear? Open an issue or say so on Discord.

Find this useful?
Pass it to the next pentester running an AD engagement
Running 2+ AD engagements/year?
Get PRO free — beta access·Free in exchange for feedback
Automated PDF reports. Save ≥1 day per engagement.

ADscan — AD pentest automation for security consultants

Guides | ADscan