Guides
Operating guidance for ADscan — engagement practice, hardening detection, and the two attack techniques that need their own page.
The command reference tells you what each verb does. These pages cover the things a reference cannot: how to run an engagement without creating problems for the client, how ADscan adapts to their existing hardening, and the two techniques whose mechanics and rollback story need explaining before you run them.
Best practices
Pre-engagement authorization and scoping, OPSEC, credential handling, and cleanup.
Hardening detection
How ADscan learns a domain's defensive controls from its first refusal and adapts, instead of retrying blind.
Troubleshooting
Installation, connectivity, authentication and graph-collection failures.
GPO abuse — Immediate Scheduled Task
Plant a SYSTEM-level task via a writable GPO, with SYSVOL and LDAP rollback.
SPNJack — SPN-jacking + constrained delegation
Take over a computer, or a DC, by relocating a delegation SPN onto it. No password crack.
CTF labs
Retired HTB machines, walked end to end with manual and automated timings.
Where to start
Before your first client engagement, read Best practices. It covers the things that are expensive to learn the hard way: getting the authorization in writing, agreeing the scope, which techniques generate telemetry the client's SOC will see, and how to hand back a clean environment.
Learning the attack chains, take a lab walkthrough end to end rather than reading the command reference top to bottom. Forest is the shortest.
Practising against something bigger than a single box, stand up GOAD — a multi-domain forest with real trusts, which is where the trust-walking and cross-domain paths become visible.
Enterprise CTEM
Need continuous AD monitoring rather than point-in-time assessment? ADscan Enterprise is an on-prem CTEM platform with scheduled scans, compliance reporting, and a web dashboard. We run a free live assessment in your environment first.
Improving these pages
Found something wrong or unclear? Open an issue or say so on Discord.