Skip to content
ADscan Docs
ADscan PRO

ADscan PRO

Automated Active Directory pentest with MITRE-mapped compliance reports. Docker-based and self-hosted — scan data and client artifacts stay on your machine.

PRO access · beta partner

The Docker image is served from GitHub Container Registry: we grant your GitHub account read access, and your partner tag arrived in your onboarding email. Anything blocking, reach us on Discord or at [email protected] — same-day response.

ADscan PRO extends the free CLI with a professional report engine. Run the same AD pentest you already know — get a client-ready PDF and structured JSON out the other side.

What PRO adds

FeatureLITE (free)PRO
AD enumeration and exploitationYesYes
Attack path generationYesYes
Raw JSON exportYesYes
Exposure report (HTML + PDF)YesYes
Client Deliverable Kit — three PDFs plus the ATT&CK Navigator bundleYes
Compliance mapping (ENS, NIS2, ISO 27001, DORA, PCI DSS)Yes
Per-finding remediation roadmapYes
Attack-path diagramsYes
Premium report themesYes
--display-name for client brandingYes
Re-render deliverables from an existing workspaceYes

Quick start

Supported compliance frameworks

KeyFrameworkPrimary use case
iso27001ISO/IEC 27001:2022Certification audits, MSSP quarterly compliance
ensENS Alto (CCN-CERT)Spanish public sector
nis2NIS2 — EU Directive 2022/2555EU critical-infrastructure operators
doraDORA EU 2022/2554EU financial entities
pci_dssPCI DSS v4.0.1Card-handling environments

Combine them in one report: --frameworks iso27001,dora.

No framework is selected by default. Name the regimes the client needs, or the Control Coverage Report renders with no compliance mapping.

How it fits your workflow

ADscan PRO is designed for pentesters and MSSPs running compliance engagements.

The typical flow (interactive — recommended):

1. adscan start — interactive REPL, the same flow you know from LITE
2. Walk each phase: recon → kerberos → ACL → attack-path collection → exploitation
3. deliver --display-name "Client Name" — packages the kit in about 90 seconds
4. PDFs → hand to the client, or attach to your engagement report
5. JSON → ingest into your own reporting pipeline

For batched or scheduled runs, adscan ci runs the same pipeline unattended.

The JSON output is structured and stable — designed to be parsed, not just read.

What does leave the machine

Scan output, credentials and the deliverables stay local. The Community and PRO command-line tools do upload pseudonymized usage telemetry and session recordings by default; the telemetry page states exactly what that contains and how to switch it off. The Enterprise appliance is the opposite — air-gapped, sending nothing.

Support

Find this useful?
Pass it to the next pentester running an AD engagement
Running 2+ AD engagements/year?
Get PRO free — beta access·Free in exchange for feedback
Automated PDF reports. Save ≥1 day per engagement.

ADscan — AD pentest automation for security consultants

ADscan PRO | ADscan