National Cyber Warfare Foundation (NCWF)login

Inside ad_attack_architecture: mapping the Active Directory attack path from recon to domain dominance


0 user ratings
2026-10-10 13:28:54
milo
Red Team (CNA)
"Inside

ad_attack_architecture is a visual reference map of Active Directory attack paths, documenting the reconnaissance-to-domain-dominance methodology for authorized pentesters and defenders.








Toolkypvas/ad_attack_architecture — a comprehensive visual map of Active Directory attack architecture for pentest reference
CategorySecurity methodology reference / HTML knowledge map
Primary UseStudy and planning aid for authorized Active Directory assessments, tracing paths from initial recon through privilege escalation to domain dominance
Safe UseIntended as an educational reference for professionals conducting authorized penetration tests, lab exercises, and internal security reviews of environments they own or are contracted to assess
Telemetry NotePurely a documentation artifact — it executes nothing, contacts nothing, and leaves no footprint; defenders benefit from it as a checklist of attacker paths to monitor

Not every valuable repository on the security landscape is a binary you compile or a Python package you install. kypvas/ad_attack_architecture belongs to a smaller but arguably more durable category: the curated knowledge map. Hosted on GitHub and written in HTML, it bills itself as a comprehensive pentest reference for Active Directory attack architecture, charting the territory from initial reconnaissance all the way to what the author bluntly calls domain dominance. For an English-speaking audience it is worth noting up front that the project's descriptive text is written in Portuguese (Mapa Abrangente de Referência de Pentest), which shapes who gets immediate value from it and how teams might adopt it internally.


What the project actually delivers is a structured, navigable map of the Active Directory attack lifecycle. Anyone who has worked an authorized internal assessment knows the problem this addresses: AD attack knowledge is scattered across dozens of tools, blog posts, MITRE ATT&CK technique descriptions, and private notes. A consolidated architecture map collapses that sprawl into a single reference you can consult mid-engagement, when you are standing at a fork — say, after collecting a set of credentials — and need to recall which lateral movement or privilege escalation avenues logically open up next.


The framing From Recon to Domain Dominance tells you the organizing principle is the kill chain itself. That matters because it reflects how real intrusions in directory environments tend to unfold: an attacker rarely goes straight to Domain Admin. Instead they chain smaller wins — enumeration that reveals misconfigurations, credential access that yields a foothold, delegation abuse or ACL misconfigurations that escalate, Kerberos ticket manipulation that extends access — until the domain itself is effectively owned. A map that mirrors that chaining logic is more useful operationally than a flat tool list, because it encodes the dependencies between stages.


Because the repository is HTML-based, it behaves more like an interactive document than a program. There is no runtime, no dependency chain, no pip install or compilation step; you consume it the way you would consume a well-organized wiki or an interactive mind map. That makes it trivially safe to pull into an assessment VM or a team wiki. The standard retrieval is nothing more exotic than a git clone https://github.com/kypvas/ad_attack_architecture, after which the content is entirely local and offline-friendly — a practical consideration for engagements run on isolated lab networks where egress is restricted.


The repo metadata gives a modest but honest picture: 36 stars, no declared license, no topic tags, and a default branch of main. This is a personal-knowledge-artifact-turned-public project rather than a maintained product, and readers should calibrate expectations accordingly. There is no versioned release cadence, no issue tracker bustling with contributions, and no license granting formal reuse rights. If you plan to fork it into internal training material for your own authorized engagements, the absence of a license is worth a moment of consideration — the safest interpretation is to treat it as reference material to read and learn from rather than something to redistribute wholesale.


The README for the project is thin in this snapshot, which means an honest analysis has to lean on what the project declares itself to be rather than an itemized feature list. That constraint is actually revealing: the value proposition is entirely in the map's coverage and organization, not in code. When evaluating resources like this, senior operators tend to ask three questions — does the enumeration section cover modern techniques, does the privilege escalation section reflect post-2020 AD attack research, and does the map distinguish between techniques that require prior privileges and those that work from a low-privileged foothold? Those questions apply directly here, and the answers will determine how current the reference remains.


For red teamers and pentesters working under proper authorization, a map of this kind serves several concrete roles. It functions as a pre-engagement planner when scoping which AD attack surfaces fall inside the rules of engagement. It works as an in-engagement memory aid, particularly during the messy middle phase of an assessment where you have partial access and many candidate paths forward. And it operates as a reporting aid — mapping observed findings back to a recognized attack architecture makes it easier to explain to clients why a chain of individually medium-severity issues compounds into a domain-compromise narrative.


The defensive audience deserves equal billing. Blue teams and threat hunters get as much out of a well-built attack map as attackers do, because every arrow on the graph between recon and domain dominance is also a detection opportunity. Each stage — directory enumeration patterns, abnormal Kerberos ticket requests, unusual LDAP query volume, sudden changes to ACLs or group memberships — corresponds to a telemetry surface in tools like Microsoft Defender for Identity or a SIEM correlation rule. Reading the map backwards, from dominance to initial access, is effectively a prioritization exercise for detection engineering: cover the choke points where every path must pass.


There are caveats a professional reader should hold onto. Reference maps age quickly in the AD space, and one constructed as static HTML will not automatically track newly published techniques; verify anything you plan to rely on against current sources such as the ATT&CK framework and primary research. The Portuguese-language descriptions mean non-Lusophone teams will either skim the visual structure or invest in translation. And the absence of a license and test data means this is a reading resource, not something you can safely embed in automated pipelines without review.


Taken on its own terms, ad_attack_architecture is a commendable example of practitioners externalizing hard-won mental models into shareable form. It will not replace BloodHound-class tooling or hands-on lab practice, and it does not try to. What it offers is orientation — a single, kill-chain-ordered view of how Active Directory compromises actually compose — and that is a resource both authorized attackers and the defenders hunting them can put to immediate, legitimate use.



Official project repository for kypvas/ad_attack_architecture.

Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.






Source: OffensiveSec
Source Link: https://www.offsecblog.com/2026/10/inside-adattackarchitecture-mapping.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.