Metadata-Version: 2.4
Name: adpentest
Version: 1.1.1.2
Summary: Active Directory penetration testing framework with automatic Domain Controller detection
Author-email: Netanel Cyber <nsh531@gmail.com>
License: MIT
Project-URL: Homepage, https://github.com/netanelcyber/AdPentestAI-Python
Project-URL: Repository, https://github.com/netanelcyber/AdPentestAI-Python.git
Project-URL: Issues, https://github.com/netanelcyber/AdPentestAI-Python/issues
Project-URL: Documentation, https://github.com/netanelcyber/AdPentestAI-Python/blob/main/README.md
Keywords: active-directory,penetration-testing,ad-enumeration,kerberos,smb,ldap,security,offensive-security,red-team
Classifier: Development Status :: 4 - Beta
Classifier: Environment :: Console
Classifier: Intended Audience :: Information Technology
Classifier: Intended Audience :: System Administrators
Classifier: License :: OSI Approved :: MIT License
Classifier: Natural Language :: English
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Topic :: System :: Networking
Classifier: Topic :: System :: Systems Administration
Classifier: Topic :: Security
Requires-Python: >=3.10
Description-Content-Type: text/markdown
License-File: LICENSE
Requires-Dist: httpx<1,>=0.27
Requires-Dist: dnspython<3,>=2.4
Requires-Dist: ldap3<3,>=2.9
Provides-Extra: dev
Requires-Dist: pytest>=7.0; extra == "dev"
Requires-Dist: black>=23.0; extra == "dev"
Requires-Dist: flake8>=6.0; extra == "dev"
Requires-Dist: mypy>=1.0; extra == "dev"
Dynamic: license-file

# AdPentestAI-Python

[![GitHub stars](https://img.shields.io/github/stars/netanelcyber/AdPentestAI-Python?style=flat)](https://github.com/netanelcyber/AdPentestAI-Python/stargazers)
[![GitHub issues](https://img.shields.io/github/issues/netanelcyber/AdPentestAI-Python)](https://github.com/netanelcyber/AdPentestAI-Python/issues)
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](LICENSE)
[![Python 3.10+](https://img.shields.io/badge/python-3.10+-blue.svg)](https://www.python.org/downloads/)

Active Directory penetration testing framework with **automatic Domain Controller detection**.

## Examples

See [`examples/sample-dry-run-output.json`](examples/sample-dry-run-output.json) for a sample of the JSON output produced by:

```bash
python -m adpentest --target corp.local --mode dry-run --scope-confirmed
```

## Contributing

Contributions are welcome! See [CONTRIBUTING.md](CONTRIBUTING.md) for setup instructions and [CODE_OF_CONDUCT.md](CODE_OF_CONDUCT.md) for community guidelines. Check the [open issues](https://github.com/netanelcyber/AdPentestAI-Python/issues) for tasks labeled `good-first-issue` or `help-wanted`.

## Features

- **Auto DC Detection** — discovers Domain Controllers via DNS SRV records, LDAP RootDSE probes, and port fingerprinting
- **Subnet expansion** — scans /24 first, widens to /23 if no DC found
- **Domain auto-discovery** — extracts domain name from LDAP RootDSE defaultNamingContext
- **DC FQDN resolution** — multi-source FQDN lookup with live LDAP probe fallback, forward DNS verification
- **DC-aware tool execution** — passes discovered domain, DC IP, and FQDN to tools
- **29 AD/SMB/Kerberos/ADCS/Email tools** — 12 cross-platform binaries + 3 Windows-native PowerShell + 3 Kerberos attack + 4 ADCS certificate attacks + 5 Email protocol enumeration
- **SMB pentesting** — null session detection, share enumeration, SMB signing detection, credential testing
- **Windows-native tools** — built-in PowerShell enumeration for LDAP, SMB, and AD forest discovery (no external dependencies on Windows)
- **Cross-platform** — runs on Linux, macOS, and Windows with platform-specific optimizations
- **Auto-install** — missing tools installed automatically via apt/pip/git (or native on Windows)
- **Safety** — `dry-run` is the default; `--scope-confirmed` required for authorization

## DC Detection Strategies

1. **DNS SRV** — queries `_ldap._tcp.dc._msdcs.<domain>`, `_kerberos._tcp.dc._msdcs.<domain>`, etc.
2. **LDAP RootDSE** — anonymous bind to extract domain, forest level, hostname
3. **Port fingerprint** — checks Kerberos (88), LDAP (389/636), Global Catalog (3268/3269)
4. **Subnet sweep** — Kerberos port 88 quick-scan on /24, expands to /23, then /22 if no DCs found

## SMB Pentesting Capabilities

- **Null session detection** — checks if targets allow anonymous SMB access (IPC$)
- **Share enumeration** — discovers available SMB shares via CrackMapExec and smbmap
- **SMB signing detection** — identifies if SMB message signing is enforced (via nmap scripts)
- **Credential testing** — attempts connection with guest/empty credentials via impacket tools
- **Secretsdump** — extracts NTLM hashes and session keys when null credentials work
- **PsExec simulation** — tests command execution capability via impacket psexec

## Kerberos/Kerberoasting Attack Vectors

- **GetUserSPNs** — enumerates service principal names (SPN) via LDAP (custom implementation, no impacket needed)
- **AS-REP Roasting** — targets accounts with DONT_REQUIRE_PREAUTH flag for offline cracking
- **Kerberoasting** — extracts and cracks service account tickets via TGS-REQ requests
- **Requires:** null/guest credentials or valid domain account (LDAP access for SPN enumeration)
- **Output formats:** .txt files compatible with Hashcat/John for cracking
- **Implementation:** Pure Python LDAP-based tools (ldap3, no external binaries)

## ADCS Certificate Attack Vectors

- **Shadow Credentials** — exploits ADCS to inject shadow credentials for account takeover via certificate-based authentication
- **ESC1** — template misconfiguration allowing client authentication without enrollment agent
- **ESC3** — enrollment agent misconfig enabling privilege escalation via certificate requests
- **ESC9** — object control abuse via ADCS certificate manipulation
- **Tools:** Certipy-AD automated enumeration and exploitation
- **Attack chain:** certificate enumeration → template analysis → credential extraction → privilege escalation

## Windows-Native Tools

**PowerShell enumeration (built-in, no external dependencies on Windows):**
- **powershell_ldap_enum** — LDAP RootDSE queries via .NET DirectoryServices
- **powershell_smb_enum** — SMB share enumeration via Get-SmbShare
- **powershell_ad_recon** — Forest/domain/DC discovery via AD API

**Python-based Enumeration Engines:**
- **enum_windows_py** — Pure Python enum4linux-ng replacement (LDAP + SMB + policy enumeration)
  - Null session detection and exploitation
  - Domain policy extraction (password complexity, lockout settings)
  - SMB share discovery via impacket
  - Works on Windows, Linux, macOS
  - Uses ldap3 + impacket (already required dependencies)

- **SPNEnumerator** — Custom LDAP-based Service Principal Name enumeration
  - Direct LDAP queries to extract SPNs without impacket.examples.GetUserSPNs
  - Anonymous LDAP bind capability
  - Hashcat/John compatible output format
  - Pure Python implementation (ldap3 only)

**Cross-platform Tools:**
- 12 binary tools (nmap, masscan, crackmapexec, smbmap, bloodhound, etc.)
- All tools auto-install via apt/pip/git based on platform

## Email Protocol Enumeration & Credential Testing

**Pure Python email enumeration (no external dependencies):**

- **SMTP User Enumeration** — Discover valid email addresses via:
  - SMTP VRFY command (traditional user discovery)
  - SMTP RCPT TO validation (validate recipient addresses)
  - Service banner detection (Exchange/Postfix/Sendmail identification)
  - Ports: 25 (plain), 465 (SMTPS), 587 (SMTP TLS)

- **Credential Testing with Protocol Fallback** — Automatic fallback chain:
  - **Primary:** SMTP AUTH (ports 25, 465, 587)
  - **Fallback:** POP3 AUTH (ports 110, 995)
  - **Fallback:** IMAP AUTH (ports 143, 993)
  - Tests multiple credentials until success or all protocols exhausted
  - Supports TLS/SSL connections for secure ports

- **Email Service Detection** — Identify email infrastructure:
  - Exchange on-premises (2016, 2019, 2021)
  - Office 365 cloud detection (outlook.office365.com routing)
  - Server banner parsing and version detection
  - Concurrent port scanning for email services

- **Implementation:** Pure Python using standard library (smtplib, poplib, imaplib)
  - No external tool dependencies
  - Cross-platform (Windows, Linux, macOS)
  - Works on any Python 3.10+ environment

**Output Format:**
- Valid users discovered via SMTP enumeration
- Working credentials (username, password, protocol, server, port)
- Email service type and version
- Protocol availability (which protocols respond on target)
- Comprehensive failure logging for debugging

## Run

```bash
# Dry-run (check tools, detect DCs, preview commands)
python -m adpentest --target 10.0.0.1 --mode dry-run --scope-confirmed

# Active scan with auto DC detection
python -m adpentest --target corp.local --mode active --scope-confirmed

# With custom timeout, no auto-install
python -m adpentest --target 192.168.1.10 --mode active --scope-confirmed --timeout 600 --no-auto-install

# With custom DNS servers (fallback to public DNS on failure)
python -m adpentest --target 192.168.1.10 --mode active --scope-confirmed --dns-server 1.1.1.1,1.0.0.1

# With custom DNS timeout (in seconds)
python -m adpentest --target 192.168.1.10 --mode active --scope-confirmed --dns-timeout 5.0
```

## DNS Configuration

The framework supports flexible DNS resolver configuration with automatic fallback:

### CLI Arguments
- `--dns-server <servers>` — Comma-separated list of custom DNS servers (e.g., `8.8.8.8,8.8.4.4`)
- `--dns-timeout <seconds>` — DNS query timeout in seconds (default: 3.0)

### Environment Variables
- `DNS_SERVERS` — Comma-separated DNS servers (e.g., `export DNS_SERVERS=8.8.8.8,8.8.4.4`)
- `DNS_TIMEOUT` — DNS query timeout in seconds (e.g., `export DNS_TIMEOUT=5.0`)

### Priority Order
1. **CLI Arguments** (`--dns-server`, `--dns-timeout`) — Highest priority
2. **Environment Variables** (`DNS_SERVERS`, `DNS_TIMEOUT`)
3. **System Default DNS** — Automatically detected from system configuration
4. **Public DNS Fallback** — Automatically uses `8.8.8.8`, `8.8.4.4`, `1.1.1.1`, `1.0.0.1` if others fail

### Examples

```bash
# Use custom DNS servers from CLI
python -m adpentest --target corp.local --mode active --scope-confirmed --dns-server 192.168.1.1,8.8.8.8

# Use environment variables for DNS
export DNS_SERVERS=192.168.1.1,1.1.1.1
export DNS_TIMEOUT=5.0
python -m adpentest --target corp.local --mode active --scope-confirmed

# Combine CLI with custom timeout
python -m adpentest --target corp.local --mode active --scope-confirmed --dns-server 8.8.8.8 --dns-timeout 10.0
```

## Resolver Behavior

- **System DNS** is queried first by default
- **Automatic fallback** to public DNS (Cloudflare, Google) on timeout or resolution failure
- **Detailed logging** shows which resolver is used and why (system, environment, CLI, or fallback)
- **All DNS functions** (SRV records, PTR lookups, forward resolution) use centralized configuration

## Requirements

- Python 3.10+
- `dnspython`, `ldap3`, `httpx`

This project does not authorize testing by itself. Operators must supply an explicitly authorized scope.
