Metadata-Version: 2.4
Name: vamp-ad-recon
Version: 1.0
Summary: Active Directory security auditor: Kerberoasting, AS-REP Roasting, delegation misconfigurations and privilege escalation paths
Author-email: VampSecure Studios <contact@vampsecurestudios.com>
License: AGPL-3.0-only
Project-URL: Homepage, https://github.com/Vampsecure-Labs/vamp-ad-recon
Project-URL: Repository, https://github.com/Vampsecure-Labs/vamp-ad-recon
Keywords: security,pentest,active-directory,kerberoasting,ldap,windows,vampsecure,red-team
Classifier: Development Status :: 5 - Production/Stable
Classifier: Environment :: Console
Classifier: Intended Audience :: Information Technology
Classifier: License :: OSI Approved :: GNU Affero General Public License v3 or later (AGPLv3+)
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Classifier: Topic :: Security
Requires-Python: >=3.9
Description-Content-Type: text/markdown
Requires-Dist: rich>=13.7.0
Requires-Dist: ldap3>=2.9.0

<!-- © VampSecure Studios — VampSecure Labs Security Research Division -->
<h1 align="center">vamp-ad-recon</h1>

<p align="center">
  <img src="https://img.shields.io/badge/python-3.9%2B-blue?logo=python&logoColor=white" alt="Python 3.9+"/>
  <img src="https://img.shields.io/badge/platform-linux%20%7C%20macOS%20%7C%20windows-lightgrey" alt="Platform"/>
  <img src="https://img.shields.io/badge/license-AGPL--3.0-green" alt="License AGPL-3.0"/>
  <img src="https://img.shields.io/badge/VampSecure-Labs-magenta" alt="VampSecure Labs"/>
</p>

## Overview

`vamp-ad-recon` is an Active Directory / LDAP security auditor for authorized penetration testing engagements against Windows domain environments. It connects via LDAP3 with NTLM authentication — no impacket or native Kerberos dependency required — and executes a multi-phase enumeration covering domain metadata, user account weaknesses, Kerberoasting candidates, AS-REP Roasting candidates, delegation misconfigurations (unconstrained, constrained, RBCD), privileged group membership auditing, GPO permission analysis, and password policy review. Findings are rated CRITICAL to INFO with MITRE ATT&CK mappings and exported to console (Rich), JSON, or HTML.

## Features

- Phase 0: domain rootDSE info (naming context, domain/forest functionality level, NetBIOS name, domain controllers)
- Phase 1: user enumeration — total count, disabled accounts, never-expiring passwords (UAC flag 65536), no-password-required accounts (UAC flag 32)
- Phase 2: Kerberoasting candidates — accounts with SPN configured, RC4 encryption type detection, password age classification (AD-001: CRITICAL if >365 days, HIGH otherwise)
- Phase 3: AS-REP Roasting candidates — accounts with DONT_REQUIRE_PREAUTH set (AD-002: CRITICAL)
- Phase 4: delegation misconfigurations — unconstrained delegation excluding DCs (AD-003: CRITICAL), constrained delegation with delegation targets (AD-004: HIGH), Resource-Based Constrained Delegation (AD-005: HIGH)
- Phase 5: privileged group membership — Domain Admins, Enterprise Admins, Schema Admins, Administrators, Account Operators, Backup Operators, Server Operators, Print Operators; flags excess membership (AD-006: MEDIUM) and service accounts in Domain Admins (AD-007: HIGH)
- Phase 6: GPO permission analysis — enumeration of all Group Policy Objects with SYSVOL paths and security descriptor review (AD-008: HIGH for writable GPOs)
- Phase 7: password policy — minimum length (AD-009: MEDIUM if <12), lockout threshold (AD-010: HIGH if disabled), maximum password age (AD-011: MEDIUM if no expiration)
- NTLM authentication via ldap3 with optional SSL (port 636)
- Anonymous null-session bind attempt with `--null-session`
- MITRE ATT&CK technique references per finding (T1558, T1558.004, T1134.001, etc.)
- Selective module execution via individual flags or `--all`
- Export to Console (Rich panels per phase), JSON, and HTML (dark-theme)

## Requirements

- Python 3.9 or later
- `rich >= 13.7.0`
- `ldap3 >= 2.9.0`
- Network connectivity to the target Domain Controller (port 389 or 636)
- Optional: `fpdf2 >= 2.7` for `--report-pdf`

## Installation

```bash
pip install vamp-ad-recon
# or with Homebrew:
brew install vampsecure-labs/labs/vamp-ad-recon
```

```bash
git clone https://github.com/Vampsecure-Labs/vamp-ad-recon.git
cd vamp-ad-recon
python3 -m venv .venv
source .venv/bin/activate   # Windows: .venv\Scripts\activate
pip install -r requirements.txt
```

## Usage

```
vamp-ad-recon --help
```

```
usage: vamp-ad-recon enum --dc <IP_OR_HOST> --domain <FQDN>
                          --user <USERNAME> --password <PASSWORD>
                          [--dc-port 389|636] [--ssl]
                          [--null-session]
                          [--kerberoast] [--asrep] [--delegation]
                          [--gpo] [--all]
                          [--json FILE] [--html FILE]
                          [--client CLIENT] [--engagement ENGAGEMENT]
                          [--auditor AUDITOR] [--report-scope SCOPE]
                          [--report-html FILE] [--report-pdf FILE]
```

## Examples

```bash
# Basic domain enumeration with NTLM authentication
vamp-ad-recon enum --dc 192.168.1.10 --domain corp.example.com \
    --user svc_audit --password 'P@ssw0rd!'

# Full enumeration with all attack-path checks
vamp-ad-recon enum --dc dc01.corp.example.com --domain corp.example.com \
    --user pentest --password 'Secret123' --all

# Kerberoasting and AS-REP Roasting checks only
vamp-ad-recon enum --dc 10.0.0.5 --domain internal.lab \
    --user auditor --password 'Lab!Pass' --kerberoast --asrep

# Anonymous null-session enumeration attempt
vamp-ad-recon enum --dc 10.0.0.5 --domain internal.lab --null-session

# SSL connection on port 636
vamp-ad-recon enum --dc ldaps.corp.com --domain corp.com \
    --user reader --password 'Pwd!' --ssl

# Export findings to JSON and dark-theme HTML
vamp-ad-recon enum --dc 192.168.1.10 --domain corp.example.com \
    --user svc_audit --password 'P@ssw0rd!' --all \
    --json findings.json --html report.html

# Generate client-ready engagement report
vamp-ad-recon enum --dc 192.168.1.10 --domain corp.example.com \
    --user svc_audit --password 'P@ssw0rd!' --all \
    --client "Acme Corp" --engagement "AD Security Review Q4 2026" \
    --auditor "J. Smith" --report-html client_report.html --report-pdf client_report.pdf
```

## CLI Reference

| Flag | Default | Description |
|------|---------|-------------|
| `--dc HOST` | required | IP address or hostname of the Domain Controller |
| `--domain FQDN` | required | Fully qualified domain name (e.g. corp.example.com) |
| `--user USERNAME` | required | Username for NTLM authentication |
| `--password PASS` | required | Password for NTLM authentication |
| `--dc-port PORT` | `389` | LDAP port (389 plain, 636 SSL) |
| `--ssl` | off | Use SSL/TLS (LDAPS) — sets port to 636 if not specified |
| `--null-session` | off | Attempt anonymous LDAP bind first |
| `--kerberoast` | off | Include Kerberoasting candidate check |
| `--asrep` | off | Include AS-REP Roasting candidate check |
| `--delegation` | off | Include delegation misconfiguration checks |
| `--gpo` | off | Include GPO permission analysis |
| `--all` | off | Run all optional modules |
| `--json FILE` | — | Export results to JSON |
| `--html FILE` | — | Export dark-theme HTML report |
| `--client TEXT` | — | Client name for VSL engagement report |
| `--engagement TEXT` | — | Engagement title for VSL engagement report |
| `--auditor TEXT` | — | Auditor name for VSL engagement report |
| `--report-scope TEXT` | — | Scope description for VSL engagement report |
| `--report-html FILE` | — | Export unified VSL client report (HTML) |
| `--report-pdf FILE` | — | Export unified VSL client report (PDF, requires fpdf2) |

## Findings Reference

| ID | Severity | Category | MITRE ATT&CK |
|----|----------|----------|--------------|
| AD-001 | CRITICAL/HIGH | Kerberoasting | T1558.003 |
| AD-002 | CRITICAL | AS-REP Roasting | T1558.004 |
| AD-003 | CRITICAL | Unconstrained Delegation | T1134.001 |
| AD-004 | HIGH | Constrained Delegation | T1134.001 |
| AD-005 | HIGH | RBCD | T1134.001 |
| AD-006 | MEDIUM | Privileged Group Excess | T1078.002 |
| AD-007 | HIGH | Service Account in Domain Admins | T1078.002 |
| AD-008 | HIGH | GPO Write Permission | T1484.001 |
| AD-009 | MEDIUM | Weak Password Policy (length) | T1110 |
| AD-010 | HIGH | No Account Lockout Policy | T1110.001 |
| AD-011 | MEDIUM | No Password Expiration Policy | T1078 |

## Output Formats

| Format | Flag | Description |
|--------|------|-------------|
| Console | (default) | Rich panels per phase with color-coded findings by severity |
| JSON | `--json FILE` | Machine-readable full result set |
| HTML | `--html FILE` | Dark-theme standalone report |
| Client HTML | `--report-html FILE` | Unified VampSecure Labs engagement report |
| Client PDF | `--report-pdf FILE` | PDF version of the VSL client report |

## Exit Codes

| Code | Meaning | CI/CD Behavior |
|------|---------|----------------|
| `0` | No critical or high findings | Pipeline passes |
| `1` | High or critical findings detected | Pipeline fails — review required |
| `2` | Connection or authentication error | Pipeline fails — check credentials/connectivity |

## Legal Notice

Use exclusively on systems you own or for which you hold explicit written authorization from the system owner. VampSecure Studios assumes no liability for unauthorized use.

## Part of VampSecure Labs Toolkit

`vamp-ad-recon` is one tool in the VampSecure Labs security research toolkit. For the full toolkit including the orchestrator that runs all tools in sequence and aggregates findings into a single engagement report, see:

- Portfolio: [github.com/Vampsecure-Labs](https://github.com/Vampsecure-Labs)
- Orchestrator: [github.com/Vampsecure-Labs/vamp-orchestrator](https://github.com/Vampsecure-Labs/vamp-orchestrator)

---

© VampSecure Studios — VampSecure Labs Security Research Division

## Versión
v1.0 — VampSecure Labs Security Research Division
