Selected route / illustrativePossible is not yet proven.
Illustrative route: svc-build, workstation-07, delegation, Tier-0. Scroll to explore the graph, then follow Collect, Graph, Validate, and Report. This is a presentation, not a live assessment.
01 / The evidence observatory
Inside the evidence.
One fictional route. Follow its relationships, inspect what is known, and carry the same context into a report.
AD//HAMMER / ROUTE 01Fictional data · browser-only
DIRECTORY MODEL 01 / 04
Observation ≠ proofNo connection to a real domain. No commands are executed.
02 / Context, preserved
A record. Not a guess.
The same selected object and evidence state, carried forward. Change the model above and this illustrative record changes with it.
ADhammer release graph: version 1.5.0 is an earlier release, version 1.5.1 is the previous release, and version 1.5.2 is available on GitHub and crates.io as checked on September 20, 2026.
03 / Release signal
More control.Clearer handoffs.
Version 1.5.2 refines the work around an assessment: quieter scripting, versioned report data, print-ready HTML, and build provenance. The changelog also records correctness fixes and dependency hardening.
Report handoffPrint styling for HTML and a JSON schema_version field for downstream consumers.
Build provenance--version includes version, commit, and build date when available; -V stays short.
One record / multiple formats / illustrative
Truth boundary
These are documented release changes, not a new live-validation claim. The validation ledger remains authoritative; partial and unvalidated paths retain their stated limits.
v1.5.2 / GitHub September 19 · crates.io September 20
Windows, Linux, and macOS assets are listed on GitHub with SHA-256 sidecars. The v1.5.2 CLI is also available on crates.io, verified unyanked on September 20, 2026. Choose a prebuilt download or install the pinned registry version below.
Historical ADhammer 1.3.3 measurements, with tool versions, transport differences, and raw logs. These results do not establish current-release performance.
Recorded wall-clockADhammer 1.3.3 matrix
54 ms · recorded ADhammer time
Zerologon safe-detect
CVE-2020-1472 · compared with NetExec
ADhammer54 ms
NetExec7,779 ms
Process spawn to exit on the published Windows Server 2025 testbed. Python tools ran through the documented WSL/SOCKS path; that caveat and the pending current-release refresh are part of the record.
Inspect all 12 recorded scenariosversions · method · exact milliseconds
Scenario
ADhammer
Comparison
Result
Recorded against an earlier release; a refresh against the current release is pending.
04 / AD CS field guide
Understand the condition. Know what to check.
Explore ESC1–ESC16 through configuration, evidence, and defensive checks. Select a class for its explanation and an ADhammer example where a focused check is verified.
AD CS / FIELD GUIDEESC1Templates
Scroll over the circle · swipe sideways · or select a class
01 / 16
Who defines the identity?
Inspect the condition, then review the evidence and check below.
v1.5.2 source-checked syntax · documentation placeholders, not ready-to-run targets. Replace hosts, account, and CA name only within your approved scope. Protect the password file. These examples contact real services when run; this page never executes commands or accepts credentials.
Before you run it
Approved LDAP collection scope, a trusted LDAPS certificate, and appropriate directory-read permissions.
What ADhammer does
Collects directory data, extracts certificate templates, and emits template-analysis findings as JSON.
Read the result
Review the affected template and its configuration evidence, then confirm permissions and approval controls separately.
Defensive follow-up
Constrain requester-controlled identity fields and restrict enrollment.
Coverage limits
No complete ACL walk, CA registry audit, or active enrollment. Empty output does not establish a secure environment.
Configuration signals ≠ proven exploitation. Missing reads, incomplete scope, and patch differences can change the interpretation. ESC1–ESC16 is this guide’s scope, not an exhaustive taxonomy or a support score. Examples were not executed against a live domain for this site.
05 / CLI methods
From command to context.
Choose the question first. See what the command reads, what it returns, and what it cannot prove.
Read the film transcript
Collect: An authorized LDAPS read gathers directory data, including certificate templates.
Inspect: Template rules evaluate the collected configuration. The animation uses a fictional template.
Retain context: JSON findings preserve the rule, affected object, explanation, and remediation. This film shows conceptual fields, not captured tool output.
Review: Confirm permissions, CA settings, patches, and scope separately. A configuration signal is not proof of exploitation; empty findings do not establish safety.
Preflight the connection
JSON checklist
Separate connectivity problems from assessment results before collecting directory data.
EXAMPLE / replace placeholders
adhammer doctor --domain example.test --dc dc.example.test --timeout 3 --json
Before you run
Authorization for DNS and TCP probes to the specified DC. No credentials are supplied in this example.
What happens
Uses the DC for DNS SRV discovery and probes AD TCP ports. It does not attempt a credentialed LDAP bind.
Read the result
Inspect checks, ran, failed, and verdict. Skipped checks are not successful checks; inconclusive is not ready.
Boundary
Reachable ports do not establish LDAP authentication, secure configuration, or assessment coverage.
Add --quiet --no-color to suppress decorative progress and request plain output. Warnings and errors remain; CLICOLOR_FORCE=1 can still override the color setting.
The global --fast flag opts into native-speed mode. Its environment equivalent is ADHAMMER_FAST=1. It reduces selected delays and timeouts—not every command’s runtime.
NATIVE SPEED FLAG
adhammer --fast <command>
Where it applies
Selected WMI output-readback delays and enum net --deep service-probe timeouts. The basic network sweep retains its fixed timeouts in v1.5.2.
Trade-off
Shorter timeouts can miss slow responses. This is not a blanket speed boost for doctor or template checks. Target-protection controls, such as lockout safeguards, remain unchanged.
Inspect the network command’s options without running a scan: adhammer --fast enum net --help. The syntax above is a pattern, not a ready-to-run command. Read the speed-mode implementation ↗
These examples were checked against v1.5.2 source, not executed against a live domain. Run only within written authorization. Replace example.test placeholders; protect password files and collected output. The website never executes commands. Check the validation ledger ↗
Reference / engineeringExplore the Rust foundationsThe standalone crates ADhammer composes into one engine+
Reference / Rust ecosystem
Under the surface.
ADhammer composes published standalone icedracon crates into one Rust engine. Each layer remains independently inspectable and reusable outside the binary.
Layer / DirectoryLDAP + security descriptors
Directory objects, ACLs, ACEs, and security descriptor parsing.