ADhammer · directory graph illustration
Illustrative scene · no live assessment data

Active Directory · Open source · v1.5.2

AD//HAMMER

Follow the relationship.
Keep the evidence.

Illustrative route: svc-build, workstation-07, delegation, Tier-0. Scroll to explore the graph, then follow Collect, Graph, Validate, and Report. This is a presentation, not a live assessment.

01 / The evidence observatory

Inside the
evidence.

One fictional route. Follow its relationships, inspect what is known, and carry the same context into a report.

AD//HAMMER / ROUTE 01Fictional data · browser-only
DIRECTORY MODEL 01 / 04
Observation ≠ proofNo connection to a real domain. No commands are executed.
02 / Context, preserved

A record.
Not a guess.

The same selected object and evidence state, carried forward. Change the model above and this illustrative record changes with it.

Return to the Observatory ↑
AD//HAMMERILLUSTRATIVE RECORD / 001
01 / Identity

svc-build

Observed / untested
Route
svc-build → workstation-07 → delegation → tier-0
Connection
Intact in the fictional model
Evidence
None attached
Interpretation
An observed object is not proof of access.
DEMO DATA

This is a presentation model, not captured output, a validation receipt, or an exact export schema.

Illustrative flow: directory observations become a relationship graph, then a review record marked possible and untested. AD//HAMMER / RELATIONSHIPSILLUSTRATIVE FLOW01 DIRECTORY02 GRAPH03 REVIEWusersvc-buildhostworkstation-07groupdelegationtier-0boundary01svc-build02workstation-0703delegation04tier-0RECORD 001 · svc-buildroutecontextevidencePOSSIBLE / UNTESTEDContext travels with the finding. Motion is not evidence of a live assessment.
Directory → graph → review / illustrative flow
Actual capability support is separate.

Consult the public ledger for evidence, tested environments, and outstanding validation.

Read the validation ledger ↗
The release registerPublished versions / source linked
ADhammer release graph: version 1.5.0 is an earlier release, version 1.5.1 is the previous release, and version 1.5.2 is available on GitHub and crates.io as checked on September 20, 2026.
03 / Release signal

More control.Clearer handoffs.

Version 1.5.2 refines the work around an assessment: quieter scripting, versioned report data, print-ready HTML, and build provenance. The changelog also records correctness fixes and dependency hardening.

Scripting controls--quiet suppresses decorative progress; --no-color supports plain output. Warnings and errors remain.
Report handoffPrint styling for HTML and a JSON schema_version field for downstream consumers.
Build provenance--version includes version, commit, and build date when available; -V stays short.
Illustrative flow: one assessment record is handed off as JSON, HTML, and Markdown. AD//HAMMER / REPORT HANDOFFILLUSTRATIVE FLOWOne recordschema_version · provenanceJSON{ "status": "possible" }HTMLMARKDOWN# svc-build- route · contextContext travels with the finding. Motion is not evidence of a live assessment.
One record / multiple formats / illustrative
Truth boundary

These are documented release changes, not a new live-validation claim. The validation ledger remains authoritative; partial and unvalidated paths retain their stated limits.

v1.5.2 / GitHub September 19 · crates.io September 20

Windows, Linux, and macOS assets are listed on GitHub with SHA-256 sidecars. The v1.5.2 CLI is also available on crates.io, verified unyanked on September 20, 2026. Choose a prebuilt download or install the pinned registry version below.

Reference / performanceHistorical benchmark record12 recorded scenarios · versions · method · exact milliseconds
Reference / Measured in the open

Recorded benchmarks.

Historical ADhammer 1.3.3 measurements, with tool versions, transport differences, and raw logs. These results do not establish current-release performance.

Recorded wall-clockADhammer 1.3.3 matrix
54 ms · recorded ADhammer time
Zerologon safe-detect
CVE-2020-1472 · compared with NetExec
ADhammer54 ms
NetExec7,779 ms

Process spawn to exit on the published Windows Server 2025 testbed. Python tools ran through the documented WSL/SOCKS path; that caveat and the pending current-release refresh are part of the record.

Inspect all 12 recorded scenariosversions · method · exact milliseconds
ScenarioADhammerComparisonResult
Recorded against an earlier release; a refresh against the current release is pending.
04 / AD CS field guide

Understand the condition.
Know what to check.

Explore ESC1–ESC16 through configuration, evidence, and defensive checks. Select a class for its explanation and an ADhammer example where a focused check is verified.

ESC1Templates

Who defines the identity?

ESC1 concerns identity control in certificate templates. Risk depends on configuration, permissions, and the service accepting the certificate.

Subject configuration

  1. 01 / SOURCERead directory
  2. 02 / CONDITIONInspect template
  3. 03 / CONTEXTRetain context
  4. 04 / REVIEWReview finding

Illustrative review sequence / ESC1 / not a running test

Template configuration check

adhammer check adcs --url ldaps://dc.example.test:636 --user auditor@example.test --password "@file:./audit-password.txt" --json

v1.5.2 source-checked syntax · documentation placeholders, not ready-to-run targets. Replace hosts, account, and CA name only within your approved scope. Protect the password file. These examples contact real services when run; this page never executes commands or accepts credentials.

Before you run it

Approved LDAP collection scope, a trusted LDAPS certificate, and appropriate directory-read permissions.

What ADhammer does

Collects directory data, extracts certificate templates, and emits template-analysis findings as JSON.

Read the result

Review the affected template and its configuration evidence, then confirm permissions and approval controls separately.

Defensive follow-up

Constrain requester-controlled identity fields and restrict enrollment.

Coverage limits

No complete ACL walk, CA registry audit, or active enrollment. Empty output does not establish a secure environment.

Configuration signals ≠ proven exploitation. Missing reads, incomplete scope, and patch differences can change the interpretation. ESC1–ESC16 is this guide’s scope, not an exhaustive taxonomy or a support score. Examples were not executed against a live domain for this site.

05 / CLI methods

From command
to context.

Choose the question first. See what the command reads, what it returns, and what it cannot prove.

Read the film transcript
  1. Collect: An authorized LDAPS read gathers directory data, including certificate templates.
  2. Inspect: Template rules evaluate the collected configuration. The animation uses a fictional template.
  3. Retain context: JSON findings preserve the rule, affected object, explanation, and remediation. This film shows conceptual fields, not captured tool output.
  4. Review: Confirm permissions, CA settings, patches, and scope separately. A configuration signal is not proof of exploitation; empty findings do not establish safety.

Preflight the connection

JSON checklist

Separate connectivity problems from assessment results before collecting directory data.

EXAMPLE / replace placeholders
adhammer doctor --domain example.test --dc dc.example.test --timeout 3 --json

Before you run
Authorization for DNS and TCP probes to the specified DC. No credentials are supplied in this example.
What happens
Uses the DC for DNS SRV discovery and probes AD TCP ports. It does not attempt a credentialed LDAP bind.
Read the result
Inspect checks, ran, failed, and verdict. Skipped checks are not successful checks; inconclusive is not ready.
Boundary
Reachable ports do not establish LDAP authentication, secure configuration, or assessment coverage.
Read this implementation ↗
New in 1.5.2 / scripting

Less noise. Same evidence.

Add --quiet --no-color to suppress decorative progress and request plain output. Warnings and errors remain; CLICOLOR_FORCE=1 can still override the color setting.

PREFLIGHT / v1.5.2
adhammer --quiet --no-color doctor --domain example.test --dc dc.example.test --timeout 3 --json
v1.5.2 / native speed

Choose the pacing.

The global --fast flag opts into native-speed mode. Its environment equivalent is ADHAMMER_FAST=1. It reduces selected delays and timeouts—not every command’s runtime.

NATIVE SPEED FLAG
adhammer --fast <command>
Where it applies
Selected WMI output-readback delays and enum net --deep service-probe timeouts. The basic network sweep retains its fixed timeouts in v1.5.2.
Trade-off
Shorter timeouts can miss slow responses. This is not a blanket speed boost for doctor or template checks. Target-protection controls, such as lockout safeguards, remain unchanged.

Inspect the network command’s options without running a scan: adhammer --fast enum net --help. The syntax above is a pattern, not a ready-to-run command. Read the speed-mode implementation ↗

These examples were checked against v1.5.2 source, not executed against a live domain. Run only within written authorization. Replace example.test placeholders; protect password files and collected output. The website never executes commands. Check the validation ledger ↗

Reference / engineeringExplore the Rust foundationsThe standalone crates ADhammer composes into one engine
Reference / Rust ecosystem

Under the surface.

ADhammer composes published standalone icedracon crates into one Rust engine. Each layer remains independently inspectable and reusable outside the binary.

Layer / DirectoryLDAP + security descriptors

Directory objects, ACLs, ACEs, and security descriptor parsing.

windows-sddl docs ↗
Layer / RPCDCE/RPC

Microsoft RPC interfaces and transport primitives.

dcerpc docs ↗
Layer / IdentityKerberos

Ticket and authentication workflows, with support tracked in the ledger.

Kerberos crate docs ↗
Layer / AuthNTLM

NTLMSSP authentication, message integrity, and session security.

ntlmssp docs ↗
Layer / OutputBloodHound export

Export directory objects and relationships for further analysis.

Export crate docs ↗
AD//HAMMERone composed engine
01Protocol-shaped

The implementation follows Microsoft protocol structures.

02Explicit state

Possible and proven remain different objects.

03Context survives

Graph, technique, command, and artifact stay linked.

04Inspectable

Open source, MIT licensed, and composed from standalone crates.

Open source / MIT / GitHub v1.5.2

Take itinto the field.

Choose a v1.5.2 GitHub download for your platform. Verify its checksum and review command help and the validation ledger before an assessment.

Prefer Cargo? crates.io v1.5.2 is available. Install with cargo install --locked adhammer@1.5.2. Registry availability checked September 20, 2026.