# AdStrike: A Modular Active Directory Framework for Authorized Penetration Testing

> AdStrike is a terminal-based Python framework for authorized Active Directory red-team engagements. It organizes 52 attack modules across nine kill-chain phases, maintains a shared session with target credentials and Kerberos state, and exposes all modules as an MCP server that can be driven by Claude Code, Cursor, or Claude Desktop without a separate API key.

**capture0x/AdStrike** — AI-powered modular Active Directory red-team framework for authorized penetration testing, AD enumeration, attack-path analysis,   Kerberos/ADCS workflows, reporting, operator automation, and MCP server integration.

- Repository: https://github.com/capture0x/AdStrike
- Website: https://adstrike.oxcapture.com
- Stars: 357 · Forks: 76
- Language: Python
- License: MIT
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/capture0x-adstrike

## What AdStrike Is and Who It Is For

Active Directory penetration testing involves many sequential steps: initial reconnaissance, LDAP enumeration, privilege escalation, lateral movement, credential access, and persistence. Most teams run these steps with separate command-line tools, re-entering target details, credentials, and domain context at each step. AdStrike addresses this by storing all session state, including the domain controller IP, credentials, Kerberos ticket cache, captured hashes, and output paths, in a shared session that every module reads from automatically.

The tool is designed for professional red-team operators and penetration testers working under explicit written permission from the asset owner. The README states this requirement prominently: "Authorized use only. Do not run this tool against systems without explicit written permission." It is built for Kali Linux 2024 or Parrot OS, and the install script targets those environments.

AdStrike is not a beginner's tool. The README expects operators to understand AD fundamentals, know how to read LDAP output, and be comfortable with the underlying tools (Impacket, NetExec, BloodHound) before using the framework's wrappers.

## Nine Kill-Chain Phases and 52 Attack Modules

The 52 attack modules are organized across nine phase groups numbered 0 through 8, plus a utilities group. Phase 0 (menu entries 1-2) covers reconnaissance: DNS enumeration, WHOIS, email harvesting, and certificate transparency. Phase 1 (3-9) covers initial access including NTLM capture and no-credential entry points. Phase 2 (10-16) covers AD enumeration via LDAP, SMB, and GPO data collection. Phases 3 through 7 cover privilege escalation, lateral movement, credential access, persistence, and cloud/hybrid environments. Phase 8 (49-52) covers advanced operations.

The utilities group (53-58) contains the AI-assisted modules: the Smart Analyst for parsing output and ranking next steps, the AdStrike Agent for AI-assisted planning, a Kerberos Manager, a report generator, a Session Manager, and a Tool Checker. These six entries are separate from the attack modules and are the primary interface for configuring the session and reviewing results.

The recommended first-run sequence from the README is: Session Manager (configure target and credentials), Tool Checker (verify external tools), AD Enumeration module 10, Smart Analyst, then Generate Report.

## Installation and First Session

AdStrike runs on Kali Linux 2024 or later. The install script creates a virtual environment and installs dependencies:

```bash
git clone https://github.com/capture0x/AdStrike.git
cd AdStrike
chmod +x install.sh run.sh
bash install.sh
source venv/bin/activate
bash run.sh
```

The README warns not to run `install.sh` with `sudo`. Running as root leaves repo-local files root-owned, which breaks subsequent runs as a normal user. If that has already happened, the fix is:

```bash
sudo chown -R "$(id -un):$(id -gn)" .
```

Before running an engagement, copy `.env.example` to `.env` and populate the target values. At minimum, `DC_IP`, `DOMAIN`, and `USERNAME` are needed. Optional fields include `NT_HASH` for pass-the-hash authentication and `USE_KERBEROS=true` for Kerberos ticket-based authentication:

```bash
python3 main.py --check
```

The `--check` flag verifies module health without starting an engagement. The README shows the expected output as "Module health OK: 56/56", which includes the attack modules plus utilities.

## Session State and the .env Configuration

Session state is the central design decision in AdStrike. Rather than requiring operators to retype the domain controller IP, credentials, or target domain with each module, the framework stores those values in a shared session derived from `.env` and updated through the Session Manager. Modules query the session for context instead of prompting interactively.

The `.env.example` file shows the full set of configurable values:

```env
DC_IP=10.10.10.10
DC_FQDN=dc1.corp.local
DOMAIN=corp.local
BASE_DN=DC=corp,DC=local
USERNAME=user
ATTACKER_IP=10.10.14.5
ATTACKER_IFACE=tun0
ENGAGEMENT_NAME=Corp-Internal-2026
ADSTRIKE_SHOW_SECRETS=false
```

Several environment flags control operational behavior. `ADSTRIKE_SHOW_SECRETS=false` masks passwords, hashes, and loot in logs and reports by default. `ADSTRIKE_OPSEC` controls agent mode noise level with three values: `loud`, `normal`, and `stealth`. `TGT_AUTO_RENEW=true` keeps Kerberos ticket renewal active. The README explicitly warns never to commit real engagement data: `.env`, output directories, ticket files, hashes, and captured loot must be kept private.

## MCP Server Integration

AdStrike 5.0 includes an MCP server that exposes all 53 tools (52 attack modules plus `set_engagement`) over the Model Context Protocol. This allows an MCP host such as Claude Code, Cursor, or Claude Desktop to drive the full engagement workflow using its own subscription, without requiring a separate `ANTHROPIC_API_KEY` or a local model.

The `.mcp.json` file at the repository root contains the server configuration for connecting an MCP host. The MCP server documentation is in `docs/mcp.md`. Direct module execution is also available without the MCP interface:

```bash
python3 main.py --module 10
python3 main.py --module 58 --no-banner
python3 main.py --session output/session.json --no-banner
```

The `--module` flag runs a specific numbered module directly. The `--session` flag loads a saved session file, which allows resuming an engagement across multiple runs without re-entering target details.

## External Tool Dependencies and Limitations

AdStrike wraps external tools rather than reimplementing their functionality. The key external tools are Impacket, NetExec (nxc), bloodhound-python, Certipy-AD, evil-winrm, Kerbrute, Responder, ldap-utils, Hashcat, John, nmap, and Kerberos utilities. The `install.sh` script installs most of these; the `scripts/repair_tools.sh` script handles optional tool installation and repairs.

This creates a practical limitation: the framework is only as reliable as the underlying tools, and each module's behavior depends on target state, network reachability, and the specific tool version installed. The README states: "Release status: beta/research build. Menu and import health checks pass; individual modules still depend on target state, credentials, network reachability, and installed third-party tools."

The last push to the repository was on 2026-06-11, about three and a half months before this review. The repository is not archived.

## Comparison with Direct Impacket Usage

Impacket is a collection of Python classes and scripts for working with network protocols, including a full set of Active Directory attack scripts such as `GetNPUsers.py`, `secretsdump.py`, and `wmiexec.py`. Each Impacket script is a standalone command that must be invoked separately, with its own argument format and without shared context between runs.

AdStrike wraps Impacket scripts into a managed workflow where the session carries target details across modules, output is saved to a consistent directory structure, and the Smart Analyst can parse Impacket output to suggest next steps. Teams who run individual Impacket commands fluently will recognize every underlying operation; AdStrike adds the session management, sequencing guidance, and reporting layer on top.

The practical trade-off is that Impacket gives direct access to individual scripts with full parameter control, while AdStrike provides higher-level workflow automation that can obscure what each underlying command is doing. For learning AD attack paths, Impacket alone is more educational. For running an organized engagement with documented output, AdStrike's session management has value.

## Conclusion

AdStrike is a practical choice for red-team operators who want a managed workflow over individual Impacket and NetExec scripts, with Kerberos state and session context carried across modules. It is not a beginner tool: the README expects operators to understand AD fundamentals, read LDAP output, and know the underlying tools before using the wrappers. Before starting an engagement, run `python3 main.py --check` to verify module health, populate `.env` with all required values, and confirm that the external tools needed by the target modules are installed and functional.

## FAQ

### what is ad strike

AdStrike is a terminal-based Python framework for authorized Active Directory penetration testing. It organizes 52 attack modules across nine kill-chain phases, from reconnaissance through persistence, and maintains a shared session carrying target credentials, Kerberos state, and output paths across modules.

### Does AdStrike require an API key for the MCP server?

No. The MCP server integration requires no ANTHROPIC_API_KEY. It connects to an MCP host such as Claude Code or Cursor that uses its own existing subscription to drive the engagement. The ANTHROPIC_API_KEY is optional and only needed for the standalone AdStrike Agent module.

### What operating systems does AdStrike support?

The README lists Kali Linux 2024 or later and Parrot OS as the recommended operating systems. Python 3.10 or higher is required. The install script and external tool wrappers are designed for those environments; other Linux distributions may work but are not documented.

## Sources

- [capture0x/AdStrike on GitHub](https://github.com/capture0x/AdStrike)
- [Issues](https://github.com/capture0x/AdStrike/issues)
- [License: MIT](https://github.com/capture0x/AdStrike/blob/main/LICENSE)
- [Project website](https://adstrike.oxcapture.com)
- [README](https://github.com/capture0x/AdStrike/blob/main/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/capture0x-adstrike
