Open-source project
S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet avatar
S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet

Active-Directory-Exploitation-Cheat-Sheet: a command reference for AD enumeration and attack paths

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

6,756 stars1,326 forksUnknownMIT

At a glance

What is it?
A MIT-licensed Markdown repository that collects PowerView, BloodHound, Impacket, Mimikatz and Rubeus commands for Windows Active Directory enumeration, privilege escalation and persistence. It is a reference document, not a tool you install.
Who is it for?
Adopt it as a command index if you already run AD assessments and know which tool each snippet belongs to; skip it if you need explanations of why an attack works or a guided lab. Before relying on it, verify the PowerView v3.0 command names against the PowerSploit dev branch, confirm which Mimikatz and Rubeus builds you are pairing with each snippet, and check the LICENSE file for the MIT terms.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 126 days ago.
What is it written in?
GitHub does not report a main language for this repository.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What the Active-Directory-Exploitation-Cheat-Sheet actually is

The repository is a single README plus a LICENSE file and one image, WalkTheDog.png. There is no source tree, no build file, no package manifest and no release. The README opens by stating that the cheat sheet contains common enumeration and attack methods for Windows Active Directory, and credits Nikos Katsiopis and Nikos Vourdas as its authors, with PayloadsAllTheThings named as the inspiration. That framing matters: the artifact is prose and command lines, and the value is in the ordering and grouping of those commands, not in any code the project owns.

The intended reader is someone already inside an AD assessment who needs the right syntax quickly. The summary alone lists sections for domain enumeration, local privilege escalation, lateral movement, domain privilege escalation, domain persistence and cross forest attacks. Each of those is a phase an operator moves through, and the README keeps the phases in that order rather than alphabetical order, which is the useful choice. A reader who does not already know what Kerberoasting is will not learn it here; the section gives commands, not a threat model.

How the material is organised: tools first, then attack phases

The README has a Tools section that lists external projects by link: PowerSploit, PowerUpSQL, Powermad, Impacket, Mimikatz, Rubeus (with a pointer to a compiled binaries repository), BloodHound, AD Module, ASREPRoast and Adalanche. Nothing is vendored. Every command in the body assumes one of those tools is already present on the host or reachable from it, and the cheat sheet never explains how to obtain the tool beyond the link.

Enumeration is split by tool rather than by question. There is a PowerView subsection, an AD Module subsection, a BloodHound subsection divided into remote and on-site collection, and an Adalanche subsection. The same domain fact, for example the list of domain controllers, can be reached through more than one of these, and the README does not say which to prefer. Later sections move to attack technique: Kerberoast, ASREPRoast, password spray, delegation variants, DNSAdmins, ACL abuse, Zerologon, PrintNightmare and Active Directory Certificate Services, followed by persistence techniques such as Golden Ticket, DCsync, Silver Ticket, Skeleton Key, DSRM abuse and custom SSP, and finally cross forest material on trust tickets, MSSQL abuse and breaking forest trusts. The data flow is entirely human: you read a snippet, you paste it into a PowerShell session or a shell, and you interpret the output yourself.

Installing it and running a first enumeration

There is nothing to install. The repository contains documentation only, so the practical setup is cloning the README and putting the tools it references on your assessment host. The README does not give a clone command, so the form below is the standard one for a GitHub repository of this shape.

bash
git clone https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet.git

After that you have README.md locally and can search it with grep instead of scrolling. The first real use is the domain enumeration block. The README's PowerView subsection, which points at PowerView v3.0 in the PowerSploit dev branch, starts with getting the current domain and its SID.

powershell
Get-Domain
Get-DomainSID

Run inside a domain-joined session with PowerView loaded, the first command returns the domain object for the context you are in, and the second returns the domain SID, which later snippets need when they build or interpret ACEs. From there the README suggests pulling domain policy, and it splits the output by expanding the relevant properties.

powershell
Get-DomainPolicy
Get-DomainPolicy | Select-Object -ExpandProperty SystemAccess
Get-DomainPolicy | Select-Object -ExpandProperty KerberosPolicy

The SystemAccess view carries password and lockout policy; the KerberosPolicy view carries ticket lifetime settings. The README also shows saving bulk output to disk, for example Get-DomainUser piped to Out-File with a file path, which is the pattern to follow when you want a record of the enumeration rather than a scrollback. Expect the first commands to be slow on a large domain: they are LDAP queries, and the README offers no batching guidance.

Where the cheat sheet stops short

The README is a command index and behaves like one. Several sections are labelled as lists of useful tools rather than as procedures, so local privilege escalation and lateral movement give you a set of names to chase rather than a sequence to follow. That is a deliberate trade-off in a document of this size, but it means the cheat sheet cannot be the only reference open during an engagement.

There is also no versioning discipline visible in the text. The PowerView subsection names PowerView v3.0 and links into the PowerSploit dev branch, while the Tools section links PowerSploit at the same dev branch. Command names have moved between PowerView releases, and the README does not record which release each snippet was written against, so a snippet that fails may be failing on syntax rather than on permissions. Nothing in the repository states when individual sections were last revised, and there is no changelog. Finally, the README does not discuss authorisation, scope or detection. It is written for people who already have a signed engagement, and it offers no guidance on what the commands leave behind in logs.

Alternatives and how they differ in approach

The closest alternative in kind is PayloadsAllTheThings, which the README itself names as its inspiration. That repository is much broader: it covers web exploitation, payload delivery and many other categories alongside Active Directory, and its AD material is one part of a larger index. This cheat sheet is narrower and deeper on AD, with the phase ordering (enumeration, privilege escalation, lateral movement, persistence, cross forest) built into the summary. If your work is AD-focused, the narrower document is faster to scan; if you need one reference for mixed engagements, the broader one avoids a second bookmark.

A different kind of alternative is BloodHound, which the README covers as an enumeration option rather than as a competitor. The difference in approach is large. BloodHound ingests collected data and computes reachability between principals, so the answer to which path exists comes from the graph. The cheat sheet answers a different question: which command do I type to collect a given fact, or to attempt a given technique. Using one does not remove the need for the other, and the README treats BloodHound as one of several enumeration routes alongside PowerView and Adalanche rather than as the centre of the workflow.

Maintenance, licensing and the cost of keeping it accurate

The repository is not archived, and the last push was on 2026-05-27. There are no retrieved releases, which fits a documentation-only project: updates arrive as commits to README.md, and a reader has no version number to pin. The upgrade cost is therefore not a dependency upgrade but a review cost. Every time PowerSploit, Impacket, Mimikatz or Rubeus changes a flag or a command name, some snippet in the README may drift, and there is no test suite that would catch it. Treat the README as a starting point to check against the tool's own documentation, not as the source of truth for syntax.

The LICENSE file is MIT, and the README does not add terms on top of it. In practice the MIT terms apply to the text and the image in this repository, not to the third-party tools it links, each of which carries its own licence. That distinction matters if you intend to copy sections of the cheat sheet into internal runbooks: the MIT grant covers the copy, but the tools you then run are governed separately, and reading each tool's licence is your own step. This is a description of what the repository states, not legal advice.

Editorial conclusion

Adopt it as a command index if you already run AD assessments and know which tool each snippet belongs to; skip it if you need explanations of why an attack works or a guided lab. Before relying on it, verify the PowerView v3.0 command names against the PowerSploit dev branch, confirm which Mimikatz and Rubeus builds you are pairing with each snippet, and check the LICENSE file for the MIT terms. The repository itself ships no binaries and no test suite, so nothing in it can be validated by running the project.

Frequently asked questions

Is the Active-Directory-Exploitation-Cheat-Sheet a tool I install?

No. The repository contains a README, a LICENSE file and an image, so there is nothing to build or run. You use it as a reference while running other tools such as PowerView, BloodHound, Impacket, Mimikatz or Rubeus, which the README links but does not bundle.

Which tools does the Active-Directory-Exploitation-Cheat-Sheet assume I already have?

The Tools section links PowerSploit, PowerUpSQL, Powermad, Impacket, Mimikatz, Rubeus (with a pointer to compiled binaries), BloodHound, AD Module, ASREPRoast and Adalanche. The body sections then give commands that belong to those tools, so the cheat sheet is not self-contained.

What licence does the Active-Directory-Exploitation-Cheat-Sheet use?

The repository carries an MIT licence, and the README does not state additional terms. That covers the text and image in this repository; the third-party tools it links carry their own licences.

Official sources

  1. Issues
  2. License: MIT
  3. README
  4. S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/s1ckb0y1337-active-directory-exploitation-cheat-sheet.svg)](https://hysenlabs.com/projects/s1ckb0y1337-active-directory-exploitation-cheat-sheet)