vamp-ad-recon
Overview
vamp-ad-recon is an Active Directory / LDAP security auditor for authorized penetration testing engagements against Windows domain environments. It connects via LDAP3 with NTLM authentication — no impacket or native Kerberos dependency required — and executes a multi-phase enumeration covering domain metadata, user account weaknesses, Kerberoasting candidates, AS-REP Roasting candidates, delegation misconfigurations (unconstrained, constrained, RBCD), privileged group membership auditing, GPO permission analysis, and password policy review. Findings are rated CRITICAL to INFO with MITRE ATT&CK mappings and exported to console (Rich), JSON, or HTML.
Features
- Phase 0: domain rootDSE info (naming context, domain/forest functionality level, NetBIOS name, domain controllers)
- Phase 1: user enumeration — total count, disabled accounts, never-expiring passwords (UAC flag 65536), no-password-required accounts (UAC flag 32)
- Phase 2: Kerberoasting candidates — accounts with SPN configured, RC4 encryption type detection, password age classification (AD-001: CRITICAL if >365 days, HIGH otherwise)
- Phase 3: AS-REP Roasting candidates — accounts with DONT_REQUIRE_PREAUTH set (AD-002: CRITICAL)
- Phase 4: delegation misconfigurations — unconstrained delegation excluding DCs (AD-003: CRITICAL), constrained delegation with delegation targets (AD-004: HIGH), Resource-Based Constrained Delegation (AD-005: HIGH)
- Phase 5: privileged group membership — Domain Admins, Enterprise Admins, Schema Admins, Administrators, Account Operators, Backup Operators, Server Operators, Print Operators; flags excess membership (AD-006: MEDIUM) and service accounts in Domain Admins (AD-007: HIGH)
- Phase 6: GPO permission analysis — enumeration of all Group Policy Objects with SYSVOL paths and security descriptor review (AD-008: HIGH for writable GPOs)
- Phase 7: password policy — minimum length (AD-009: MEDIUM if <12), lockout threshold (AD-010: HIGH if disabled), maximum password age (AD-011: MEDIUM if no expiration)
- NTLM authentication via ldap3 with optional SSL (port 636)
- Anonymous null-session bind attempt with
--null-session - MITRE ATT&CK technique references per finding (T1558, T1558.004, T1134.001, etc.)
- Selective module execution via individual flags or
--all - Export to Console (Rich panels per phase), JSON, and HTML (dark-theme)
Requirements
- Python 3.9 or later
rich >= 13.7.0ldap3 >= 2.9.0- Network connectivity to the target Domain Controller (port 389 or 636)
- Optional:
fpdf2 >= 2.7for--report-pdf
Installation
pip install vamp-ad-recon
# or with Homebrew:
brew install vampsecure-labs/labs/vamp-ad-recon
git clone https://github.com/Vampsecure-Labs/vamp-ad-recon.git
cd vamp-ad-recon
python3 -m venv .venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
pip install -r requirements.txt
Usage
vamp-ad-recon --help
usage: vamp-ad-recon enum --dc <IP_OR_HOST> --domain <FQDN>
--user <USERNAME> --password <PASSWORD>
[--dc-port 389|636] [--ssl]
[--null-session]
[--kerberoast] [--asrep] [--delegation]
[--gpo] [--all]
[--json FILE] [--html FILE]
[--client CLIENT] [--engagement ENGAGEMENT]
[--auditor AUDITOR] [--report-scope SCOPE]
[--report-html FILE] [--report-pdf FILE]
Examples
# Basic domain enumeration with NTLM authentication
vamp-ad-recon enum --dc 192.168.1.10 --domain corp.example.com \
--user svc_audit --password 'P@ssw0rd!'
# Full enumeration with all attack-path checks
vamp-ad-recon enum --dc dc01.corp.example.com --domain corp.example.com \
--user pentest --password 'Secret123' --all
# Kerberoasting and AS-REP Roasting checks only
vamp-ad-recon enum --dc 10.0.0.5 --domain internal.lab \
--user auditor --password 'Lab!Pass' --kerberoast --asrep
# Anonymous null-session enumeration attempt
vamp-ad-recon enum --dc 10.0.0.5 --domain internal.lab --null-session
# SSL connection on port 636
vamp-ad-recon enum --dc ldaps.corp.com --domain corp.com \
--user reader --password 'Pwd!' --ssl
# Export findings to JSON and dark-theme HTML
vamp-ad-recon enum --dc 192.168.1.10 --domain corp.example.com \
--user svc_audit --password 'P@ssw0rd!' --all \
--json findings.json --html report.html
# Generate client-ready engagement report
vamp-ad-recon enum --dc 192.168.1.10 --domain corp.example.com \
--user svc_audit --password 'P@ssw0rd!' --all \
--client "Acme Corp" --engagement "AD Security Review Q4 2026" \
--auditor "J. Smith" --report-html client_report.html --report-pdf client_report.pdf
CLI Reference
| Flag | Default | Description |
|---|---|---|
--dc HOST |
required | IP address or hostname of the Domain Controller |
--domain FQDN |
required | Fully qualified domain name (e.g. corp.example.com) |
--user USERNAME |
required | Username for NTLM authentication |
--password PASS |
required | Password for NTLM authentication |
--dc-port PORT |
389 |
LDAP port (389 plain, 636 SSL) |
--ssl |
off | Use SSL/TLS (LDAPS) — sets port to 636 if not specified |
--null-session |
off | Attempt anonymous LDAP bind first |
--kerberoast |
off | Include Kerberoasting candidate check |
--asrep |
off | Include AS-REP Roasting candidate check |
--delegation |
off | Include delegation misconfiguration checks |
--gpo |
off | Include GPO permission analysis |
--all |
off | Run all optional modules |
--json FILE |
— | Export results to JSON |
--html FILE |
— | Export dark-theme HTML report |
--client TEXT |
— | Client name for VSL engagement report |
--engagement TEXT |
— | Engagement title for VSL engagement report |
--auditor TEXT |
— | Auditor name for VSL engagement report |
--report-scope TEXT |
— | Scope description for VSL engagement report |
--report-html FILE |
— | Export unified VSL client report (HTML) |
--report-pdf FILE |
— | Export unified VSL client report (PDF, requires fpdf2) |
Findings Reference
| ID | Severity | Category | MITRE ATT&CK |
|---|---|---|---|
| AD-001 | CRITICAL/HIGH | Kerberoasting | T1558.003 |
| AD-002 | CRITICAL | AS-REP Roasting | T1558.004 |
| AD-003 | CRITICAL | Unconstrained Delegation | T1134.001 |
| AD-004 | HIGH | Constrained Delegation | T1134.001 |
| AD-005 | HIGH | RBCD | T1134.001 |
| AD-006 | MEDIUM | Privileged Group Excess | T1078.002 |
| AD-007 | HIGH | Service Account in Domain Admins | T1078.002 |
| AD-008 | HIGH | GPO Write Permission | T1484.001 |
| AD-009 | MEDIUM | Weak Password Policy (length) | T1110 |
| AD-010 | HIGH | No Account Lockout Policy | T1110.001 |
| AD-011 | MEDIUM | No Password Expiration Policy | T1078 |
Output Formats
| Format | Flag | Description |
|---|---|---|
| Console | (default) | Rich panels per phase with color-coded findings by severity |
| JSON | --json FILE |
Machine-readable full result set |
| HTML | --html FILE |
Dark-theme standalone report |
| Client HTML | --report-html FILE |
Unified VampSecure Labs engagement report |
| Client PDF | --report-pdf FILE |
PDF version of the VSL client report |
Exit Codes
| Code | Meaning | CI/CD Behavior |
|---|---|---|
0 |
No critical or high findings | Pipeline passes |
1 |
High or critical findings detected | Pipeline fails — review required |
2 |
Connection or authentication error | Pipeline fails — check credentials/connectivity |
Legal Notice
Use exclusively on systems you own or for which you hold explicit written authorization from the system owner. VampSecure Studios assumes no liability for unauthorized use.
Part of VampSecure Labs Toolkit
vamp-ad-recon is one tool in the VampSecure Labs security research toolkit. For the full toolkit including the orchestrator that runs all tools in sequence and aggregates findings into a single engagement report, see:
- Portfolio: github.com/Vampsecure-Labs
- Orchestrator: github.com/Vampsecure-Labs/vamp-orchestrator
© VampSecure Studios — VampSecure Labs Security Research Division
Versión
v1.0 — VampSecure Labs Security Research Division
Metadata
Release files for vamp-ad-recon 1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vamp_ad_recon-1.0.tar.gz | 29.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vamp_ad_recon-1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 60.8 kB
Release files / vamp_ad_recon-1.0.tar.gz
| Download URL | vamp_ad_recon-1.0.tar.gz |
|---|---|
| Size | 29.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
4bf53676aea0fbedb839b337be55d301e189ff1ad87046d4bc4289e31be09f75
|
|
BLAKE2b-256 checksum How to use checksums |
9b0209b18169d455f86dd98135abcf1791a563f212879332e5cfef3443ae6800
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|
Release files / vamp_ad_recon-1.0-py3-none-any.whl
| Download URL | vamp_ad_recon-1.0-py3-none-any.whl |
|---|---|
| Size | 31.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8599d22a2b1a15e7cf0aecf8f86add5f14ebe4265e0032f3c6e9b1b80123f37f
|
|
BLAKE2b-256 checksum How to use checksums |
d3448c5a7460635cb05a2a94b1a7a15098dc4117fb3f00f9e09cb280234ec1ad
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|