Skip to main content

vamp-ad-recon

Python 3.9+ Platform License AGPL-3.0 VampSecure Labs

Overview

vamp-ad-recon is an Active Directory / LDAP security auditor for authorized penetration testing engagements against Windows domain environments. It connects via LDAP3 with NTLM authentication — no impacket or native Kerberos dependency required — and executes a multi-phase enumeration covering domain metadata, user account weaknesses, Kerberoasting candidates, AS-REP Roasting candidates, delegation misconfigurations (unconstrained, constrained, RBCD), privileged group membership auditing, GPO permission analysis, and password policy review. Findings are rated CRITICAL to INFO with MITRE ATT&CK mappings and exported to console (Rich), JSON, or HTML.

Features

  • Phase 0: domain rootDSE info (naming context, domain/forest functionality level, NetBIOS name, domain controllers)
  • Phase 1: user enumeration — total count, disabled accounts, never-expiring passwords (UAC flag 65536), no-password-required accounts (UAC flag 32)
  • Phase 2: Kerberoasting candidates — accounts with SPN configured, RC4 encryption type detection, password age classification (AD-001: CRITICAL if >365 days, HIGH otherwise)
  • Phase 3: AS-REP Roasting candidates — accounts with DONT_REQUIRE_PREAUTH set (AD-002: CRITICAL)
  • Phase 4: delegation misconfigurations — unconstrained delegation excluding DCs (AD-003: CRITICAL), constrained delegation with delegation targets (AD-004: HIGH), Resource-Based Constrained Delegation (AD-005: HIGH)
  • Phase 5: privileged group membership — Domain Admins, Enterprise Admins, Schema Admins, Administrators, Account Operators, Backup Operators, Server Operators, Print Operators; flags excess membership (AD-006: MEDIUM) and service accounts in Domain Admins (AD-007: HIGH)
  • Phase 6: GPO permission analysis — enumeration of all Group Policy Objects with SYSVOL paths and security descriptor review (AD-008: HIGH for writable GPOs)
  • Phase 7: password policy — minimum length (AD-009: MEDIUM if <12), lockout threshold (AD-010: HIGH if disabled), maximum password age (AD-011: MEDIUM if no expiration)
  • NTLM authentication via ldap3 with optional SSL (port 636)
  • Anonymous null-session bind attempt with --null-session
  • MITRE ATT&CK technique references per finding (T1558, T1558.004, T1134.001, etc.)
  • Selective module execution via individual flags or --all
  • Export to Console (Rich panels per phase), JSON, and HTML (dark-theme)

Requirements

  • Python 3.9 or later
  • rich >= 13.7.0
  • ldap3 >= 2.9.0
  • Network connectivity to the target Domain Controller (port 389 or 636)
  • Optional: fpdf2 >= 2.7 for --report-pdf

Installation

pip install vamp-ad-recon
# or with Homebrew:
brew install vampsecure-labs/labs/vamp-ad-recon
git clone https://github.com/Vampsecure-Labs/vamp-ad-recon.git
cd vamp-ad-recon
python3 -m venv .venv
source .venv/bin/activate   # Windows: .venv\Scripts\activate
pip install -r requirements.txt

Usage

vamp-ad-recon --help
usage: vamp-ad-recon enum --dc <IP_OR_HOST> --domain <FQDN>
                          --user <USERNAME> --password <PASSWORD>
                          [--dc-port 389|636] [--ssl]
                          [--null-session]
                          [--kerberoast] [--asrep] [--delegation]
                          [--gpo] [--all]
                          [--json FILE] [--html FILE]
                          [--client CLIENT] [--engagement ENGAGEMENT]
                          [--auditor AUDITOR] [--report-scope SCOPE]
                          [--report-html FILE] [--report-pdf FILE]

Examples

# Basic domain enumeration with NTLM authentication
vamp-ad-recon enum --dc 192.168.1.10 --domain corp.example.com \
    --user svc_audit --password 'P@ssw0rd!'

# Full enumeration with all attack-path checks
vamp-ad-recon enum --dc dc01.corp.example.com --domain corp.example.com \
    --user pentest --password 'Secret123' --all

# Kerberoasting and AS-REP Roasting checks only
vamp-ad-recon enum --dc 10.0.0.5 --domain internal.lab \
    --user auditor --password 'Lab!Pass' --kerberoast --asrep

# Anonymous null-session enumeration attempt
vamp-ad-recon enum --dc 10.0.0.5 --domain internal.lab --null-session

# SSL connection on port 636
vamp-ad-recon enum --dc ldaps.corp.com --domain corp.com \
    --user reader --password 'Pwd!' --ssl

# Export findings to JSON and dark-theme HTML
vamp-ad-recon enum --dc 192.168.1.10 --domain corp.example.com \
    --user svc_audit --password 'P@ssw0rd!' --all \
    --json findings.json --html report.html

# Generate client-ready engagement report
vamp-ad-recon enum --dc 192.168.1.10 --domain corp.example.com \
    --user svc_audit --password 'P@ssw0rd!' --all \
    --client "Acme Corp" --engagement "AD Security Review Q4 2026" \
    --auditor "J. Smith" --report-html client_report.html --report-pdf client_report.pdf

CLI Reference

Flag Default Description
--dc HOST required IP address or hostname of the Domain Controller
--domain FQDN required Fully qualified domain name (e.g. corp.example.com)
--user USERNAME required Username for NTLM authentication
--password PASS required Password for NTLM authentication
--dc-port PORT 389 LDAP port (389 plain, 636 SSL)
--ssl off Use SSL/TLS (LDAPS) — sets port to 636 if not specified
--null-session off Attempt anonymous LDAP bind first
--kerberoast off Include Kerberoasting candidate check
--asrep off Include AS-REP Roasting candidate check
--delegation off Include delegation misconfiguration checks
--gpo off Include GPO permission analysis
--all off Run all optional modules
--json FILE — Export results to JSON
--html FILE — Export dark-theme HTML report
--client TEXT — Client name for VSL engagement report
--engagement TEXT — Engagement title for VSL engagement report
--auditor TEXT — Auditor name for VSL engagement report
--report-scope TEXT — Scope description for VSL engagement report
--report-html FILE — Export unified VSL client report (HTML)
--report-pdf FILE — Export unified VSL client report (PDF, requires fpdf2)

Findings Reference

ID Severity Category MITRE ATT&CK
AD-001 CRITICAL/HIGH Kerberoasting T1558.003
AD-002 CRITICAL AS-REP Roasting T1558.004
AD-003 CRITICAL Unconstrained Delegation T1134.001
AD-004 HIGH Constrained Delegation T1134.001
AD-005 HIGH RBCD T1134.001
AD-006 MEDIUM Privileged Group Excess T1078.002
AD-007 HIGH Service Account in Domain Admins T1078.002
AD-008 HIGH GPO Write Permission T1484.001
AD-009 MEDIUM Weak Password Policy (length) T1110
AD-010 HIGH No Account Lockout Policy T1110.001
AD-011 MEDIUM No Password Expiration Policy T1078

Output Formats

Format Flag Description
Console (default) Rich panels per phase with color-coded findings by severity
JSON --json FILE Machine-readable full result set
HTML --html FILE Dark-theme standalone report
Client HTML --report-html FILE Unified VampSecure Labs engagement report
Client PDF --report-pdf FILE PDF version of the VSL client report

Exit Codes

Code Meaning CI/CD Behavior
0 No critical or high findings Pipeline passes
1 High or critical findings detected Pipeline fails — review required
2 Connection or authentication error Pipeline fails — check credentials/connectivity

Use exclusively on systems you own or for which you hold explicit written authorization from the system owner. VampSecure Studios assumes no liability for unauthorized use.

Part of VampSecure Labs Toolkit

vamp-ad-recon is one tool in the VampSecure Labs security research toolkit. For the full toolkit including the orchestrator that runs all tools in sequence and aggregates findings into a single engagement report, see:


© VampSecure Studios — VampSecure Labs Security Research Division

Versión

v1.0 — VampSecure Labs Security Research Division

Metadata

Release files for vamp-ad-recon 1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vamp-ad-recon 1.0
File Size Uploaded
vamp_ad_recon-1.0.tar.gz 29.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vamp-ad-recon 1.0
File Interpreter ABI Platform
vamp_ad_recon-1.0-py3-none-any.whl Python 3 none any Details

Total release size: 60.8 kB

Release files / vamp_ad_recon-1.0.tar.gz

Download URL vamp_ad_recon-1.0.tar.gz
Size 29.8 kB
Tags Source
SHA-256 checksum
How to use checksums
4bf53676aea0fbedb839b337be55d301e189ff1ad87046d4bc4289e31be09f75
BLAKE2b-256 checksum
How to use checksums
9b0209b18169d455f86dd98135abcf1791a563f212879332e5cfef3443ae6800
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release files / vamp_ad_recon-1.0-py3-none-any.whl

Download URL vamp_ad_recon-1.0-py3-none-any.whl
Size 31.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8599d22a2b1a15e7cf0aecf8f86add5f14ebe4265e0032f3c6e9b1b80123f37f
BLAKE2b-256 checksum
How to use checksums
d3448c5a7460635cb05a2a94b1a7a15098dc4117fb3f00f9e09cb280234ec1ad
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release history Release notifications | RSS feed

This release

1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page