ACTIVE DIRECTORY PATH VALIDATION

You get the paths to Domain Admin that actually hold, and the command that proved each one.

Every candidate is reproduced before it counts.

Explore the
platform.
  • Reproduced Findings

    A credential counts when it authenticates.

  • Full Identity Graph

    We cover roasting, ADCS ESC1-ESC15, delegation, ACLs, shadow credentials, GPOs, coercion, relay, SCCM, LAPS and trusts.

  • Clean Rollback

    RBCD, msDS-KeyCredentialLink and GPO writes are saved, restored, then re-read to confirm.

  • Kerberos-First Tradecraft

    A TGT and ccache per operation, Kerberos flags everywhere, no NTLM fallback.

Scope

A run covers Kerberoasting and AS-REP roasting, ADCS certificate abuse, constrained and resource-based delegation, ACL and GPO paths, coercion and relay, and trust relationships. Each of these is a hard limit in the shipped playbook. Where a job stops, it stops with the material in your operator's hands.

  • No offline cracking

    Roasted and dumped hashes come back with their principal, type and hashcat mode.

  • No password spraying

    There is no spraying skill in the bundle.

  • No remediation. Cracken does not close a delegation, unpublish a template, or repair an ACL

    A misconfiguration that pre-dates the engagement is a finding, not something to clean up.

  • No Entra ID tenant attack

    This playbook works on-premises Active Directory.

  • No detection scoring

    Cracken records what it ran and when, including the noisier steps.

Who this is for

Start testing
  • Identity / AD Administrator

    You inherited twenty years of nested groups and delegation. You need to know which part of it hands an attacker domain admin.

  • Red Team Lead

    You want Kerberoasting, delegation abuse and ACL paths run against the live directory, each with the exact request that proved it.

  • CISO

    Every ransomware case study you read ends in Active Directory. You need to know how far one compromised laptop gets in yours.

Questions

Does Cracken need Domain Admin to start?

No. The AD Pentest playbook works at whatever access it is given: no credentials at all (network recon, RID cycling, poisoning surface), a username only (AS-REP targets, Kerberos user validation), or one standard domain account. Domain Admin is the objective, not the prerequisite.

Will an Active Directory pentest change anything in my domain?

Some techniques must write: RBCD sets a computer object attribute, shadow credentials write msDS-KeyCredentialLink, GPO abuse edits a policy. Each captures the exact original value before mutating, restores it on completion, and re-reads the attribute to verify. A technique that cannot prove its rollback is escalated as a blocking cleanup failure with every remaining artifact named.

How is this different from BloodHound or an attack path graph?

A path graph infers routes from directory data. Cracken uses BloodHound collection as one input to that same map, then runs the technique each edge implies against the live domain and keeps only what a separate verify operation reproduced. The graph is the plan; the reproduction is the finding.

What happens when a step fails?

Cracken separates "the reproduction ran and the access did not hold" (UNPROVEN) from "the reproduction could not run" (BLOCKED). A missing tool is installed and retried. Clock skew stops the run and asks for ntpdate rather than falling back to NTLM. A blocked candidate stays pending and is re-dispatched; it never turns into a negative result.

Walk the edges your graph only scored.

Set the scope, name the DC, pick Manual, Semi, or Auto. Then watch every command as it runs.