Ross ROSS = Recommend OSS · open-source software intelligence for agents

infosecn1nja/AD-Attack-Defense resource

Attack and defend active directory using modern post exploitation adversary tradecraft activity observed · 2026-08-28

github.com/infosecn1nja/AD-Attack-Defense observed · 2026-08-28

Health v2 · maintenance only

48/100

  • Activity 34
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2845
  • days_rel: n/a
  • days_push: 400
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

4858 stars · 1081 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

A curated knowledge base mapping the Active Directory attack kill chain to detection, mitigation, and prevention guidance. It catalogs attacker TTPs across discovery, privilege escalation, credential dumping, lateral movement, and persistence, with links to tools and reference articles for both red and blue teams.

Use cases

  • learn active directory attack techniques
  • find detection guidance for AD attacks
  • prepare for red team engagements against AD
  • build detection rules for credential dumping and lateral movement
  • study post-exploitation tradecraft
  • harden and defend an active directory environment

When to choose

  • you need a reference map of AD attack TTPs with matching defenses
  • you are training a security team on AD attack and detection
  • you are planning or defending against AD-focused penetration tests

When to avoid

  • you need runnable software rather than a curated link collection
  • you need coverage of non-Windows or cloud-only identity environments
  • you need step-by-step tutorials rather than curated references

Facets

learning-resource · maturity active

security penetration-testing developer-tools security penetration-testing awesome-lists cross-platform active-directory kill-chain red-team blue-team threat-detection curated-list post-exploitation

1 source

Member repositories

RepositoryRoleHealth v2
infosecn1nja/AD-Attack-Defensemain48

For agents

markdown · JSON · MCP: product_card(name="infosecn1nja/AD-Attack-Defense")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem