# infosecn1nja/AD-Attack-Defense

Attack and defend active directory using modern post exploitation adversary tradecraft activity

Repository: https://github.com/infosecn1nja/AD-Attack-Defense
Canonical: https://ross.abutalabs.com/products/ad-attack-defense
License Family: other
Last push: 2025-07-29T11:12:41+00:00

## Health v2 (maintenance only)
Score: 48/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 34, release rhythm 35, longevity 100
- inputs: {"age_days": 2845, "days_push": 400, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4858, forks 1081 (observed 2026-08-28T04:09:01.514511+00:00)

## What it is
A curated knowledge base mapping the Active Directory attack kill chain to detection, mitigation, and prevention guidance. It catalogs attacker TTPs across discovery, privilege escalation, credential dumping, lateral movement, and persistence, with links to tools and reference articles for both red and blue teams.

## Use cases
- learn active directory attack techniques
- find detection guidance for AD attacks
- prepare for red team engagements against AD
- build detection rules for credential dumping and lateral movement
- study post-exploitation tradecraft
- harden and defend an active directory environment

## When to choose
- you need a reference map of AD attack TTPs with matching defenses
- you are training a security team on AD attack and detection
- you are planning or defending against AD-focused penetration tests

## When to avoid
- you need runnable software rather than a curated link collection
- you need coverage of non-Windows or cloud-only identity environments
- you need step-by-step tutorials rather than curated references

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, penetration-testing, developer-tools
- domain: security, penetration-testing, awesome-lists
- platform: cross-platform
- tags: active-directory, kill-chain, red-team, blue-team, threat-detection, curated-list, post-exploitation

## Member repositories
- infosecn1nja/AD-Attack-Defense (main) score 48

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:01.514511+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:18:22.612420+00:00, confidence not recorded.
  - readme: https://github.com/infosecn1nja/AD-Attack-Defense (fetched 2026-08-28T04:09:01.514511+00:00, sha 484e0a8b9991)
- Data as of 2026-08-30T08:39:29.467469+00:00.
