# lkarlslund/Adalanche

Attack Graph Visualizer and Explorer (Active Directory) ...Who's *really* Domain Admin?

Repository: https://github.com/lkarlslund/Adalanche
Canonical: https://ross.abutalabs.com/products/adalanche
Homepage: https://www.netsection.com
Language: Go
License: AGPL-3.0
License Family: copyleft
Topics: blueteam, active-directory, activedirectory, acl, infosec, ldap, graph-theory, reconnaissance, acl-audit, ad-audit, ldap-audit
Last push: 2026-08-25T06:39:38+00:00

## Health v2 (maintenance only)
Score: 67/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 8, longevity 100
- inputs: {"age_days": 2156, "days_push": 8, "days_rel": 573, "gap_med": null, "n_releases_24m": 1}
- flags: no_readme
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2195, forks 202 (observed 2026-08-28T04:06:25.153439+00:00)

## What it is
Adalanche is an open-source Active Directory attack graph visualizer and explorer written in Go. It collects data via LDAP and SYSVOL, analyzes privilege escalation paths with a custom in-memory graph engine, and visualizes who can really become Domain Admin.

## Use cases
- find who can escalate to Domain Admin in Active Directory
- audit dangerous ACL misconfigurations in AD
- visualize attack paths in Active Directory infrastructure
- run LDAP queries to find vulnerable AD objects
- do risk-based remediation of AD privilege escalation paths
- audit Active Directory as a blue team without a graph database

## When to choose
- you need a download-and-run single binary AD attack path analyzer with no prerequisites
- you want graph-based visualization of AD escalation paths without learning a graph query language
- you need cross-platform (Windows/Linux/macOS) AD auditing using only a regular user account

## When to avoid
- you need cloud identity (Azure AD/Entra ID) attack path analysis rather than on-prem AD
- you want a persistent graph database or long-term monitoring rather than point-in-time analysis
- you need a stealthy red-team tool that avoids generating LDAP read traffic

## Facets
- artifact type: application
- maturity: active
- function: search-engine, data-visualization, security, nlp
- domain: security, osint, networking, developer-tools
- platform: windows, cross-platform, cli
- tags: active-directory, attack-graph, ldap, acl-audit, reconnaissance, blueteam, graph-analysis, infosec, linux, macos

## Member repositories
- lkarlslund/Adalanche (main) score 67

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:25.153439+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:47:15.142740+00:00, confidence not recorded.
  - homepage: https://www.netsection.com (fetched 2026-08-29T10:27:38.855825+00:00, sha 2b81636feae3)
  - site_page: https://www.netsection.com/features (fetched 2026-08-29T10:27:38.858400+00:00, sha c0e0dfeb6736)
- Data as of 2026-08-30T08:39:29.467469+00:00.
