# WADComs/WADComs.github.io

WADComs is an interactive cheat sheet, containing a curated list of offensive security tools and their respective commands, to be used against Windows/AD environments.

Repository: https://github.com/WADComs/WADComs.github.io
Canonical: https://ross.abutalabs.com/products/wadcomsgithubio
Homepage: https://wadcoms.github.io/
Language: HTML
License: GPL-3.0
License Family: copyleft
Topics: exploitation, windows, redteam, blueteam, wadcoms, cheatsheet, commands, enumeration, persistence, privilege-escalation
Last push: 2026-08-18T00:38:36+00:00

## Health v2 (maintenance only)
Score: 76/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 98, release rhythm 35, longevity 100
- inputs: {"age_days": 2104, "days_push": 16, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1713, forks 200 (observed 2026-08-28T04:05:25.819987+00:00)

## What it is
WADComs is an interactive cheat sheet website hosting a curated list of offensive security tools and their commands for attacking Windows and Active Directory environments. Users filter by credentials, services, attack type, and OS to get copy-pasteable command templates.

## Use cases
- find commands for enumerating an Active Directory domain
- look up exploitation commands when I have a username and password for a Windows box
- find privilege escalation tools for Windows shells
- get a quick command template for Kerberoasting
- find persistence techniques for Windows/AD environments
- filter offensive tools by what services are exposed like SMB or LDAP
- reference credential-based attack commands for red team engagements

## When to choose
- you need quick, vetted command references for Windows/AD offensive tooling
- you want an interactive filter similar to GTFOBins or LOLBAS
- you are a red teamer or pentester working Active Directory engagements
- you are a blue teamer studying what commands attackers may run

## When to avoid
- you need a runnable tool rather than a reference site
- you target non-Windows or non-AD environments
- you need defensive detection rules rather than attack commands
- you require guaranteed up-to-date tool syntax without verification

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, penetration-testing, documentation, developer-tools
- domain: security, penetration-testing, documentation
- platform: cross-platform
- tags: cheatsheet, active-directory, windows, red-team, offensive-security, interactive, gtfobins-inspired, command-line, web-server

## Member repositories
- WADComs/WADComs.github.io (main) score 76

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:25.819987+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:34:41.300410+00:00, confidence not recorded.
  - readme: https://github.com/WADComs/WADComs.github.io (fetched 2026-08-28T04:05:25.819987+00:00, sha d0f125479dcb)
  - homepage: https://wadcoms.github.io/ (fetched 2026-08-29T11:10:36.823798+00:00, sha 66f7ddc6f8c0)
- Data as of 2026-08-30T08:39:29.467469+00:00.
