Qianlitp/WatchAD
AD Security Intrusion Detection System observed · 2026-08-28
Health v2 · maintenance only
10/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases archived
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2505
- days_rel: n/a
- days_push: 1251
- n_releases_24m: 0
Adoption not part of the score
1321 stars · 299 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
WatchAD is an open-source Active Directory security intrusion detection system that analyzes Windows event logs (and optionally Kerberos network traffic) from domain controllers to detect AD attacks. It covers detections across discovery, credential dumping, lateral movement, privilege escalation, persistence, and defense evasion using rule matching, honeypot accounts, and historical behavior analysis.
Use cases
- detect kerberoasting and golden ticket attacks in active directory
- monitor domain controller event logs for intrusions
- detect ntlm relay and dcsync attacks
- set up honeypot accounts to catch attackers in AD
- blue team active directory threat detection
- detect privilege escalation and persistence in windows domains
When to choose
- you run a Windows Active Directory environment and need open-source AD-specific intrusion detection
- you want detection coverage for common AD attack techniques like Kerberoasting, DCShadow, and Skeleton Key
- you are a blue team looking for free alternatives to commercial AD monitoring
When to avoid
- you need the network-traffic-based (Kerberos traffic) detections, which are not included in the open-source release
- you need a actively developed tool - the project has seen limited recent activity
- your environment is not Windows Active Directory
Facets
application · maturity maintenance
monitoring alerting security logging security monitoring self-hosted python self-hosted active-directory intrusion-detection blue-team kerberos event-log-analysis ids linux docker
1 source
- readme: https://github.com/Qianlitp/WatchAD · fetched 2026-08-28 · 6362701e6cb5
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| Qianlitp/WatchAD | main | 10 |
For agents
markdown · JSON · MCP: product_card(name="Qianlitp/WatchAD")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem