MSADPT is an evidence-driven Active Directory security assessment and penetration-testing platform for authorized environments. Clone the repository to a local folder that is not synchronized to a cloud-storage service when unredacted evidence may be produced.
git clone https://github.com/rolling-code/MSADPT.git
Set-Location .\MSADPTRun the release preflight before an assessment:
.\Tests\Offline\Test-MSADPTPublicRelease.ps1Start or resume an assessment through the unified entry point:
.\Invoke-MSADPT.ps1 -Mode Audit.\Invoke-MSADPT.ps1 -Mode Resume -EngagementDirectory .\Engagements\<engagement-name>The public release candidate is designed for authorized testing. Review the displayed target, port, protocol, authentication, change, and cleanup plan before permitting live stages.
MSADPT follows a deterministic, evidence-first workflow:
- Discover the environment and available tools.
- Display planned network operations before execution.
- Collect structured evidence using deterministic modules.
- Correlate candidates and validate pipeline integrity.
- Select bounded behavioral validators only when prerequisites justify them.
- Record cleanup and evidence-manifest status separately.
- Produce one consolidated HTML report with links to local evidence.
- Resume from completed evidence instead of rerunning expensive stages.
Run the default authorized audit workflow:
.\Invoke-MSADPT.ps1 -Mode AuditRun offline analysis against existing evidence:
.\Invoke-MSADPT.ps1 -Mode Analyze -EngagementDirectory .\Engagements\<engagement-name>Preview the planned modules and network activity without executing live stages:
.\Invoke-MSADPT.ps1 -Mode PlanThe project currently includes reusable components for:
- Active Directory and domain-controller discovery
- AD CS collection and ESC1 through ESC16 prerequisite correlation
- AD CS runtime configuration and candidate planning
- Kerberos, SPN, AS-REP, delegation, and controlled TGS validation
- LDAP signing, channel-binding, SMB signing, and relay-prerequisite analysis
- MachineAccountQuota behavioral validation with cleanup verification
- Active Directory ACL collection, semantic correlation, integrity auditing, and transitive path analysis
- SMB reachability, signing, share enumeration, and resumable continuation
- SYSVOL and NETLOGON metadata discovery and replicated-path deduplication
- Bounded, redacted P1 and P2 content analysis without script execution
- In-memory PKCS#12/PFX inspection with null and empty-password imports only, ephemeral key storage, no private-key export, no authentication, and no PFX retention
- Snapshot comparison, evidence manifests, structured operational errors, and offline regression tests
- Optional local Ollama integration as a non-authoritative reasoning layer
Ollama is optional. Deterministic collectors and validators remain authoritative. Ollama may explain evidence, prioritize already-established candidates, and suggest bounded next steps. Ollama must not invent findings, claim that a command ran, or override deterministic dispositions.
Install Ollama from its official distribution, then install a local coding or reasoning model supported by the operator's hardware. Configure the local endpoint and model through the MSADPT policy or integration settings. Do not place credentials, raw secrets, private keys, or unredacted evidence in prompts.
Example connectivity test:
.\Tests\Offline\Test-MSADPTOllamaIntegration.ps1If Ollama is unavailable, MSADPT continues with deterministic collection, correlation, and reporting.
MSADPT distinguishes among:
- Confirmed
- Likely or probable
- Inconclusive
- Not detected
- Not applicable
Scanner matches, fingerprints, prerequisite values, and static patterns are leads. A vulnerability is confirmed only when the affected component and conditions are present and the central security impact is reproduced with captured evidence.
Every module should report these stages separately where applicable:
- Planning
- Discovery
- Network operation
- Acquisition
- Parsing
- Semantic analysis
- Behavioral validation
- Impact reproduction
- Cleanup
- Evidence serialization
- Manifest verification
MSADPT/
├── Invoke-MSADPT.ps1
├── Analysis/
├── Catalogs/
├── Common/
├── Controller/
├── Integrations/
├── Modules/
├── Policies/
├── Schemas/
├── Tests/
└── docs/
Runtime engagement evidence, transcripts, generated test output, local session state, backups, internal migration files, and organization-specific material are intentionally excluded from the public repository.
- Windows PowerShell 5.1 or PowerShell 7, depending on the selected module
- ActiveDirectory PowerShell module for ADWS-based collection stages
- Network access to explicitly selected assessment targets for live stages
- Nmap for modules that collect Nmap-backed protocol evidence
- Appropriate authorization and credentials for the selected environment
- Optional Ollama installation for local, non-authoritative reasoning
- Environment-neutral source code and examples
- No organization names, domains, hostnames, identities, addresses, or evidence
- No persistent private-key or credential material
- No automatic password guessing
- No exploit or write operation without an explicit bounded validator, rollback plan, and cleanup verification
- Resume completed work instead of repeating broad scans
- One consolidated report backed by local structured evidence
MSADPT is under active development. Modules that are present in the repository have different maturity levels. Run the release preflight and review the module registry before using live functionality.
Use MSADPT only in environments where testing is authorized. Contributions should include parser validation, offline tests, sanitized fixtures, explicit safety boundaries, and structured evidence outputs.