ADscan

August 3, 2026 · View on GitHub

Every technique below is implemented in ADscan and mapped to MITRE ATT&CK.

How to read the Status column. ADscan validates exposure — it proves whether a path to compromise exists. It does not test your defensive stack, and it never claims a security product blocked anything.

  • Executed — ADscan runs the technique end to end and proves the outcome.
  • Detected — ADscan identifies and maps the exposure but does not execute it.
  • Detected · not executed (safety) — ADscan deliberately refuses to run it because it is destructive or disruptive to a production directory.
  • Observed (attack-path pivot) — a condition ADscan observes and chains into an attack path rather than a standalone step it runs.

This page is generated from the product catalog by scripts/sync_technique_count.py. Do not edit the table by hand; edit the catalog and regenerate.

103 techniques across 14 categories · 70 executed end to end · AD CS ESC1–ESC17 · 79 reported finding types.

ACL / ACE Abuse (18)

TechniqueWhat ADscan doesStatusMITRE ATT&CK
Add Member to GroupAdd arbitrary members to target groupExecutedT1098
Add Self to GroupSelf-add to controlled group under permissive ACLExecutedT1098
All Extended RightsBroad extended rights over directory objectExecutedT1098
Force Change PasswordReset target account password without current passwordExecutedT1098
GenericAllFull object control over target principal/objectExecutedT1098
GenericWriteWrite permissions over target object attributesExecutedT1098
Object OwnershipObject ownership grants implicit GenericAll-equivalent rightsExecutedT1222.001
RODC Password Replication Policy ControlModify the RODC password-replication policy on the RODC computer objectObserved (attack-path pivot)T1098
Read LAPS PasswordRead LAPS local administrator passwordExecutedT1555
Read gMSA PasswordRead gMSA managed password materialExecutedT1555
Shadow Credentials (Key Credential Link)Write msDS-KeyCredentialLink to add shadow credentialsExecutedT1649
Sync LAPS PasswordRead/replicate LAPS password materialDetectedT1555
Writable SMB PathTheoretical write access to an SMB share/path that can host attack payloadsObserved (attack-path pivot)T1105
Write Account RestrictionsModify account-restriction property sets on the target user/computer objectExecutedT1098
Write Logon ScriptWrite the user's logon script path to attacker-controlled contentExecutedT1098
Write SPNSet SPN to force kerberoastable ticket generationExecutedT1558.003
WriteDACLRewrite ACLs to grant further privilegesExecutedT1222.001
WriteOwnerTake ownership to unlock privilege escalationExecutedT1222.001

AD CS — Certificate Services (17)

TechniqueWhat ADscan doesStatusMITRE ATT&CK
AD CS ESC1Enroll exploitable template and authenticate as targetExecutedT1649
AD CS ESC10ADCS ESC10 privilege escalation pathDetectedT1649
AD CS ESC11ADCS ESC11 privilege escalation pathExecutedT1649
AD CS ESC13ADCS ESC13 effective linked-group membership pathExecutedT1649
AD CS ESC14ADCS ESC14 privilege escalation pathExecutedT1649
AD CS ESC15ADCS ESC15 privilege escalation pathExecutedT1649
AD CS ESC16ADCS ESC16 privilege escalation pathDetectedT1649
AD CS ESC17ADCS ESC17 privilege escalation pathDetectedT1557
AD CS ESC2ADCS ESC2 privilege escalation pathExecutedT1649
AD CS ESC3Use enrollment agent cert to request impersonation certsExecutedT1649
AD CS ESC4Modify template permissions/configuration for abuseExecutedT1649
AD CS ESC5 — Vulnerable PKI Object Access ControlADCS ESC5 privilege escalation pathExecutedT1649
AD CS ESC6ADCS ESC6 privilege escalation pathExecutedT1649
AD CS ESC7ADCS ESC7 privilege escalation pathExecutedT1649
AD CS ESC8ADCS ESC8 privilege escalation pathExecutedT1649
AD CS ESC9ADCS ESC9 privilege escalation pathExecutedT1649
Coerce and Relay NTLM to AD CS (ESC8)Coerce NTLM authentication and relay it to ADCS endpointsExecutedT1187

Authentication Coercion (3)

TechniqueWhat ADscan doesStatusMITRE ATT&CK
DFSCoerceCoerce machine authentication via DFS endpoint behaviorDetectedT1187
PetitPotamMS-EFSRPC coercion path (PetitPotam)DetectedT1187
PrinterBug (MS-RPRN)Spooler coercion path (PrinterBug)DetectedT1187

Collection (1)

TechniqueWhat ADscan doesStatusMITRE ATT&CK
MSSQL OPENROWSET Bulk ReadSQL Server can read the raw content of any file the SQL Server service account can access on its host, without executing a single operating-system command. Any principal holding ADMINISTER BULK OPERATIONS — sysadmin, the bulkadmin fixed server role, an explicit grant, or a linked-server login mapping that lands on the same permission remotely — can pull configuration files, backup files, and scripts off the host and recover any credentials or connection strings stored in them.ExecutedT1005

Credential Access (15)

TechniqueWhat ADscan doesStatusMITRE ATT&CK
DCSyncReplicate AD secrets remotely from domain controllerExecutedT1003.006
DPAPI Secret ExtractionCredential extraction from DPAPI-protected materialExecutedT1555.004
DS-Replication-Get-ChangesPartial replication right; combined with GetChangesAll enables DCSyncDetectedT1003.006
DS-Replication-Get-Changes-AllExtended replication right; combined with GetChanges enables DCSyncDetectedT1003.006
DS-Replication-Get-Changes-In-Filtered-SetReplication right over filtered attribute set dataDetectedT1003.006
Domain Password ReuseDomain account credential reuse pivot through clustered shared secret materialObserved (attack-path pivot)T1078.002
LLMNR/NBT-NS Poisoning and NetNTLMv2 RecoveryBroadcast name-resolution poisoning to NetNTLMv2 capture and offline crack: an unauthenticated attacker on the same local network segment as the victim answers LLMNR, NBT-NS, and mDNS name-resolution requests with a rogue address, causing the victim to authenticate to the attacker. The captured NetNTLMv2 challenge/response is then cracked offline to recover the user's cleartext password, converting a wire capture into a usable domain credential without any prior access.ExecutedT1557.001
LSA Secrets ExtractionCredential extraction from LSA secretsExecutedT1003.004
LSASS Credential ExtractionCredential extraction from LSASS memoryExecutedT1003.001
Local-to-Domain Credential ReuseCredential reuse pivot from local credential material to domain identityObserved (attack-path pivot)T1078.002
MSSQL NetNTLMv2 TheftA SQL sysadmin (or any user with EXECUTE rights on xp_dirtree / xp_fileexist) can force the SQL Server service account to authenticate to an attacker-controlled SMB share, capturing its NTLMv2 response hash. If the service account is a domain user, the hash can be cracked offline or relayed to authenticate as that account on other network resources.ExecutedT1557.001
RODC krbtgt Secret ExtractionExtract the per-RODC krbtgt secret from the compromised RODCExecutedT1003
Readable SharePrincipal has read access to a network SMB shareExecutedT1039
Shadow Credentials PresentExisting shadow credentials allow PKINIT authentication and NT hash retrievalExecutedT1606.002
TimeroastingOffline crack MS-SNTP challenge material from machine accountsExecutedT1110.002

Delegation Abuse (4)

TechniqueWhat ADscan doesStatusMITRE ATT&CK
Coercion to TGT (Unconstrained Delegation)Coerce a target into providing a usable TGT for delegation abuseDetectedT1187
Constrained DelegationAbuse AllowedToDelegate paths to impersonate users to delegated servicesExecutedT1558
Resource-Based Constrained Delegation (inbound)Resource-based constrained delegation attack pathExecutedT1134.001
SPN-JackingCompromise a computer by hijacking a delegated SPN: move the SPN the principal can delegate to onto the target computer, then abuse constrained delegation (S4U) with protocol transition to mint a service ticket against the target as a privileged userExecutedT1558.003

Execution (1)

TechniqueWhat ADscan doesStatusMITRE ATT&CK
xp_cmdshell ExecutionThe SQL Server service can execute operating-system commands on its host when a session holds sysadmin. Any principal that reaches sysadmin on the instance — a direct sysadmin login, or a linked-server login mapping that lands as a sysadmin login on the remote instance — can therefore run commands on the host as the SQL Server service account, a full host code-execution capability.ExecutedT1059

Initial Access (9)

TechniqueWhat ADscan doesStatusMITRE ATT&CK
Anonymous LDAP BindAnonymous LDAP bind entry vectorDetectedT1087.002
Blank PasswordBlank-password entry vectorExecutedT1110.001
Credentials in User DescriptionCredentials recovered from LDAP user description fieldsDetectedT1087.002
Group Policy Preferences PasswordCredentials recovered from Group Policy Preferences artifactsDetectedT1552.006
Password SprayingPassword spraying entry vectorExecutedT1110.003
Password in FileCredentials discovered in host filesystem artifacts after service accessDetectedT1552.001
Password in ShareCredentials discovered in SMB share contentDetectedT1552.001
Pre-Windows 2000 Computer AccountPre2k computer-account password entry vectorExecutedT1110.003
Username as PasswordUsername-as-password entry vectorExecutedT1110.003

Kerberos Attacks (4)

TechniqueWhat ADscan doesStatusMITRE ATT&CK
AS-REP RoastingOffline crack AS-REP material from users without preauthExecutedT1558.004
KerberoastingOffline crack service ticket material for credential recoveryExecutedT1558.003
Kerberos Key List (RODC)Use the forged RODC golden ticket to request Key List data from a writable domain controllerExecutedT1558
RODC Golden TicketForge a reusable RODC golden ticket from recovered per-RODC krbtgt materialExecutedT1558.001

Known CVEs (5)

TechniqueWhat ADscan doesStatusMITRE ATT&CK
MS14-068 / Kerberos PAC ForgeryMSEven coercion-style authentication trigger pathDetectedT1187
MS17-010 (EternalBlue)EternalBlue SMBv1 remote code execution pathDetectedT1210
PrintNightmarePrintNightmare privileged code execution pathDetected · not executed (safety)T1068
Zerologon (CVE-2020-1472)Netlogon cryptographic flaw exploitation pathDetected · not executed (safety)T1210
noPac (CVE-2021-42278/42287)NoPac domain takeover pathDetected · not executed (safety)T1068

Lateral Movement (11)

TechniqueWhat ADscan doesStatusMITRE ATT&CK
DCOM ExecutionRemote command execution capability over DCOMDetectedT1021.003
Full Control SharePrincipal has full control over a network SMB shareExecutedT1570
Guest SessionGuest SMB session accepted, enabling unauthenticated share accessExecutedT1135
Local Admin Password ReuseCredential reuse pivot between hosts sharing local admin credentialsObserved (attack-path pivot)T1078.003
Local Admin RightsAdministrative access from one principal to a hostExecutedT1021.002
MSSQL AccessAuthenticated access over MSSQL without confirmed sysadmin-level controlExecutedT1078
MSSQL Linked Server Lateral MovementA SQL Server linked server relationship allows an attacker with sysadmin access on the source instance to execute arbitrary SQL on a second SQL Server instance (the linked target). This effectively extends the attack surface: each linked server hop can be chained with local privilege escalation (SeImpersonate or token theft) to achieve SYSTEM on additional hosts.Observed (attack-path pivot)T1210
MSSQL SysadminAdministrative access over MSSQL control surfaceExecutedT1078
PowerShell Remoting AccessRemote command execution capability over WinRM/PowerShellExecutedT1021.006
RDP AccessInteractive login capability via RDPExecutedT1021.001
Writable SharePrincipal has write access to a network SMB shareExecutedT1570

NTLM Relay (3)

TechniqueWhat ADscan doesStatusMITRE ATT&CK
NetNTLMv1 Offline RecoveryNTLMv1 offline crack: a domain user coerces the victim computer, captures its NTLMv1 response, and cracks it offline to recover the victim's machine account NT hash. The most universal NTLMv1 avenue, independent of relay viability, LDAP signing, channel binding, ADCS, or DC count.DetectedT1187
NetNTLMv1 Relay to RBCDNTLMv1 coerce-and-relay to RBCD: a domain user coerces the victim computer, relays its NTLMv1 authentication to the DC, configures resource-based constrained delegation, and obtains local administrator access on the victim via S4U.ExecutedT1187
NetNTLMv1 Relay to Shadow CredentialsNTLMv1 coerce-and-relay to Shadow Credentials: a domain user coerces the victim computer, relays its NTLMv1 authentication to the DC, writes a key credential, and recovers the victim's machine NT hash via PKINIT.ExecutedT1187

NTLM Weaknesses (1)

TechniqueWhat ADscan doesStatusMITRE ATT&CK
NetNTLMv1 EnabledNTLMv1 authentication enabled on the host (LmCompatibilityLevel < 3). The host's NTLMv1 response can be coerced and relayed or cracked to a machine NT hash.Observed (attack-path pivot)T1556

Privilege Escalation (11)

TechniqueWhat ADscan doesStatusMITRE ATT&CK
Backup Operators EscalationDomain compromise via Backup Operators: remote registry hive extraction → DC machine account hashExecutedT1003.002
DnsAdmins AbusePotential domain compromise path via DNSAdmins abuseDetected · not executed (safety)T1543.003
MSSQL Login ImpersonationA low-privilege SQL login that has been granted IMPERSONATE rights on a higher-privileged login (e.g. 'sa') can assume that identity within the SQL Server session using EXECUTE AS LOGIN. This effectively grants sysadmin access, enabling xp_cmdshell execution, CLR assembly loading, and all other sysadmin capabilities, without knowing the target login's password.ExecutedT1078.002
MSSQL SeImpersonate EscalationThe SQL Server service account's SeImpersonatePrivilege allows escalating to NT AUTHORITY\SYSTEM on the database server via a CLR stored procedure. No file is written to disk: the exploit assembly is loaded directly into SQL Server memory as a hexadecimal literal, bypassing AV write-time scanning.ExecutedT1134.001
MSSQL TRUSTWORTHY Database EscalationA TRUSTWORTHY database owned by a sysadmin account allows any user with db_owner rights (or EXECUTE AS USER='dbo') to escalate to effective sysadmin server-wide. When EXECUTE AS USER impersonates the database owner context inside a TRUSTWORTHY database, SQL Server grants server-level permissions equivalent to the database owner's server role, giving sysadmin access to any db_owner in that database.ExecutedT1078.002
MSSQL Token Theft EscalationEven when SeImpersonatePrivilege has been removed from the SQL Server process token (a common hardening measure), the original service startup token stored in LSASS retains the privilege. A CLR stored procedure recovers this token via SMB loopback named pipe authentication (Forshaw shared logon session technique) and escalates to NT AUTHORITY\SYSTEM. This bypass is architectural. Removing the privilege from the process token is insufficient.ExecutedT1134.001
Print Operators AbusePotential escalation path unlocked by Print Operators membershipDetectedT1547.006
Privileged Group ControlDirect control achieved through membership in a terminal privileged groupDetectedT1098
Privileged Session AbuseHigh-value user session observed on a non-Tier-0 computer that can be abused for scheduled-task impersonationExecutedT1053.005
RODC Credential CachingPrepare RODC credential caching by modifying the RODC password-replication policyExecutedT1098
Scheduled Task ExecutionImpersonate a logged-on user by registering a scheduled task whose principal is that user's interactive logon sessionExecutedT1053.005