Active Directory and OSINT, in the same assessment
Internal path enumeration and external footprint discovery join the same engine, so the route from a leaked credential to a domain controller is one graph rather than two reports.
- Version
- 2.0
- Released
- December 14, 2025
- New features
- 4
- Category
- Coverage
What's new
Features and improvements in this update
New features
4Active Directory attack path enumeration
Users, groups, ACLs, delegations, trusts and certificate templates are collected read-only and rendered as a reachability graph, with every route to Tier 0 enumerated and each hop validated.
Kerberos and certificate abuse checks
Kerberoastable service accounts, unconstrained and constrained delegation, AS-REP roasting and misconfigured certificate templates are tested directly rather than inferred from settings.
Lockout-aware credential testing
Attempts respect the domain lockout policy with a configurable margin and check account state before each try, which is what makes credential testing possible against production directories.
OSINT footprint discovery
Subdomains, certificate transparency records, exposed credentials in public breach corpora, code repository leakage and cloud storage exposure are collected into the same asset inventory the active scans use.
Improvements
1External findings feed internal paths
A credential found in a public leak is tested as an entry point to the directory graph, which is how the two modules produce one attack path instead of two unrelated observations.
Benefits
What it changes for you
Stated as work removed rather than capability added, the only version of a benefit that can be checked.
The path that matters spans both sides
Real intrusions start outside and end inside. Reporting the external exposure and the internal path separately leaves the reader to join them, which is the step that usually does not happen.
Internal testing that operations will agree to
Read-only collection and lockout-aware credential testing remove the two objections that block most internal assessments before they start.
Choke points instead of a misconfiguration list
Once paths are enumerated, the changes that sit on many of them can be identified, which is a remediation plan rather than a backlog.
Upgrade
Getting it
Getting this update
Requires a domain-joined collector or read-only directory credentials. OSINT discovery runs without any additional access.
pip install --upgrade aiptxRelated
Other updates
Business logic testing, as a first-class scan type
Twenty-nine abuse patterns (race conditions, IDOR, price manipulation, workflow bypass) now run as their own scan phase, against the class of flaw that has no CVE and no signature.
Read90+ SAST rules across Python, JavaScript, Java and Go
Static analysis with rules written against real exploit conditions rather than pattern matches, wired to the same validation and ranking as everything else.
ReadDAST for applications that stopped being pages
GraphQL, WebSocket and single-page application scanners ship together, so the parts of a modern application a crawler never reached are now tested like the rest of it.
ReadSee Your Attack Surface in Real-Time
Run a comprehensive VAPT assessment powered by advanced security tools. Get actionable findings in hours, not weeks. No credit card required.