Skip to main content
Coverage · v2.0

Active Directory and OSINT, in the same assessment

Internal path enumeration and external footprint discovery join the same engine, so the route from a leaked credential to a domain controller is one graph rather than two reports.

Version
2.0
Released
December 14, 2025
New features
4
Category
Coverage

What's new

Features and improvements in this update

New features

4
  • Active Directory attack path enumeration

    Users, groups, ACLs, delegations, trusts and certificate templates are collected read-only and rendered as a reachability graph, with every route to Tier 0 enumerated and each hop validated.

  • Kerberos and certificate abuse checks

    Kerberoastable service accounts, unconstrained and constrained delegation, AS-REP roasting and misconfigured certificate templates are tested directly rather than inferred from settings.

  • Lockout-aware credential testing

    Attempts respect the domain lockout policy with a configurable margin and check account state before each try, which is what makes credential testing possible against production directories.

  • OSINT footprint discovery

    Subdomains, certificate transparency records, exposed credentials in public breach corpora, code repository leakage and cloud storage exposure are collected into the same asset inventory the active scans use.

Improvements

1
  • External findings feed internal paths

    A credential found in a public leak is tested as an entry point to the directory graph, which is how the two modules produce one attack path instead of two unrelated observations.

Benefits

What it changes for you

Stated as work removed rather than capability added, the only version of a benefit that can be checked.

  • The path that matters spans both sides

    Real intrusions start outside and end inside. Reporting the external exposure and the internal path separately leaves the reader to join them, which is the step that usually does not happen.

  • Internal testing that operations will agree to

    Read-only collection and lockout-aware credential testing remove the two objections that block most internal assessments before they start.

  • Choke points instead of a misconfiguration list

    Once paths are enumerated, the changes that sit on many of them can be identified, which is a remediation plan rather than a backlog.

Upgrade

Getting it

Getting this update

Requires a domain-joined collector or read-only directory credentials. OSINT discovery runs without any additional access.

pip install --upgrade aiptx

See Your Attack Surface in Real-Time

Run a comprehensive VAPT assessment powered by advanced security tools. Get actionable findings in hours, not weeks. No credit card required.