NOOB2ROOT

Tools Active Directory

ADReaper

Active Directory and Windows privilege-escalation recon, without touching exploitation

Python · LDAP

Enumerates Active Directory attack surface over LDAP — Kerberoasting and ASREPRoasting candidates, delegation, ACLs, trusts and GPOs — then ranks what it finds and prints the exact command to run next.

Recon only. It maps the ground and hands you the commands; it does not exploit anything itself, which keeps it safe to run early in an engagement.