Active Directory
Kerbrute
Kerberos pre-auth enumeration and password spraying tool.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Validating usernames and careful password sprays against AD.
How
userenum with wordlist; passwordspray with lockout awareness.
Why
Kerberos user enum is quieter than SMB sometimes.
Commands & usage
kerbrute userenum -d domain.local --dc 10.0.0.10 users.txt
kerbrute passwordspray -d domain.local --dc 10.0.0.10 users.txt 'Welcome1'
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
Related in Active Directory
Impacket
Python collection for Windows network protocols (SMB, WMI, Kerberos, etc.).
CrackMapExec / NetExec
Swiss army knife for pentesting Windows/Active Directory networks (NetExec successor).
BloodHound / SharpHound / AzureHound
Maps Active Directory attack paths using graph theory.
Rubeus
C# toolset for Kerberos abuse (AS-REP, kerberoast, tickets, etc.).
enum4linux-ng
SMB/Windows enumeration tool wrapping common Samba tools.
SMBMap
Enumerates Samba share drives across networks with permissions.