whatisgithub

What is ad-attack-defense?

ridter/ad-attack-defense — explained in plain English

Analysis updated 2026-08-04 · repo last pushed 2018-11-19

3Audience · ops devopsComplexity · 1/5DormantSetup · easy

In one sentence

A curated list of links covering how hackers attack Active Directory networks and how defenders can protect them, organized by attack stages like discovery, credential theft, and lateral movement.

Mindmap

mindmap
  root((repo))
    What it does
      Maps attack stages
      Links to tools
      Links to articles
    Content areas
      Discovery
      Privilege escalation
      Credential dumping
      Lateral movement
    Use cases
      Red team training
      Blue team defense
      Incident response
    Audience
      Red teamers
      Blue teamers
      Security researchers
    Format
      Curated link list
      No software code
      External resources

Code map

Detail Auto

An interactive map of this repo's files and how they connect — its source is parsed live in your browser. Click Visualize to build it.

filefunction / class

What do people build with it?

USE CASE 1

Red teamers can find links to tools and tactics for simulating attacks on Active Directory networks.

USE CASE 2

Blue teamers can study attack stages to learn what alerts and defenses to set up.

USE CASE 3

Security learners can follow the attack path to understand how hackers move through corporate networks.

USE CASE 4

Incident responders can use the resource list to recognize and investigate specific attack techniques.

What is it built with?

Markdown

How does it compare?

ridter/ad-attack-defense000madz000/payload-test-api-route-handler0marildo/imago
Stars333
LanguageTypeScriptPython
Last pushed2018-11-19
MaintenanceDormant
Setup difficultyeasyeasyeasy
Complexity1/52/52/5
Audienceops devopsdevelopergeneral

Figures from each repo's GitHub metadata at analysis time.

How do you get it running?

Difficulty · easy Time to first run · 5min

No setup needed, it is a curated README of links to external security resources.

No license information is provided in this repository.

So what is it?

The ad-attack-defense repository is a curated knowledge base focused on Active Directory security. Active Directory is the system that most large organizations use to manage user accounts, permissions, and computers on their network. This project serves as a comprehensive guide for understanding how hackers attack these networks and how defenders can protect them. The content is organized into stages that mirror a hacker's typical path, like discovery, privilege escalation, credential dumping, and lateral movement. Instead of containing software code, the README is essentially an organized list of links to external articles, tools, and videos. It walks through each phase of an attack, providing resources on specific tactics, such as the Zerologon vulnerability, password spraying, or exploiting domain trusts, along with guidance on how to mitigate and detect these threats. This resource is built for security professionals working in "red team" and "blue team" roles. A red teamer (or penetration tester) simulates real-world attacks to find an organization's weaknesses, while a blue teamer focuses on defense, detection, and incident response. For example, a red teamer might use the links under "Lateral Movement" to understand how to move from one compromised machine to another, while a blue teamer would study the same resources to figure out what alarms to set up to catch that activity. The project is notable for how it pairs offensive and defensive perspectives side by side. By covering the full "kill chain", the sequence of steps an attacker takes, it helps defenders think like attackers and vice versa. The README doesn't go into detail on every linked resource itself, but serves as a high-level map pointing to deeper technical content across the security community.

Copy-paste prompts

Prompt 1
Help me set up a home Active Directory lab so I can practice the attack and defense techniques linked in the ad-attack-defense resource list.
Prompt 2
Using the attack stages from ad-attack-defense, walk me through how an attacker might go from initial discovery to lateral movement in an Active Directory environment.
Prompt 3
I want to build a detection checklist for my blue team based on the attack phases covered in ad-attack-defense. Help me create alerts for credential dumping and lateral movement.
Prompt 4
Summarize the Zerologon vulnerability and password spraying techniques referenced in ad-attack-defense, and explain how a defender would detect and mitigate each one.

Frequently asked questions

What is ad-attack-defense?

A curated list of links covering how hackers attack Active Directory networks and how defenders can protect them, organized by attack stages like discovery, credential theft, and lateral movement.

Is ad-attack-defense actively maintained?

Dormant — no commits in 2+ years (last push 2018-11-19).

What license does ad-attack-defense use?

No license information is provided in this repository.

How hard is ad-attack-defense to set up?

Setup difficulty is rated easy, with roughly 5min to a first successful run.

Who is ad-attack-defense for?

Mainly ops devops.

Open on GitHub → Ask about another repo

This repo across BitVibe Labs

Verify against the repo before relying on details.