Why should I use ADProbe? How is it different?

๐Ÿ”’ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—•๐—ถ๐˜๐˜€

๐—ช๐—ต๐˜† ๐˜€๐—ต๐—ผ๐˜‚๐—น๐—ฑ ๐—œ ๐˜‚๐˜€๐—ฒ ๐—”๐——๐—ฃ๐—ฟ๐—ผ๐—ฏ๐—ฒ? ๐—›๐—ผ๐˜„ ๐—ถ๐˜€ ๐—ถ๐˜ ๐—ฑ๐—ถ๐—ณ๐—ณ๐—ฒ๐—ฟ๐—ฒ๐—ป๐˜?

That is something people ask me quite often. So let me explain why I createdย ADProbeย in the first place.

โžก๏ธ ADProbe started during my ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜† ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ฎ๐˜€๐˜€๐—ฒ๐˜€๐˜€๐—บ๐—ฒ๐—ป๐˜๐˜€. At the beginning, it was not really a โ€œtoolโ€. It was just me using PowerShell to check a few things faster.

Then I kept ๐—ฎ๐—ฑ๐—ฑ๐—ถ๐—ป๐—ด ๐—บ๐—ผ๐—ฟ๐—ฒ ๐—ฐ๐—ต๐—ฒ๐—ฐ๐—ธ๐˜€. More environments. More assessments. More repeated findings. More things I wanted to verify quickly and consistently.

๐—”๐˜ ๐˜€๐—ผ๐—บ๐—ฒ ๐—ฝ๐—ผ๐—ถ๐—ป๐˜, ๐—œ ๐—ต๐—ฎ๐—ฑ ๐˜๐—ผ ๐—ฑ๐—ฒ๐—ฐ๐—ถ๐—ฑ๐—ฒ:

Should I use an existing third-party AD assessment tool, or should I keep building my own? I tried ๐—บ๐˜‚๐—น๐˜๐—ถ๐—ฝ๐—น๐—ฒ ๐—ฒ๐˜…๐—ถ๐˜€๐˜๐—ถ๐—ป๐—ด ๐˜๐—ผ๐—ผ๐—น๐˜€. And donโ€™t get me wrong – many of them are really good. But I had two problems.

1๏ธโƒฃ ๐—ง๐—ผ๐—ผ ๐—บ๐˜‚๐—ฐ๐—ต ๐—ป๐—ผ๐—ถ๐˜€๐—ฒ

Some tools produced a lot of findings, but many of them were not really useful for the type of AD security assessment I was doing. I donโ€™t want hundreds of findings just to make the report look bigger. I want findings I can explain, defend, and connect to real risk.

2๏ธโƒฃ ๐—ง๐—ฟ๐˜‚๐˜€๐˜ ๐—ฎ๐—ป๐—ฑ ๐˜๐—ฟ๐—ฎ๐—ป๐˜€๐—ฝ๐—ฎ๐—ฟ๐—ฒ๐—ป๐—ฐ๐˜†

In customer environments, I try to avoid running third-party compiled tools whenever possible. Not because they are automatically bad. But because I prefer to know exactly what I am running, what it queries, and what it does.

โœ… ๐—ง๐—ต๐—ฎ๐˜ ๐—ถ๐˜€ ๐—ต๐—ผ๐˜„ ๐—”๐——๐—ฃ๐—ฟ๐—ผ๐—ฏ๐—ฒ ๐˜€๐˜๐—ฎ๐—ฟ๐˜๐—ฒ๐—ฑ.

A simple PowerShell-based tool for checking Active Directory vulnerabilities, misconfigurations, and persistence methods attackers may leave behind.

๐—™๐—ฟ๐—ผ๐—บ ๐—บ๐˜† ๐—ฝ๐—ผ๐—ถ๐—ป๐˜ ๐—ผ๐—ณ ๐˜ƒ๐—ถ๐—ฒ๐˜„, ๐˜๐—ต๐—ฒ ๐—บ๐—ฎ๐—ถ๐—ป ๐—ฏ๐—ฒ๐—ป๐—ฒ๐—ณ๐—ถ๐˜๐˜€ ๐—ฎ๐—ฟ๐—ฒ:

๐Ÿ”น less noise

๐Ÿ”น focused on real AD security assessment needs

๐Ÿ”น one simple PowerShell script (one file only)

๐Ÿ”น transparent checks you can review

๐Ÿ”น easy to extract only the queries you need

And I think the โ€œsimple PowerShell scriptโ€ part is ๐—ถ๐—บ๐—ฝ๐—ผ๐—ฟ๐˜๐—ฎ๐—ป๐˜. You do not need to blindly trust it. You can open it. Read it. Verify it.

โžก๏ธ ๐—˜๐˜…๐˜๐—ฟ๐—ฎ๐—ฐ๐˜ only the AD queries you want.

Right now, ADProbe containsย ๐Ÿฑ๐Ÿญ ๐—ฐ๐—ต๐—ฒ๐—ฐ๐—ธ๐˜€ย for Active Directory vulnerabilities, misconfigurations, and persistence methods. It is free, transparent and built specifically for needs of AD security assessments.

๐Ÿ”— https://horizon-secured.com/tools/

๐—ฃ๐—น๐—ฒ๐—ฎ๐˜€๐—ฒ, let me know what you think about it.