Attacking Active Directory from Linux means operating remotely β typically with no domain-joined machine. The toolset revolves around Impacket, NetExec (nxc), BloodHound-python, Certipy, Kerbrute, and Responder.
The main constraint is that you cannot run Windows-native tools directly β but nearly every critical attack has a Python/Linux equivalent.
| Topic | File |
|---|---|
| Enumeration & Discovery | enumeration |
| Kerberos Attacks | kerberos-attacks |
| Credential Attacks & Relay | credential-attacks |
| Delegation Attacks | delegation-attacks |
| Lateral Movement | lateral-movement |
| Domain & Forest Trusts | domain-trusts |
| Persistence | persistence |
Disclaimer: For educational purposes only. Unauthorized access to computer systems is illegal.