Active Directory Control Paths Logo

Active Directory Control Paths

0
Free
Updated 11 March 2025
Visit Website

Control paths in Active Directory are an aggregation of 'control relations' between entities of the domain (users, computers, groups, GPO, containers, etc.) which can be visualized as graphs and whose purpose is to answer questions like 'Who can get Domain Admins privileges?' or 'What resources can a user control?' and even 'Who can read the CEO's emails?'. Changes: - New workflow for all steps, automating neo4j setup and import. - Basic Cypher querying through Neo4j REST API, increasing performance. - New control paths added: Kerberos delegation, SCCM dumping utilities for local admins and sessions control paths. - Adding EXCHANGE permissions in v1.3 'Who Can Read the CEO's Emails Edition'. - Permissions extracted from AD Users, Mailbox/DB descriptors, RBAC, and MAPI folders. - Better resume features, nodes clustering (through OVALI) in v1.2.3. - New control paths added in v1.2.2: RoDC and LAPS. - Major code changes take place in v1.2, as it is now able to dump and analyze very large Active Directories without hogging too much RAM. Some very large ADs with over 1M objects and 150M ACEs have been processed.

FEATURES

SIMILAR TOOLS

A simple drop-in library for managing users, permissions, and groups in your application.

Free

A secret keeper that stores secrets in DynamoDB, encrypted at rest.

Free

Securely store and access AWS credentials in a development environment.

Free

A list of Windows privilege escalation techniques, categorized and explained in detail.

Free

Akamai Identity Cloud is a CIAM solution that manages customer identities, enhances user experiences, and ensures data protection and regulatory compliance for high-volume consumer brands.

Commercial

A powerful tool that enables organizations to discover, manage, and secure privileged access, helping to reduce the risks associated with privileged accounts and activities.

Commercial

Permiso is an Identity Threat Detection and Response platform that provides comprehensive visibility and protection for identities across multiple cloud environments.

Commercial

Airlock Secure Access Hub is an integrated security platform that combines identity and access management with web application and API protection to secure digital applications while maintaining user experience.

Commercial

Provision, manage, and renew SSL/TLS certificates for your AWS resources with AWS Certificate Manager.

Free
CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

VAT: NL005301434B12

Copyright © 2025 - All rights reserved