Active Directory Control Paths Logo

Active Directory Control Paths

0
Free
Visit Website

Control paths in Active Directory are an aggregation of 'control relations' between entities of the domain (users, computers, groups, GPO, containers, etc.) which can be visualized as graphs and whose purpose is to answer questions like 'Who can get Domain Admins privileges?' or 'What resources can a user control?' and even 'Who can read the CEO's emails?'. Changes: - New workflow for all steps, automating neo4j setup and import. - Basic Cypher querying through Neo4j REST API, increasing performance. - New control paths added: Kerberos delegation, SCCM dumping utilities for local admins and sessions control paths. - Adding EXCHANGE permissions in v1.3 'Who Can Read the CEO's Emails Edition'. - Permissions extracted from AD Users, Mailbox/DB descriptors, RBAC, and MAPI folders. - Better resume features, nodes clustering (through OVALI) in v1.2.3. - New control paths added in v1.2.2: RoDC and LAPS. - Major code changes take place in v1.2, as it is now able to dump and analyze very large Active Directories without hogging too much RAM. Some very large ADs with over 1M objects and 150M ACEs have been processed.

FEATURES

ALTERNATIVES

A tool for privilege escalation within Linux environments by targeting vulnerabilities in SUDO usage.

Free

Secure and manage passwords across devices with Bitwarden's open-source, encrypted password manager.

Free

Okta Workforce Identity Cloud is an identity and access management platform that provides secure, streamlined access for an organization's workforce across various applications and resources.

Commercial

A tool for searching through public EBS snapshots for secrets, organized as an Elastic Beanstalk application.

Free

A library for forward compatibility with PHP password functions.

Free

An attacker can create a new IAM policy version and set it as the default version without requiring the iam:SetDefaultPolicyVersion permission.

Free

CLI for generating AWS IAM policy documents, SAM policy templates or SAM Connectors

Free

IAM Zero detects IAM issues and suggests least-privilege policies for AWS and other cloud platforms.

Free

PINNED