Control paths in Active Directory are an aggregation of 'control relations' between entities of the domain (users, computers, groups, GPO, containers, etc.) which can be visualized as graphs and whose purpose is to answer questions like 'Who can get Domain Admins privileges?' or 'What resources can a user control?' and even 'Who can read the CEO's emails?'. Changes: - New workflow for all steps, automating neo4j setup and import. - Basic Cypher querying through Neo4j REST API, increasing performance. - New control paths added: Kerberos delegation, SCCM dumping utilities for local admins and sessions control paths. - Adding EXCHANGE permissions in v1.3 'Who Can Read the CEO's Emails Edition'. - Permissions extracted from AD Users, Mailbox/DB descriptors, RBAC, and MAPI folders. - Better resume features, nodes clustering (through OVALI) in v1.2.3. - New control paths added in v1.2.2: RoDC and LAPS. - Major code changes take place in v1.2, as it is now able to dump and analyze very large Active Directories without hogging too much RAM. Some very large ADs with over 1M objects and 150M ACEs have been processed.
FEATURES
ALTERNATIVES
CLI for generating AWS IAM policy documents, SAM policy templates or SAM Connectors
A comprehensive resource for securing Active Directory, including attack methods and effective defenses.
Provision, manage, and renew SSL/TLS certificates for your AWS resources with AWS Certificate Manager.
A tool for privilege escalation within Linux environments by targeting vulnerabilities in SUDO usage.
A list of disposable email domains to detect or block disposable accounts
Encrypt Kubernetes Secrets into SealedSecrets for safe storage and controlled decryption within the cluster.
Airlock Secure Access Hub is an integrated security platform that combines identity and access management with web application and API protection to secure digital applications while maintaining user experience.
PINNED

InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.

Mandos Brief Newsletter
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

Kriptos
An AI-driven data classification and governance platform that automatically discovers, analyzes, and labels sensitive information while providing risk management and compliance capabilities.

System Two Security
An AI-powered platform that automates threat hunting and analysis by processing cyber threat intelligence and generating customized hunt packages for SOC teams.

Aikido Security
Aikido is an all-in-one security platform that combines multiple security scanning and management functions for cloud-native applications and infrastructure.

Permiso
Permiso is an Identity Threat Detection and Response platform that provides comprehensive visibility and protection for identities across multiple cloud environments.

Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.

Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.