linWinPwn is a free, open source threat detection & response project written in Shell and released under MIT. It has 2,224 GitHub stars, 311 forks and 0 open issues, and was last pushed 7 days ago. On this registry it ranks #39 of 58 tracked projects in Threat Detection & Response, with 5 head-to-head comparisons available.

What is linWinPwn?

linWinPwn is a bash script that wraps and streamlines a large collection of Active Directory penetration-testing tools on Linux, aimed at security testers who work in Active Directory environments.

What it is

linWinPwn is a command-line bash script for Active Directory penetration testing on Linux. It acts as a single interactive front end over a wide toolchain — impacket, bloodhound, netexec, enum4linux-ng, ldapdomaindump, lsassy, smbmap, kerbrute, certipy, silenthound, bloodyAD, DonPAPI and others — covering enumeration over LDAP, RPC, ADCS, MSSQL, Kerberos and SCCM, along with vulnerability checks, object modifications and password dumping. It runs either as an interactive menu where checks are launched separately, or in an automated mode for enumeration only.

The concrete problem it solves is tool sprawl: an Active Directory engagement normally means invoking dozens of separate utilities by hand, each with its own arguments, authentication flags and output handling. linWinPwn replaces that manual orchestration by wrapping the tools behind one script with shared options for domain, user, password, NTLM hash, Kerberos ticket, AES key or certificate, so a tester drives enumeration, vulnerability checks such as noPac, ZeroLogon, MS17-010 and MS14-068, modifications including password change, adding a user to a group, RBCD and Shadow Credentials, and dumping via secretsdump, lsassy, nanodump and DonPAPI from a single command line.

Key capabilities

  • Runs in interactive mode (linWinPwn -t [-d -u -p -H -K -A -C -o]) to execute individual checks from a menu, or in automated mode with --auto.
  • Automated mode performs enumeration only — no exploitation, object modifications or password dumping — with a different check set depending on whether credentials are supplied.
  • Unauthenticated automated runs perform anonymous enumeration with netexec, enum4linux-ng, ldapdomaindump and ldeep, RID bruteforce, kerbrute user spraying, Pre2k authentication checks, ASREPRoast and Blind Kerberoast, plus the CVE-2022-33679 exploit and krbjack checks for DNS unsecure updates.
  • Authenticated automated runs add DNS extraction, BloodHound data collection, GPOParser, sccmhunter, rdwatool and bloodyAD enumeration, wordlist generation for cracking, and account discovery where user equals password.
  • Extracts ADCS information with certipy and certi.py, and performs ASREPRoasting, Kerberoasting and Targeted Kerberoasting with hashes cracked using john-the-ripper against the rockyou wordlist.
  • Enumerates SMB shares across domain servers with smbmap, FindUncommonShares and cme's spider_plus, and scans for WebDav, dfscoerce, shadowcoerce and Spooler services using cme, Coercer and RPC Dump.
  • Checks weaknesses including ms17-010, ms14-068, zerologon, petitpotam, nopac, smb-signing, ntlmv1, runasppl, certifried, ldapnightmare and badsuccessor, plus MSSQL privilege-escalation and relay paths.

Who uses it and how

  • Penetration testers auditing an Active Directory domain from a Linux workstation, authenticating with a password, NTLM hash, Kerberos ticket, AES key or pfx certificate.
  • Testers running a safe first pass with --auto to collect BloodHound data, dump LDAP with ldapdomaindump and enumerate shares before attempting modifications or dumping.
  • Engagement teams that want repeatable unauthenticated reconnaissance — RID bruteforce, kerbrute spraying and service checks — before any credentials are in hand.
  • Operators who prefer a fixed toolchain delivered as a container, running with --net=host and a volume mapping output to the host's current directory.

Getting started

Clone the repository and run chmod +x install.sh; ./install.sh to install requirements, or pull the pre-built Docker image with docker pull lefayjey/linwinpwn:latest and invoke it through the linWinPwn_docker wrapper.

How it compares

Rather than being an alternative to any of them, linWinPwn sits alongside impacket, bloodhound, netexec, certipy, bloodyAD and DonPAPI as an orchestrator that calls those tools with consistent arguments and shared output handling. A tester who already works fluently with each tool separately gains a menu, an automated enumeration sequence and unified authentication flags instead of new detection or exploitation capability.

When to use it — and when not to

You must be prepared to install and maintain a large external toolchain — and to accept that the script's checks are only as current as the wrapped tools — with the container option available to avoid that setup. Automated mode deliberately stops at enumeration, so anyone seeking automated exploitation, object modification or password dumping must use the interactive menu. It is not for unauthorised use or for testers without an Active Directory target, and the MIT licence plus zero open issues and a recent last push leave no obvious maintenance warning in these facts.

project readme (upstream, from github) — read inline

linWinPwn - Swiss-Army knife for Active Directory Pentesting using Linux

Description

linWinPwn is a bash script that wraps a number of Active Directory tools for enumeration (LDAP, RPC, ADCS, MSSQL, Kerberos, SCCM), vulnerability checks (noPac, ZeroLogon, MS17-010, MS14-068), object modifications (password change, add user to group, RBCD, Shadow Credentials) and password dumping (secretsdump, lsassy, nanodump, DonPAPI). The script streamlines the use of a large number of tools: impacket, bloodhound, netexec, enum4linux-ng, ldapdomaindump, lsassy, smbmap, kerbrute, certipy, silenthound, bloodyAD, DonPAPI and many others.

Setup

Git clone the repository and install requirements using the install.sh script

git clone https://github.com/lefayjey/linWinPwn
cd linWinPwn
chmod +x install.sh
./install.sh

Alternatively, use the pre-built Docker image from Docker Hub

docker pull lefayjey/linwinpwn:latest

# Add linWinPwn_docker to PATH
echo -e "docker run --rm --init -it --net=host -v \$(pwd):/opt/lwp-output lefayjey/linwinpwn:latest \$@" | sudo tee "/usr/local/sbin/linWinPwn_docker"
sudo chmod 755 /usr/local/sbin/linWinPwn_docker
# Run linWinPwn_docker (output to host's current directory)
linWinPwn_docker -t <DC_IP>
linWinPwn_docker -t <DC_IP> -d <domain> -u <user> -p <password> --auto

Or build from source

docker build -t linwinpwn .
docker run --rm --init -it --net=host -v $(pwd):/opt/lwp-output linwinpwn -t <DC_IP>

Usage

Mode

The linWinPwn script can be executed in interactive mode (default), or in automated mode (enumeration only).

1. Interactive Mode (Default) - Open interactive menu to run checks separately

linWinPwn -t <Domain_Controller_IP> [-d <AD_domain> -u <AD_user> -p <AD_password> -H <hash[LM:NT]> -K <kerbticket[./krb5cc_ticket]> -A <AES_key> -C <cert[./cert.pfx]> -o <output_dir>]

2. Automated Mode - Using the --auto parameter, run enumeration tools (no exploitation, modifications or password dumping)

When using the automated mode, different checks are performed based on the authentication method.

  • Unauthenticated (no credentials provided)
    • Anonymous enumeration using netexec, enum4linux-ng, ldapdomaindump, ldeep
    • RID bruteforce using netexec
    • kerbrute user spray
    • Pre2k authentication check on collected list of computers
    • ASREPRoast using collected list of users (and cracking hashes using john-the-ripper and the rockyou wordlist)
    • Blind Kerberoast
    • CVE-2022-33679 exploit
    • Check for DNS unsecure updates for AS-REQ abuse using krbjack
    • SMB shares anonymous enumeration on identified servers
    • Enumeration for WebDav, dfscoerce, shadowcoerce and Spooler services on identified servers
    • Check for ms17-010, zerologon, petitpotam, nopac, smb-sigining, ntlmv1, runasppl weaknesses
linWinPwn -t <Domain_Controller_IP> --auto [-o <output_dir>]
  • Authenticated (using password, NTLM hash, Kerberos ticket, AES key or pfx Certificate)
    • DNS extraction using netexec
    • BloodHound data collection
    • Enumeration using netexec, enum4linux-ng, ldapdomaindump, bloodyAD, sccmhunter, rdwatool, sccmhunter, GPOParser
    • Generate wordlist for password cracking
    • netexec find accounts with user=pass
    • Pre2k authentication check on domain computers
    • Extract ADCS information using certipy and certi.py
    • kerbrute find accounts with user=pass
    • ASREPRoasting (and cracking hashes using john-the-ripper and the rockyou wordlist)
    • Kerberoasting (and cracking hashes using john-the-ripper and the rockyou wordlist)
    • Targeted Kerberoasting (and cracking hashes using john-the-ripper and the rockyou wordlist)
    • SMB shares enumeration on all domain servers using smbmap, FindUncommonShares and cme's spider_plus
    • Enumeration for WebDav, dfscoerce, shadowcoerce and Spooler services on all domain servers (using cme, Coercer and RPC Dump)
    • Check for ms17-010, ms14-068, zerologon, petitpotam, nopac, smb-signing, ntlmv1, runasppl, certifried weaknesses, ldapnightmare, badsuccessor
    • Check mssql privilege escalation paths
    • Check mssql relay possibilities
linWinPwn -t <Domain_Controller_IP>  -d <AD_domain> -u <AD_user> [-p <AD_password> -H <hash[LM:NT]> -K <kerbticket[./krb5cc_ticket]> -A <AES_key> -C <cert[./cert.pfx]>] [-o <output_dir>] --auto

Parameters

Auto config - Run NTP sync with target DC and add entry to /etc/hosts before running the modules

linWinPwn -t <Domain_Controller_IP> --auto-config

LDAPS - Use LDAPS instead of LDAP (port 636)

linWinPwn -t <Domain_Controller_IP> --ldaps

Force Kerberos Auth - Force using Kerberos authentication instead of NTLM (when possible)

linWinPwn -t <Domain_Controller_IP> --force-kerb

Verbose - Enable all verbose and debug outputs

linWinPwn -t <Domain_Controller_IP> --verbose

Interface - Choose attacker's network interface

linWinPwn -t <Domain_Controller_IP> -I tun0
linWinPwn -t <Domain_Controller_IP> --interface eth0

Targets - Choose targets to be scanned (DC, All, IP=IP_or_hostname, File=./path_to_file)

linWinPwn -t <Domain_Controller_IP> --targets All
linWinPwn -t <Domain_Controller_IP> --targets DC
linWinPwn -t <Domain_Controller_IP> -T IP=192.168.0.1
linWinPwn -t <Domain_Controller_IP> -T File=./list_servers.txt

Custom wordlists - Choose custom user and password wordlists

linWinPwn -t <Domain_Controller_IP> -U /usr/share/seclists/Usernames/xato-net-10-million-usernames.txt
linWinPwn -t <Domain_Controller_IP> -P /usr/share/seclists/Passwords/xato-net-10-million-passwords.txt

Tunneling

linWinPwn can be particularly useful when you have access to an Active Directory environment for a limited time only, and you wish to be more efficient in the enumeration process and in the collection of evidence. In addition, linWinPwn can replace the use of enumeration tools on Windows in the aim of reducing the number of created artifacts (e.g., PowerShell commands, Windows Events, created files on disk), and bypassing certain Anti-Virus or EDRs. This can be achieved by performing remote dynamic port forwarding through the creation of an SSH tunnel from the Windows host (e.g., VDI machine or workstation or laptop) to a remote Linux machine (e.g., Pentest laptop or VPS), and running linWinPwn with proxychains.

On the Windows host, run using PowerShell:

ssh.exe kali@<linux_machine> -R 1080 -NCqf

On the Linux machine, first update /etc/proxychains4.conf to include socks5 127.0.0.1 1080, then run:

linWinPwn_proxychains -t <Domain_Controller_IP>  -d <AD_domain> -u <AD_user> [-p <AD_password> -H <hash[LM:NT]> -K <kerbticket[./krb5cc_ticket]> -A <AES_key> -C <cert[./cert.pfx]>] [-o <output_dir>] [--auto]

Current supported authentications

Tool Null Session Password NTLM Hash Kerberos Ticket AES Key Certificate
netexec ✅ ✅ ✅ ✅ ✅ ✅
Impacket ✅ ✅ ✅ ✅ ✅ ❌
bloodhound-python ❌ ✅ ✅ ✅ ✅ ❌
ldapdomaindump ✅ ✅ ✅ ❌ ❌ ❌
enum4linux-ng ✅ ✅ ✅ ✅ ❌ ❌
bloodyAD ❌ ✅ ✅ ✅ ❌ ✅
SilentHound ✅ ✅ ✅ ❌ ❌ ❌
ldeep ✅ ✅ ✅ ✅ ❌ ✅
windapsearch ✅ ✅ ✅ ❌ ❌ ❌
LDAPWordlistHarvester ❌ ✅ ✅ ✅ ✅ ❌
LDAPConsole ❌ ✅ ✅ ✅ ✅ ❌
pyLDAPmonitor ❌ ✅ ✅ ✅ ✅ ❌
sccmhunter ❌ ✅ ✅ ✅ ✅ ❌
ldapper ❌ ✅ ✅ ❌ ❌ ❌
Adalanche ❌ ✅ ✅ ✅ ❌ ❌
GPOwned ❌ ✅ ✅ ✅ ✅ ❌
ACED ❌ ✅ ✅ ✅ ✅ ❌
breads ✅ ✅ ✅ ❌ ❌ ❌
godap ✅ ✅ ✅ ✅ ❌ ❌
adcheck ❌ ✅ ✅ ❌ ❌ ❌
certi.py ❌ ✅ ✅ ✅ ✅ ✅
Certipy ❌ ✅ ✅ ✅ ✅ ✅
certsync ❌ ✅ ✅ ✅ ✅ ❌
pre2k ❌ ✅ ✅ ✅ ✅ ❌
orpheus ❌ ✅ ✅ ✅ ✅ ❌
smbmap ✅ ✅ ✅ ❌ ❌ ❌
FindUncommonShares ❌ ✅ ✅ ✅ ✅ ❌
smbclient-ng ❌ ✅ ✅ ✅ ✅ ❌
manspider ✅ ✅ ✅ ❌ ❌ ❌
coercer ✅ ✅ ✅ ❌ ❌ ❌
privexchange ✅ ✅ ✅ ❌ ❌ ❌
RunFinger.py ✅ ✅ ✅ ✅ ✅ ❌
mssqlrelay ❌ ✅ ✅ ✅ ✅ ❌
targetedKerberoast ❌ ✅ ✅ ✅ ✅ ❌
pygpoabuse ❌ ✅ ✅ ✅ ❌ ❌
DonPAPI ❌ ✅ ✅ ✅ ✅ ❌
hekatomb ❌ ✅ ✅ ❌ ❌ ❌
ExtractBitlockerKeys ❌ ✅ ✅ ✅ ✅ ❌
evilwinrm ❌ ✅ ✅ ✅ ✅ ✅
mssqlpwner ❌ ✅ ✅ ✅ ✅ ❌
SoaPy ❌ ✅ ✅ ❌ ❌ ❌
SCCMSecrets ✅ ✅ ✅ ❌ ❌ ❌
Soaphound ❌ ✅ ✅ ❌ ❌ ❌
gpoParser ❌ ✅ ✅ ❌ ❌ ❌
spearspray ❌ ✅ ❌ ❌ ❌ ❌
GroupPolicyBackdoor ✅ ✅ ✅ ✅ ❌ ❌
NetworkHound ❌ ✅ ✅ ✅ ❌ ❌
ShareHound ✅ ✅ ✅ ❌ ❌ ❌
DACLSearch ❌ ✅ ✅ ✅ ✅ ❌
ScriptScout ❌ ✅ ❌ ❌ ❌ ❌
relayking ✅ ✅ ✅ ✅ ✅ ❌
ADWS Domain Dump ❌ ✅ ✅ ❌ ❌ ❌
PyADRecon ❌ ✅ ❌ ✅ ❌ ❌
PyADRecon-ADWS ❌ ✅ ❌ ✅ ❌ ❌
ADPulse ❌ ✅ ✅ ❌ ❌ ❌
PowerView.py ✅ ✅ ✅ ✅ ✅ ✅
evil-winrm-py ❌ ✅ ✅ ❌ ❌ ✅
GhostSPN ✅ ✅ ✅ ❌ ❌ ❌
rbcdbrute ❌ ✅ ✅ ✅ ✅ ❌
xfreerdp ❌ ✅ ✅ ✅ ❌ ❌
LDAP Channel Binding support

ldap3: netexec, ldapdomaindump (NTLM), Certipy, pre2k, bloodhound, ldeep, GroupPolicyBackdoor, relayking

msldap: bloodyAD

LDAP Custom port support

netexec, ldapdomaindump, ldeep, windapsearch, godap, pre2k, ldapnomnom

Demos

  • HackTheBox Forest

Interactive Mode: asciicast

Automated Mode: asciicast

  • TryHackme AttacktiveDirectory

asciicast

TO DO

  • Add more enumeration and exploitation tools...

Credits

For Developers

Tool Integrator

lwp_tool_integrator.py automates the integration of new tools. It patches linWinPwn.sh, install.sh, and README.md in one step:

  • Adds tool variable definition and wrapper function
  • Patches authenticate() with appropriate flags
  • Adds the tool to the interactive menu
  • Updates install.sh for automatic installation
  • Adds reference and auth table row to README.md

Usage:

python3 lwp_tool_integrator.py <tool_config.json>

See lwp_tool_template.json for a configuration example.

Legal Disclaimer

Usage of linWinPwn for attacking targets without prior mutual consent is illegal. It's the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program. Only use for educational purposes.

Frequently asked questions

Is linWinPwn free to use?

linWinPwn is open source under the MIT licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does linWinPwn do?

linWinPwn is a bash script that streamlines the use of a number of Active Directory tools

What is linWinPwn written in?

linWinPwn is primarily written in Shell. Its source is publicly available at https://github.com/lefayjey/linWinPwn, and it has 2,224 GitHub stars.