Map the terrain before you move. Users, groups, computers, trusts, GPOs, and ACLs — you can't hunt what you haven't mapped. No shots fired in this phase.
EHWS is a structured four-phase methodology used by W-Logic consultants to enumerate, hunt, weaponize, and secure Active Directory environments — with evidence at every step.
EHWS gives every engagement a consistent, repeatable structure — so you never fly blind and your reports always tell a coherent story.
Map the terrain before you move. Users, groups, computers, trusts, GPOs, and ACLs — you can't hunt what you haven't mapped. No shots fired in this phase.
Find the paths. Every DACL weakness, Kerberoastable account, delegation misconfiguration, and AS-REP roasting target is an edge. Hunt is additive — run all tools, then chain.
Prove the risk. Exploit the chain. Demonstrate real-world impact from a compromised credential all the way to Domain Admin. Every finding needs a proof-of-concept.
Close the gap. Remediate, validate with a re-run, and export the evidence. Leave the environment provably better than you found it — with a BloodHound diff to prove it.
Every EHWS tool runs entirely in your browser. Paste your output, get structured analysis. Nothing leaves your machine — ever.
DACL Reader, ADCS ESC Finder, Delegation Auditor, Attack Path Chainer, NTLM Relay Analyzer, BloodHound Diff, Trust & Forest Map, Shadow Credential & gMSA Auditor, DCSync Rights Auditor
PreAuth Enum Analyzer, Kerberoast Triage, Kerberos Ticket Inspector, Hash Analyzer, GPP Password Decryptor, Timeroast Analyzer
Payload Studio, Upload Filter Analyzer, JWT / Token Inspector
Entra / Azure Token & Scope Analyzer, AWS IAM PassRole Analyzer
Linux Privesc Parser, Password Spray Planner, Certificate Validator
GPO Security Auditor, LAPS Auditor, DC Infrastructure & Legacy Protocol Auditor, Password Policy & Account Hygiene Auditor, Detection Rule Generator
The EHWS video series walks through every tool and technique — one episode per tool. Hands-on TryHackMe rooms let you practice in a guided lab.
Spot WriteDACL, GenericAll, and GenericWrite from BloodHound or manual ACE output
Identify Kerberos preauthentication-disabled accounts and understand the offline cracking risk
Extract Kerberoastable SPNs, assess password age, and prioritize crack targets
Identify and exploit delegation misconfigurations — from full impersonation to resource-based
Calculate safe spray windows from password policy output — never lock an account by accident
Walk through a complete Phase 1 engagement on a realistic AD environment. Map users, groups, GPOs, and trust relationships using the EHWS Enumerate tools.
Exploit WriteDACL and GenericAll permissions in a guided lab. Follow the Hunt → Weaponize chain from initial access to Domain Admin.
Guided EHWS labs are being built on the TryHackMe TryBuildMe platform. Subscribe to the YouTube channel for launch announcements.
EHWS wasn't designed in a lab. It was extracted from hundreds of hours of authorized Active Directory penetration tests by W-Logic consultants.
Most AD pentests are a bag of techniques. EHWS is a phase-gated methodology — you can't Weaponize what you haven't Hunted, and you can't close in Secure what you haven't proven in Weaponize.
EHWS tools output structured findings with MITRE ATT&CK technique IDs, operator paths, and remediation steps. Every finding is a paragraph in your final report — ready to copy.
All 28 tools are permanently free. No paywalls, no accounts. If these tools help you pass a cert, land a job, or close a finding — that's the point. Revenue comes from services, not access.
W-Logic delivers authorized Active Directory penetration tests using the EHWS Framework — structured, evidence-backed, and built to drive remediation, not just fill a report with screenshots.