Fully Offline · Client-Side · Nothing Leaves Your Browser

Ethical Hackers
Workshop Toolkit

28 specialized HTML tools for authorized Active Directory, cloud, web app, and credential security assessments. Open any file locally — no install, no backend, no telemetry.

28Interactive Tools
6Domains
100%Offline
0Install Required
AD Attack Paths 9 tools
DACL Reader Grades Active Directory ACL attack paths from PowerView/xlsx exports, with a Tier 0 baseline to cut the noise. Open tool ADCS ESC Finder Classifies ESC1–ESC16 from Certipy / Certify / certutil output with operator + defender guidance. Open tool Delegation Auditor Finds unconstrained / constrained / S4U2Self / RBCD delegation with the exact S4U commands. Open tool Attack Path Chainer Ranks the shortest paths from widely-held principals to Domain Admin. Exports BloodHound OpenGraph. Open tool NTLM Relay & Coercion Analyzer Finds relay-viable hosts (SMB signing off) from NetExec/nmap output, maps coercion vectors, and builds the ntlmrelayx + ADCS ESC8 chain. Open tool BloodHound Diff Compare two SharpHound collections to surface new attack edges, new Tier-0 paths, and removed privileges between snapshots. Drop before/after JSON files — offline. Open tool Trust & Forest Map Visualize AD domain/forest trusts from nltest, Get-ADTrust, or BloodHound exports. Flags SID filtering gaps, PAM trusts, selective auth, and cross-forest attack paths. Open tool NEW Shadow Credential & gMSA Auditor Find who can write msDS-KeyCredentialLink (Shadow Credentials → PKINIT account takeover) and who can read gMSA passwords. Certipy/pyWhisker/Whisker + gMSADumper commands, edges export. Open tool NEW DCSync Rights Auditor Paste an ACL export over the domain head — aggregates DS-Replication-Get-Changes + Get-Changes-All per principal and flags exactly who can DCSync (full / partial / indirect). Open tool
Credentials & Hashes 6 tools
Web App 3 tools
Cloud 2 tools
Recon & Planning 3 tools
Detection & Defense 5 tools
Utilities 8 tools