ADReaper
Active Directory and Windows privilege-escalation recon, without touching exploitation
Python · LDAP
Enumerates Active Directory attack surface over LDAP — Kerberoasting and ASREPRoasting candidates, delegation, ACLs, trusts and GPOs — then ranks what it finds and prints the exact command to run next.
Recon only. It maps the ground and hands you the commands; it does not exploit anything itself, which keeps it safe to run early in an engagement.