8-10 - Min Full Scan
Hackflix - Live Attack Show4 Platforms - Multiple Options
Report - Instant (Example)
Rescan Engine - Every PathRun From Anywhere (Mobile)
100% - Non-AI
[ HOW IT WORKS ]
From zero to Domain Admin — fully automated
01 SECURE TUNNEL .OVPN
1

Upload VPN

Upload .ovpn — tunnel's live.

02 DC · 10.0.0.1 BREACHED
2

Target & Scan

Enter DC IP — attack launches.

03 DOMAINATOR NEWS [+] TGS hash captured [*] AS-REP svc_backup [+] ESC1 cert template [!] DOMAIN ADMIN [+] TGS hash captured [*] AS-REP svc_backup [+] ESC1 cert template [!] DOMAIN ADMIN BREAKING: ENTIRE FOREST COMPROMISED IN 4 MINUTES —
3

Watch Live

Every module streams live.

04 REPORT DOMAIN ADMIN ACHIEVED
4

Get Report

Chain, hashes, fixes — one report.

[ LIVE SCAN ]
Same attack. Every platform.
language WEB
desktop_windows WINDOWS
terminal LINUX
phone_android ANDROID
app.domainator.tools/scan/live
◆ DOMAINator.exe
─
□
✕
● domainator@kali:~$ ./DOMAINator.bin
─
□
✕
10:48 LTE   39%
SCANNING
[ AVAILABLE ON ]
One platform. Every device.
Web Windows Linux Android
[ AI VS REALITY ]
Why AI scanners fail at Active Directory
3%
of AI scanners can execute a single real Kerberos attack chain. They guess. We prove.
CAPABILITY AI SCANNERS DOMAINATOR
Kerberos Exploitation✗✓ TGS-REQ + cracking
ADCS Certificate Abuse✗✓ ESC1-ESC11
DCSync Domain Dump✗✓ DRSUAPI replication
Pass-the-Hash / Relay✗✓ NTLM + Kerberos relay
Golden Ticket Forge✗✓ KRBTGT + crypto
Multi-Step Attack Chains✗✓ 30+ chained flows
Data Stays On-Premise✗ sent to cloud LLM✓ isolated namespaces
Reproducible Results✗ non-deterministic✓ deterministic always
No "Vibe Coding"✗ improvises actions live✓ fixed, audited exploit code
Works If AI Providers Don't✗ dead without a live LLM API✓ zero third-party AI dependency
3%
INDEPENDENT AI SUCCESS RATE
30+
ATTACK CHAINS
8-10m
TO DOMAIN ADMIN
0
DATA SENT TO AI
KERBEROAST ◆ AS-REP ROAST ◆ DCSYNC ◆ ADCS ESC1-ESC11 ◆ PASS-THE-HASH ◆ GOLDEN TICKET ◆ SHADOW CREDENTIALS ◆ RBCD DELEGATION ◆ NTLM RELAY ◆ S4U IMPERSONATION ◆ GPO ABUSE ◆ ZEROLOGON ◆ NOPAC ◆ HASHDUMP ◆ LAPS DUMP ◆ ACL ABUSE ◆ SILVER TICKET ◆ TICKET REUSE ◆ PASSWORD SPRAY ◆ DELEGATION ABUSE ◆ UNCONSTRAINED DELEG ◆ CREDENTIAL DUMP ◆ LATERAL MOVEMENT ◆ PRIVILEGE ESCALATION ◆ KERBEROAST ◆ AS-REP ROAST ◆ DCSYNC ◆ ADCS ESC1-ESC11 ◆ PASS-THE-HASH ◆ GOLDEN TICKET ◆ SHADOW CREDENTIALS ◆ RBCD DELEGATION ◆ NTLM RELAY ◆ S4U IMPERSONATION ◆ GPO ABUSE ◆ ZEROLOGON ◆ NOPAC ◆ HASHDUMP ◆ LAPS DUMP ◆ ACL ABUSE ◆ SILVER TICKET ◆ TICKET REUSE ◆ PASSWORD SPRAY ◆ DELEGATION ABUSE ◆ UNCONSTRAINED DELEG ◆ CREDENTIAL DUMP ◆ LATERAL MOVEMENT ◆ PRIVILEGE ESCALATION ◆
[ BATTLE PLANS ]
Individual AD penetration testing
sword_rose SQUIRE — FREE TRIAL
Start with 1 free scan — no credit card required. Experience the full attack chain on your own environment.
1 SCAN 1 RESCAN WEB REPORT FREE
START FREE SCAN
BATTLE PLANS
FOR COMPANIES, TEAMS & INDEPENDENT OPERATORS
shield
BARON
Entry Warrior
$49
/month
  • ✔ 3 scans / month
  • ✔ 1 rescan / month
  • ✔ Partial report (unlockable)
  • ✔ Live attack terminal
  • ✔ 24h report access
GET STARTED
👑
EMPEROR
Supreme Ruler
$299
/month
  • ✔ 12 scans / month
  • ✔ 4 rescans / month
  • ✔ Full report — all pages + features
  • ✔ All exports (PDF, XLS, JSON, TXT)
  • ✔ 48h report access
  • ✔ Priority scan queue
  • ✔ Dedicated support
GET STARTED
CISO'S FORTRESS
FOR TEAM LEADERS MANAGING RANGERS
Multi-hacker team management
groups
WARBAND
CISO · 3 Rangers
$299
/month
  • ♦ 3 rangers included
  • ♦ 4 scans / ranger / month
  • ♦ 1 rescan / ranger / month
  • ♦ Live ranger monitoring
  • ♦ CISO analytics dashboard
  • ♦ Team key management
GET STARTED
BEST VALUE
verified_user
LEGION
CISO · 5 Rangers
$499
/month
  • ♦ 5 rangers included
  • ♦ 5 scans / ranger / month
  • ♦ 2 rescans / ranger / month
  • ♦ Live ranger monitoring
  • ♦ CISO analytics dashboard
  • ♦ Team key management
  • ♦ Priority support
GET STARTED
INDIVIDUAL / FREELANCER
EMPLOYEES' PERSONAL EDGE / FREELANCERS' OWN CLIENTS
Independent engagements, client-ready reports
terminal
HACKER
Solo Operator
$149
/month
  • ✔ 5 scans / month
  • ✔ 2 rescans / month
  • ✔ Findings + Mitigations report
  • ✔ Full attack chain analysis
  • ✔ 24h report access
GET STARTED
play_circle
Video Coming Soon
close
DOMAINATOR
Emperor Report
flagCONQUEST
keyCREDENTIALS
verified_userADCS
account_treeATTACK CHAIN
buildREMEDIATION
SCAN #4701 · 2026-05-10
✅
DOMAIN COMPROMISED
Target Domaincorp.contoso.com
Domain ControllerDC01
DC IP Address10.10.14.5
Scan Duration23 minutes
9.8
CRITICAL
RISK SCORE
2,847
USERS
156
CREDENTIALS
342
MACHINES
ATTACK PATH SUMMARY
AS-REP Roast → Kerberoast → ADCS ESC1 → Domain Admin
key CAPTURED CREDENTIALS
6 credentials recovered across multiple attack vectors
USERNAMEHASH / PASSWORDSOURCETYPE
Administrator:500aad3b435b51404ee:fc525c9683e8fe067cbb...DCSyncNTLM
krbtgt:502aad3b435b51404ee:9d1d6c0327e80c2a4c3b...DCSyncNTLM
svc_mssqlSummer2024!KerberoastCleartext
svc_backup$krb5asrep$23$svc_backup@CORP...AS-REPHash
j.smithWelcome2024!SprayCleartext
DA_adminP@ssw0rd2024SYSVOL/GPPCleartext
verified_user ADCS ANALYSIS
Certificate AuthorityCONTOSO-DC01-CA
Templates Analyzed14
warning ESC1 VULNERABLE: CorpTemplate
Enrollee Supplies SubjectYES
Client Authentication EKUYES
Low-Privilege EnrollmentDomain Users
Manager ApprovalDISABLED
Authorized Signatures0
EXPLOITATION RESULT
Certificate issued for: [email protected]
TGT obtained via PKINIT authentication
account_tree ATTACK CHAIN
Full exploitation path from anonymous to domain admin
Anonymous Enumeration
847 users discovered
↓
User Spray
j.smith:Welcome2024!
↓
AS-REP Roast
svc_backup - no pre-auth
↓
Kerberoast
svc_mssql:Summer2024!
↓
ADCS ESC1
Certificate as Administrator
↓
PKINIT → TGT
Administrator TGT obtained
↓
DCSync
All domain hashes extracted
↓
DOMAIN ADMIN
Full domain compromise achieved
build REMEDIATION
5 findings requiring immediate attention
Disable SPN accounts pre-auth requirement CRITICAL
Account svc_backup has Kerberos pre-authentication disabled, enabling AS-REP roasting. Enable pre-auth on all service accounts and audit accounts with DONT_REQUIRE_PREAUTH flag.
Fix ADCS ESC1 template - remove enrollee-supplies-subject CRITICAL
CorpTemplate allows any domain user to request certificates with arbitrary SANs. Remove CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT, restrict enrollment to specific groups, and require CA manager approval.
Rotate all service account passwords (>25 chars) HIGH
svc_mssql password (Summer2024!) was cracked via Kerberoasting. Replace all SPN-associated accounts with gMSA (Group Managed Service Accounts) for automatic 120-char password rotation.
Implement tiered admin model HIGH
Lateral movement was trivial due to flat admin structure. Implement Microsoft's tiered administration model (Tier 0/1/2) to segment privileged access and prevent credential exposure across tiers.
Enable LDAP signing and channel binding MEDIUM
LDAP signing is not enforced, enabling relay attacks and MITM on LDAP traffic. Configure LdapServerIntegrity=2 and enable LDAP channel binding on all domain controllers.
close
LIVE SCAN DEMO
Watch the conquest unfold in real-time
language WEB
desktop_windows WINDOWS
terminal LINUX
phone_android ANDROID
app.domainator.tools/scan/live
◆ DOMAINator.exe
─
□
✕
● domainator@kali:~$ ./DOMAINator.bin
─
□
✕
10:48LTE   39%
SCANNING
close
AVAILABLE ON
One platform. Every device.
Web Windows Linux Android
zoom_in CLICK TO ZOOM
Web
Windows & Linux
Android
WEB APP WINDOWS LINUX ANDROID
close
AI VS REALITY
Why AI scanners fail at Active Directory
0%
of AI scanners can execute a single real Kerberos attack chain. They guess. We prove.
CAPABILITY AI SCANNERS DOMAINATOR
Kerberos Exploitation✗✓ TGS-REQ + cracking
ADCS Certificate Abuse✗✓ ESC1-ESC11
DCSync Domain Dump✗✓ DRSUAPI replication
Pass-the-Hash / Relay✗✓ NTLM + Kerberos relay
Golden Ticket Forge✗✓ KRBTGT + crypto
Multi-Step Attack Chains✗✓ 30+ chained flows
Data Stays On-Premise✗ sent to cloud LLM✓ isolated namespaces
Reproducible Results✗ non-deterministic✓ deterministic always
No "Vibe Coding"✗ improvises actions live✓ fixed, audited exploit code
Works If AI Providers Don't✗ dead without a live LLM API✓ zero third-party AI dependency

Built by penetration testers who hack Active Directory daily. Every attack chain is battle-tested — not generated by AI and hoped for the best.

THE REAL DIFFERENCE

WHY DOMAINATOR?

Whether you're a security team, a freelance pentester, or a company protecting its own domain — DOMAINator finds every attack path in minutes, not days.

CATEGORY WITHOUT DOMAINATOR AI SCANNERS DOMAINATOR
COST $10,000–$30,000+ per engagement $200–$500/mo (limited scope) From $49/mo — unlimited depth
TIME TO REPORT 3–5 days testing + 1–2 weeks for report delivery Hours (surface-level only) 15–45 minutes — full report on completion
ATTACK COVERAGE 1–2 attack paths found on average. Manual testing finds one path to DA and stops Suggests theoretical vulnerabilities. Doesn't exploit anything Tests every known privilege escalation gate — doesn't stop at the first win
PE GATES TESTED Limited to what time allows (usually 1–3 techniques) ✖ None — doesn't perform real exploitation 30+ escalation vectors — every combination of access + vulnerability
MISSED OPPORTUNITIES Common. Valuable access found but chaining into PE takes time to explore manually Can't chain — no real exploitation engine Zero. Every credential, every access, every path is cross-referenced and exploited
TESTING MODES Usually graybox only (given a domain user) External scanning only Anonymous, graybox (domain user), and machine account — all from one scan
REAL EXPLOITATION ✔ Yes — but limited by time and scope ✖ No — reports theoretical risks only ✔ Full exploitation — real credentials, real shells, real DA
RETEST Manual retest covers only the previously reported findings. Full re-engagement needed for new paths Reruns the same surface scan Full rescan — retests everything including new paths. Finds regressions AND new issues
CONSISTENCY Results vary by who runs it and when. Hard to guarantee same depth every time Consistent but shallow Same depth every time. No human variance. No bad days
LIVE VISIBILITY Results delivered after the engagement. No real-time visibility during the test Dashboard with scan progress Watch every attack live in real-time. Full terminal output. Nothing hidden
KNOWLEDGE Bounded by time on-site. Impossible to test every AD misconfiguration manually Trained on public data — misses real-world edge cases Encyclopedic. Every known AD attack technique, every combination, tested systematically
INTELLIGENCE BRIEFING

FREQUENTLY ASKED

What exactly does DOMAINator do?
+
DOMAINator is a fully automated Active Directory penetration testing platform. You connect a VPN to a client's network, enter the target IP, and the system executes a real attack chain — credential harvesting, relay attacks, privilege escalation, and lateral movement. It tests every known escalation path, not just the first one it finds. You get a full penetration test report with evidence, attack paths, and remediation — not a vulnerability scan.
How does DOMAINator work alongside pentesters?
+
DOMAINator runs before your pentester arrives on-site. It maps the entire Active Directory, tests every escalation path systematically, and delivers a full report with proven exploits — all in minutes. When your pentester starts, they already have the domain map, every credential, every attack chain laid out. They spend their time validating and expanding instead of discovering from scratch. It's the recon phase on steroids — giving your team a head start that turns a 5-day engagement into a focused, high-impact assessment.
Why not just use an AI-based scanner?
+
AI scanners suggest theoretical vulnerabilities. They don't exploit anything. They can't relay a credential, escalate privileges, or move laterally through an Active Directory environment. DOMAINator performs real exploitation with real tools — it harvests actual credentials, gains real shells, and achieves actual Domain Admin access. The report shows proof, not predictions.
What does "rescan" mean and why does it matter?
+
A traditional retest checks only the findings that were reported. DOMAINator's rescan runs the entire attack chain again from scratch. It re-tests everything — including new attack paths that appeared since the fixes, regressions, and misconfigurations the original scan didn't need because it already had DA. Your pentester gets a fresh full report showing what's fixed, what's not, and what's new — without spending another week on-site.
Is my client's data safe?
+
Your data never leaves the scan environment. Credentials and hashes found during the scan are used only within the attack chain and kept only inside your report. The report stays available for a limited time based on your plan (24 hours, or 48 hours on Emperor and CISO), then the report and the sensitive scan contents are permanently deleted — only a non-sensitive summary is kept for your history. We don't share data with third parties. Zero data is sent to any AI service.
Do I need authorization to run a scan?
+
Yes, absolutely. DOMAINator executes real attacks against real infrastructure. You must have written authorization from the network owner before running any scan. Every scan requires you to confirm authorization. Unauthorized use is illegal and a violation of our terms of service.
What do I need to get started?
+
Three things: 1) An account on DOMAINator. 2) A VPN configuration file (.ovpn) that connects to the target network. 3) The IP address of a Domain Controller. Upload the VPN, enter the target, and hit scan. The platform handles everything else — from reconnaissance to the final report.
How long does a scan take?
+
Most scans complete in 8–10 minutes depending on the environment. You can watch the entire attack chain live in real-time through the terminal view. Every action is logged and visible — nothing happens behind a black box.
What's the CISO plan for?
+
The CISO plans (Warband and Legion) are built for security teams. You get a command dashboard to manage multiple pentesters, monitor all scans across your team, view aggregate analytics, and control scan policies. Each team member gets their own credentials — they run scans, you see everything.
Can I cancel anytime?
+
Yes. All plans are month-to-month unless you choose annual billing (which saves 17%). Cancel anytime — no contracts, no hidden fees, no cancellation penalties. Your account and any remaining scan credits stay active until the end of your billing period. (Individual reports still follow their normal access window — 24 hours, or 48 hours on Emperor and CISO — after which they are deleted.)
keyboard_arrow_up
✕
⏳
COMING SOON

DOMAINator downloads aren't public yet — we're putting the final polish on before release.
Stay tuned.