ADRoute is a tool for visualizing Active Directory attack paths. It uses data from SharpHound or BloodHound to help you map out AD relationships and find ways to escalate privileges.
- Red Teaming & Pentesting: Find the easiest or shortest path to compromise a target (like Domain Admin) and keep track of your notes and looted credentials.
- Blue Teaming & Defense: See what an attacker could reach if a specific account is compromised (blast radius), or find the main choke points in your AD network that need to be fixed.
| Feature | BloodHound | ADRoute |
|---|---|---|
| Path Weights | All paths are treated the same. | Assigns "weights" to different attacks. It can prioritize quiet attacks (like Group Membership) over noisy ones (like DCSync). |
| Multiple Starting Points | Finds paths from one node to another. | Can find the easiest path to a target starting from all the nodes you currently control. |
| Keeping Track | Mainly just for viewing the graph. | Lets you save hashes, passwords, and notes directly on the nodes. It saves your progress locally. |
| Finding Bottlenecks | Need to write custom Cypher queries. | Automatically highlights the nodes that show up in the most attack paths. |
It can calculate different types of paths:
- Shortest Path: Finds the path with the fewest steps.
- Easiest Path: Tries to find paths that require less complex or noisy exploits based on hardcoded weights.
- Paths from Owned: Automatically finds the best route to your target from any node you've already compromised.
- Loot: Save credentials or hashes on the computers or users you compromise.
- Notes: Write down what you find on each node.
- Persistence: Everything is saved to a local file (
data/state.json), so if you close the tool, your data is still there when you open it again.
- Impact Analysis: See all the nodes you can reach from a single starting point.
- Choke Points: Shows you the most common nodes used in attack paths so defenders know what to fix first.
- Highlights important nodes like Domain Admins and Domain Controllers.
- Shows Group Policy links and ADCS objects.
-
Clone the repo:
git clone https://github.com/navnee1h/ADRoute cd ADRoute -
Install requirements:
pip install -r requirements.txt
(Requires:
flask,networkx,scipy) -
Start the app:
python app.py
-
Open in browser: Go to
http://127.0.0.1:5000
- Load Data: Click the file icon in the top right to upload your SharpHound
.jsonfile. - Mark Owned: Right-click on a node you control and click "Mark as Owned".
- Find Paths: Use the sidebar to set a Target and click "Trace Fastest Path" or "Trace Stealthiest Path".
- Save Loot: Click on a node to open the side panel where you can type in notes and hashes.



