Post

HN
Hacker News (Newest)

ADFT: Deterministic offline AD investigation toolkit

1 point ยท 0 comments

ADFT is an offline Active Directory / Windows investigation toolkit with an integrated local web UI.

This official v1.0 release ships one coherent product surface:

ADFT ingests exported evidence, converts every supported source into canonical JSONL, applies deterministic detections and correlations, computes an observed AD exposure score, reconstructs attack progression, and generates investigation and hardening artefacts.

ADFT analyzes offline Windows / AD / SIEM-oriented datasets and produces investigation artifacts through a CLI and an integrated GUI.

ADFT accepts source evidence in multiple formats and converts them to canonical JSONL before analysis:

Detailed dependency notes are listed in docs/DEPENDENCIES.md .