finds.dev← search

// the find

CR1MS0N-Operator/Lant3rn

C · MIT · updated Sep 2026

Lightweight C tool that audits Windows Active Directory for risky permissions: LDAP enumeration, MITRE ATT&CK-mapped risk scoring, deterministic JSON/CSV output.

Lantern (ACLGuard) is a C command-line tool that pulls AD users and group memberships over read-only LDAP and scores each principal from 0 to 100 against a few MITRE ATT&CK techniques. It is for defenders and purple teams who want one binary that emits deterministic JSON or CSV they can diff between runs or gate a pipeline on, not a BloodHound-style attack graph.

The output contract is the best part. Deterministic JSON and CSV means a scheduled run can be diffed against the last one to catch permission drift, which is the automation most teams actually need. The mock data under data/mock lets someone exercise the CLI without a domain controller. The limitations section is blunt about what is not covered (no DACL parsing, no nested groups, no LDAPS), which is more useful than a feature list that implies coverage it does not have.

The detection is group-membership heuristics, not ACL analysis. There is no DACL or ACE parsing, so GenericAll, WriteDacl, and WriteOwner, which drive most real AD escalation paths, are invisible, and a clean report says nothing about them. Only direct memberships are resolved, so a user who reaches Domain Admins through nested groups is not flagged. The ATT&CK mapping is loose: the README maps authentication delegation to T1484.001, which it names Group Policy Modification, and it does not explain how the 0 to 100 score is computed, which makes a CI threshold hard to justify. The bind password comes from an environment variable and the only transport shown is cleartext ldap://, and CI is still listed as planned.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →