• 🎬 Home
  • 🎯 About
  • Articles
  • Labs
  • 🔥 Kerberoasting
  • ⚙️ Tools & Scripts
  • 🧨 CVE Tracker
  • AI - ArkAI
  • More
    • 🎬 Home
    • 🎯 About
    • Articles
    • Labs
    • 🔥 Kerberoasting
    • ⚙️ Tools & Scripts
    • 🧨 CVE Tracker
    • AI - ArkAI
  • 🎬 Home
  • 🎯 About
  • Articles
  • Labs
  • 🔥 Kerberoasting
  • ⚙️ Tools & Scripts
  • 🧨 CVE Tracker
  • AI - ArkAI

💻 Welcome to the RootDC.io PowerShell Toolbox

Scripts, EXEs, and CLI tools to audit, clean, and secure your AD like a pro.  

Handcrafted by KuroStrike. Battle-tested in real-world engagements.

🛠️ Featured Tools

🔧 AD Auditor Pro

 Complete GUI tool for GPO cleanup, privileged account mapping, and reporting.

⬇️ Download EXE + Source

🎯 GPO Hunter Lite

Fast GPO anomaly scanner — no module required. Lightweight & CLI-ready.


red team sidhistory, gpo cleanup, ntlm powershell, active directory audit

⚡ Get Script

🧭 Privileged Mapper

 Maps orphaned T1/T2 accounts and finds AD inconsistencies quickly.

📥 Download Mapper

📊 LogonTracer Parser

 Parses EventID 4624/4625 for user session tracking & forensic auditing.

🔍 View Usage Guide

🔄 PS-ResetDC

 Resets stale replication states & triggers SYSVOL refresh (For Domain Controllers  only) .

🔧 Run Script

🧹 SIDHistory Cleaner

Detects and removes legacy SIDHistory entries to harden migration hygiene (To use very carefully, it has a serious impact on the trust) .

🧼 Clean SIDHistory

🧪 Tier Escalation Tracker (Tier0)

Detects privilege boundary violations by analyzing T0, T1, and T2 account memberships. Flags risky delegation or lateral access vectors.


⏳ Coming soon

🧠 GPO Attack Surface Analyzer

Audits Group Policy Objects for misconfigurations, excessive permissions, and inheritance vulnerabilities that expose the domain.

⏳ Coming soon

🌐 ForestTrustScope.ps1

Scans for misconfigured cross-domain trust paths and lateral movement opportunities via SIDHistory, adminSDHolder, and inter-forest ACLs.

⏳ Coming soon

🛠️ Got a PowerShell script, EXE, or CLI tool you want to share?


RootDC.io thrives thanks to contributors who push the boundaries of AD defense and attack simulation.  

If you’ve built a script that deserves visibility — detection, cleanup, audit, or exploitation — we want it on board.


📬 Submit your tools or scripts on GitHub:  

🔗 [github.com/KuroStrike](https://github.com/KuroStrike)


Together we build stronger domains.

powershell, active directory audit sidhistory, gpo cleanup, ntlm red team

© 2025 RootDC.io | Built by KuroStrike | GitHub

Powered by

  • Privacy Policy

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

DeclineAccept