Skip to content

Security: capture0x/AdStrike

Security

SECURITY.md

Security Policy

AdStrike is intended only for authorized penetration testing, red-team engagements, lab use, and security research.

Do not use this framework against systems you do not own or do not have explicit written permission to test.

Before Publishing Logs or Issues

Remove all sensitive material before sharing output:

  • Real domains, usernames, IP addresses, and hostnames
  • Passwords, NTLM hashes, Kerberos tickets, ccache/kirbi files, PFX files, and private keys
  • Reports, loot, packet captures, dumps, and session JSON files
  • Customer, client, or lab-identifying evidence

Reporting Security Issues

If you find a vulnerability in the framework itself, open a private report or contact the maintainer directly rather than posting exploit details publicly.

There aren't any published security advisories