EHWS Framework — Active Directory Offense

Stop Guessing.
Start Mapping.

EHWS is a structured four-phase methodology used by W-Logic consultants to enumerate, hunt, weaponize, and secure Active Directory environments — with evidence at every step.

Enumerate
Hunt
Weaponize
Secure
ehws-operator — zsh
# PHASE 1 — ENUMERATE: Map the terrain
PS > Get-DomainUser | Where-Object {$_.admincount -eq 1}
→ 14 privileged accounts identified

# PHASE 2 — HUNT: Find the paths
PS > Find-InterestingDomainAcl | ? { $_.IdentityRef -match "Domain Users" }
→ WriteDACL on AdminSDHolder [T1484.001]

# PHASE 3 — WEAPONIZE: Prove the risk
PS > Rubeus.exe kerberoast /stats
→ 7 Kerberoastable accounts [T1558.003]

# PHASE 4 — SECURE: Close the gap
PS > BloodHound-Diff --before snap1.json --after snap2.json
→ 3 attack paths removed ✓ remediated

Four Phases. One Framework.

EHWS gives every engagement a consistent, repeatable structure — so you never fly blind and your reports always tell a coherent story.

E
Enumerate

Map the terrain before you move. Users, groups, computers, trusts, GPOs, and ACLs — you can't hunt what you haven't mapped. No shots fired in this phase.

Domain User & Group Mapper
Trust Relationship Visualizer
Password Policy Auditor
GPO Security Auditor
DC Infrastructure Auditor
H
Hunt

Find the paths. Every DACL weakness, Kerberoastable account, delegation misconfiguration, and AS-REP roasting target is an edge. Hunt is additive — run all tools, then chain.

DACL Rights Reader
Kerberoast Target Mapper
AS-REP Roast Analyzer
Delegation Misconfiguration Finder
BloodHound Path Analyzer
W
Weaponize

Prove the risk. Exploit the chain. Demonstrate real-world impact from a compromised credential all the way to Domain Admin. Every finding needs a proof-of-concept.

Attack Chain Synthesizer
Spray Planner & Lockout Guard
Privilege Escalation Mapper
Lateral Movement Tracker
AWS IAM PassRole Analyzer
S
Secure

Close the gap. Remediate, validate with a re-run, and export the evidence. Leave the environment provably better than you found it — with a BloodHound diff to prove it.

BloodHound Snapshot Diff
LAPS Coverage Auditor
Remediation Report Generator
MITRE ATT&CK Coverage Map
Executive Summary Builder

28 Free Tools. Zero Installs.

Every EHWS tool runs entirely in your browser. Paste your output, get structured analysis. Nothing leaves your machine — ever.

28 Interactive Tools
100% Client-Side
0 Installs Required
0 Data Leaves Browser

AD Attack Paths

DACL Reader, ADCS ESC Finder, Delegation Auditor, Attack Path Chainer, NTLM Relay Analyzer, BloodHound Diff, Trust & Forest Map, Shadow Credential & gMSA Auditor, DCSync Rights Auditor

9 tools

Credentials & Hashes

PreAuth Enum Analyzer, Kerberoast Triage, Kerberos Ticket Inspector, Hash Analyzer, GPP Password Decryptor, Timeroast Analyzer

6 tools

Web App

Payload Studio, Upload Filter Analyzer, JWT / Token Inspector

3 tools

Cloud

Entra / Azure Token & Scope Analyzer, AWS IAM PassRole Analyzer

2 tools

Recon & Planning

Linux Privesc Parser, Password Spray Planner, Certificate Validator

3 tools

Detection & Defense

GPO Security Auditor, LAPS Auditor, DC Infrastructure & Legacy Protocol Auditor, Password Policy & Account Hygiene Auditor, Detection Rule Generator

5 tools
All 28 Tools 100% offline · nothing leaves your browser

Watch. Practice. Prove It.

The EHWS video series walks through every tool and technique — one episode per tool. Hands-on TryHackMe rooms let you practice in a guided lab.

YouTube Series
@ETHICALSOUP
Subscribe
E01
DACL Reader — Mapping DACL Abuse Paths

Spot WriteDACL, GenericAll, and GenericWrite from BloodHound or manual ACE output

Live
E02
PreAuth Enum — AS-REP Roasting Without Credentials

Identify Kerberos preauthentication-disabled accounts and understand the offline cracking risk

Live
E03
Kerberoast Mapper — Targeting Service Accounts

Extract Kerberoastable SPNs, assess password age, and prioritize crack targets

Coming Soon
E04
Delegation Finder — Unconstrained & Constrained Delegation

Identify and exploit delegation misconfigurations — from full impersonation to resource-based

Coming Soon
E05
Spray Planner — Password Spray Without a Lockout

Calculate safe spray windows from password policy output — never lock an account by accident

Coming Soon
Hands-On Labs
TryHackMe Rooms
EHWS: Active Directory Enumeration

Walk through a complete Phase 1 engagement on a realistic AD environment. Map users, groups, GPOs, and trust relationships using the EHWS Enumerate tools.

ENUMERATE BloodHound PowerView AD
EHWS: Privilege Escalation via DACL Abuse

Exploit WriteDACL and GenericAll permissions in a guided lab. Follow the Hunt → Weaponize chain from initial access to Domain Admin.

HUNT WEAPONIZE DACL T1484.001
Rooms Launching Q1 2025

Guided EHWS labs are being built on the TryHackMe TryBuildMe platform. Subscribe to the YouTube channel for launch announcements.

Built on Real Engagements.

EHWS wasn't designed in a lab. It was extracted from hundreds of hours of authorized Active Directory penetration tests by W-Logic consultants.

Structured, Not Ad Hoc

Most AD pentests are a bag of techniques. EHWS is a phase-gated methodology — you can't Weaponize what you haven't Hunted, and you can't close in Secure what you haven't proven in Weaponize.

Evidence at Every Step

EHWS tools output structured findings with MITRE ATT&CK technique IDs, operator paths, and remediation steps. Every finding is a paragraph in your final report — ready to copy.

Free for the Community

All 28 tools are permanently free. No paywalls, no accounts. If these tools help you pass a cert, land a job, or close a finding — that's the point. Revenue comes from services, not access.

Your tools are showing you the data.
Do you know what it means?

W-Logic delivers authorized Active Directory penetration tests using the EHWS Framework — structured, evidence-backed, and built to drive remediation, not just fill a report with screenshots.

Full EHWS-phase engagement with BloodHound before/after snapshots
MITRE ATT&CK-mapped findings with executive and technical reports
Remediation validation — we re-run the same tools to prove the fix worked
30-minute scoping call — free, no pressure
Book a Scoping Call — Free
Typical Engagement Results
14 Privileged accounts found with exploitable DACL paths on average
7 Kerberoastable service accounts — median across AD environments
3.2 Hop attack paths from Domain User → Domain Admin (average shortest)
100% of critical findings resolved and BloodHound-validated in remediation phase