⚯ KEY-CREDENTIAL & gMSA AUDIT
// SHADOW CREDENTIAL & gMSA AUDITOR

Shadow Credential & gMSA Auditor

Two of the most current AD abuses in one pass. From an ACL / LDAP export the tool finds who can write msDS-KeyCredentialLink on a target (Shadow Credentials → PKINIT takeover, no password reset needed) and who can read a gMSA’s managed password (PrincipalsAllowedToRetrieveManagedPassword / ReadGMSAPassword). Analyzed locally — nothing leaves your browser.