Exposure discovery Institution-led

ORADAD

Windows command-line utility that exports Active Directory data through LDAP, including multi-domain forests, to support directory security audits and investigations.

By ANSSI · France

Institution-led

Primary sources connect this project to an EU public or research institution.

At a glance

Recorded facts
Response workflow
Exposure discovery
Developer or maintainer
ANSSI
Recorded country
France
Product model
Open source
Deployment
Desktop/CLI
Software license
GPL-3.0
Upstream status
Active
Evidence class
Institution-led

What the sources establish

Origin note

Published in ANSSI’s official project organization by the French national cybersecurity agency.

Reported capabilities

  • Exports Active Directory data via LDAP.
  • Supports multi-domain forests.
  • Provides configurable x86 and x64 executable releases.

Scope and limits

Primarily documented as an audit data collector rather than a complete vulnerability scanner or incident response platform.

Inspect the research evidence 3 source observations
  1. identity / capabilities / deployment / license

    README says ORADAD dumps LDAP data for security audits, supports multi-domain forests and is invoked as a Windows executable; repository carries GPL-3.0.

    Read source
  2. origin / country

    ANSSI organization profile states its repositories are projects developed by the French agency.

    Read source
  3. maintenance

    Official releases list v3.6.220b in July 2026, primarily extending executable validity dates.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Scope exposure discovery, validate vulnerability findings, prioritize affected assets and verify remediation. Practical guidance with documented European tools.

From vulnerability finding to verified remediation