discovered 14 Aug 2026
Scan-broken-owner
→ View on GitHubThe Scan-broken-owner tool is a PowerShell script designed to audit Active Directory for vulnerabilities related to object ownership, specifically targeting "broken owners" which pose a security risk. Its primary use case is to help organizations identify and mitigate control-takeover vulnerabilities by ensuring that Active Directory objects are owned by appropriate, legitimate users, thereby preventing potential attacks such as Kerberos Resource-Based Constrained Delegation abuse. Notable features include the generation of a detailed HTML report, the ability to skip specific users or groups during scans, and operation without requiring administrative privileges.