Active Directory security appliance

Active Directory security auditing on a Raspberry Pi.

An AI-accelerated hardware appliance that performs 35+ read-only AD misconfiguration checks and monitors critical changes in real time. No cloud. No licensing fees. Zero attack surface.

35+
Security Checks
9
Audit Categories
26 TOPS
AI Acceleration
2
Operating Modes

From plug-in to hardened domain in three steps.

No agents to install. No admin rights to grant. No changes to your infrastructure.

01

Connect the appliance

Plug Supernova into your network switch. It binds to Active Directory using a low-privilege Domain User account and enforces network-scope verification before running anything.

02

Run the audit

The appliance runs 35+ read-only checks across 9 categories, scoring every misconfiguration by exploitability and impact using the Hailo-8 NPU, and mapping each to a MITRE ATT&CK technique.

03

Apply the fixes

Review the HTML report and copy the PowerShell remediation command for every finding. Then leave the Real-Time Guard running to alert on future dangerous changes.

Two modes. One appliance.

Supernova operates as a self-contained security tool plugged directly into your lab network switch. No agents. No cloud. No admin rights required.

Automated Misconfiguration Audit

Runs 35+ read-only LDAP checks across account policies, Kerberos delegation, ACL hygiene, GPO compliance, certificate services, and endpoint hardening. Every finding comes with a copy-paste PowerShell remediation command.

Real-Time Change Guard

Continuously monitors critical AD state — Domain Admin membership, DCSync rights, delegation — and fires Discord webhook alerts the moment a dangerous change is detected. No SIEM required.

AI Risk Scoring

Hailo-8 NPU (26 TOPS) scores every misconfiguration by exploitability and impact, maps findings to MITRE ATT&CK techniques, and prioritises the most critical issues first.

Professional Reports

Generates self-contained HTML reports and machine-parseable JSON. Every finding includes evidence, severity, MITRE ATT&CK reference, and step-by-step remediation.

Read-Only Architecture

Zero write operations to AD. No credential dumping. No exploitation. Service account with Domain User rights only. Hard guarantees enforced in code.

Air-Gapped Operation

Fully self-contained. No internet connectivity needed during audits. All packages and OS pre-loaded on NVMe SSD. Designed for isolated laboratory environments.

Why read-only?

Most security assessment tools attack your domain to prove a point. Supernova doesn't. It identifies, scores, and reports — nothing more. There is no code path that writes to Active Directory, dumps credentials, or executes commands on your systems.

No credential dumping Zero write operations No exploitation Domain User rights only Full audit trail

35+ checks across 9 domains.

Every auditor is read-only. Every finding maps to a specific MITRE ATT&CK technique with a PowerShell fix.

Account Policy
Kerberos Configuration
Privileged Groups
ACL Integrity
GPO Hygiene
Protocol Hardening
Certificate Services
Trust Configuration
Endpoint Security
T1558.003Kerberoasting
T1558.004AS-REP Roasting
T1003.006DCSync
T1557.001LLMNR / SMB Relay
T1098Account Manipulation
T1552.006GPP Credentials
T1649ADCS Abuse

Consumer hardware. Enterprise results.

Everything runs on a Raspberry Pi 5 with 8GB RAM, 256GB NVMe SSD, and an optional Hailo-8 AI accelerator. Total cost: under RM 2,500.

Raspberry Pi 5

8GB RAM, Quad-core ARM Cortex-A76

Hailo-8 NPU

M.2 2242, 26 TOPS AI Accelerator

256GB NVMe SSD

PCIe Gen 3, MakerDisk preloaded

Pironman 5-MAX

Dual M.2, OLED display, active cooling

Built with open tools.

PythonFlaskldap3ImpacketAPSchedulerHailo-8 NPURaspberry Pi OSPowerShellMITRE ATT&CKChart.jsDiscord WebhooksWindows Server

Common questions.

Does it modify my Active Directory?

No. Supernova is strictly read-only. There is no code path that writes to AD, dumps credentials, or executes commands on your systems. It only runs LDAP search and SMB read operations.

Does it need internet access?

No. The appliance is fully air-gapped. The operating system, Python packages, and AI models are pre-loaded on the NVMe SSD. It runs entirely within your isolated lab network.

What access does it need?

Only a standard Domain User account. No domain admin rights, no schema changes, no agents installed on any machine. That's enough for comprehensive read-only auditing.

Can it run on other hardware?

The architecture is designed for ARM64 single-board computers. The Raspberry Pi 5 is the reference platform, but the code runs on any Linux ARM64 system with Python 3.11+.

CBS/08/24B — German-Malaysian Institute

Final Year Project 2026. Supervised by Mohamad Aiman Hanif Apandi.

01

Luqman Zafree

Project Manager & Lead Developer

02

Sitee Hajarr

Security Researcher

03

Anaqie Mikael

Hardware & Infrastructure

04

Mohamad Aiman Hanif

Supervisor