Active Directory security auditing on a Raspberry Pi.

An AI-accelerated hardware appliance that performs 35+ read-only AD misconfiguration checks and monitors critical changes in real time. No cloud. No licensing fees. Zero attack surface.

View on GitHub Launch Dashboard Learn more
35+
Security Checks
9
Audit Categories
26 TOPS
AI Acceleration
2
Operating Modes
How It Works

From plug-in to hardened domain in three steps.

No agents to install. No admin rights to grant. No changes to your infrastructure.

01

Connect the appliance

Plug Supernova into your network switch. It binds to Active Directory using a low-privilege Domain User account and enforces network-scope verification before running anything.

02

Run the audit

The appliance runs 35+ read-only checks across 9 categories, scoring every misconfiguration by exploitability and impact using the Hailo-8 NPU, and mapping each to a MITRE ATT&CK technique.

03

Apply the fixes

Review the HTML report and copy the PowerShell remediation command for every finding. Then leave the Real-Time Guard running to alert on future dangerous changes.

What It Does

Two modes. One appliance.

Supernova operates as a self-contained security tool plugged directly into your lab network switch. No agents. No cloud. No admin rights required.

📡

Automated Misconfiguration Audit

Runs 35+ read-only LDAP checks across account policies, Kerberos delegation, ACL hygiene, GPO compliance, certificate services, and endpoint hardening. Every finding comes with a copy-paste PowerShell remediation command.

🛡

Real-Time Change Guard

Continuously monitors critical AD state — Domain Admin membership, DCSync rights, delegation — and fires Discord webhook alerts the moment a dangerous change is detected. No SIEM required.

🤖

AI Risk Scoring

Hailo-8 NPU (26 TOPS) scores every misconfiguration by exploitability and impact, maps findings to MITRE ATT&CK techniques, and prioritises the most critical issues first.

📄

Professional Reports

Generates self-contained HTML reports and machine-parseable JSON. Every finding includes evidence, severity, MITRE ATT&CK reference, and step-by-step remediation.

📡

Read-Only Architecture

Zero write operations to AD. No credential dumping. No exploitation. Service account with Domain User rights only. Hard guarantees enforced in code.

🔌

Air-Gapped Operation

Fully self-contained. No internet connectivity needed during audits. All packages and OS pre-loaded on NVMe SSD. Designed for isolated laboratory environments.

🛡

Why read-only?

Most security assessment tools attack your domain to prove a point. Supernova doesn't. It identifies, scores, and reports — nothing more. There is no code path that writes to Active Directory, dumps credentials, or executes commands on your systems.

No credential dumping Zero write operations No exploitation Domain User rights only Full audit trail
Audit Categories

35+ checks across 9 domains.

Every auditor is read-only. Every finding maps to a specific MITRE ATT&CK technique with a PowerShell fix.

Account Policy
Kerberos Configuration
Privileged Groups
ACL Integrity
GPO Hygiene
Protocol Hardening
Certificate Services
Trust Configuration
Endpoint Security
T1558.003Kerberoasting
T1558.004AS-REP Roasting
T1003.006DCSync
T1557.001LLMNR / SMB Relay
T1098Account Manipulation
T1552.006GPP Credentials
T1649ADCS Abuse
Hardware Stack

Consumer hardware. Enterprise results.

Everything runs on a Raspberry Pi 5 with 8GB RAM, 256GB NVMe SSD, and an optional Hailo-8 AI accelerator. Total cost: under RM 2,500.

Raspberry Pi 5
8GB RAM, Quad-core ARM Cortex-A76
Hailo-8 NPU
M.2 2242, 26 TOPS AI Accelerator
256GB NVMe SSD
PCIe Gen 3, MakerDisk preloaded
Pironman 5-MAX
Dual M.2, OLED display, active cooling
Technology Stack

Built with open tools.

Python Flask ldap3 Impacket APScheduler Hailo-8 NPU Raspberry Pi OS PowerShell MITRE ATT&CK Chart.js Discord Webhooks Windows Server
FAQ

Common questions.

Does it modify my Active Directory?

No. Supernova is strictly read-only. There is no code path that writes to AD, dumps credentials, or executes commands on your systems. It only runs LDAP search and SMB read operations.

Does it need internet access?

No. The appliance is fully air-gapped. The operating system, Python packages, and AI models are pre-loaded on the NVMe SSD. It runs entirely within your isolated lab network.

What access does it need?

Only a standard Domain User account. No domain admin rights, no schema changes, no agents installed on any machine. That's enough for comprehensive read-only auditing.

Can it run on other hardware?

The architecture is designed for ARM64 single-board computers. The Raspberry Pi 5 is the reference platform, but the code runs on any Linux ARM64 system with Python 3.11+.

Team

CBS/08/24B — German-Malaysian Institute

Final Year Project 2026. Supervised by Mohamad Aiman Hanif Apandi.

Luqman Zafree

Project Manager & Lead Developer

Sitee Hajarr

Security Researcher

Anaqie Mikael

Hardware & Infrastructure

Mohamad Aiman Hanif

Supervisor