An AI-accelerated hardware appliance that performs 35+ read-only AD misconfiguration checks and monitors critical changes in real time. No cloud. No licensing fees. Zero attack surface.
No agents to install. No admin rights to grant. No changes to your infrastructure.
Plug Supernova into your network switch. It binds to Active Directory using a low-privilege Domain User account and enforces network-scope verification before running anything.
The appliance runs 35+ read-only checks across 9 categories, scoring every misconfiguration by exploitability and impact using the Hailo-8 NPU, and mapping each to a MITRE ATT&CK technique.
Review the HTML report and copy the PowerShell remediation command for every finding. Then leave the Real-Time Guard running to alert on future dangerous changes.
Supernova operates as a self-contained security tool plugged directly into your lab network switch. No agents. No cloud. No admin rights required.
Runs 35+ read-only LDAP checks across account policies, Kerberos delegation, ACL hygiene, GPO compliance, certificate services, and endpoint hardening. Every finding comes with a copy-paste PowerShell remediation command.
Continuously monitors critical AD state — Domain Admin membership, DCSync rights, delegation — and fires Discord webhook alerts the moment a dangerous change is detected. No SIEM required.
Hailo-8 NPU (26 TOPS) scores every misconfiguration by exploitability and impact, maps findings to MITRE ATT&CK techniques, and prioritises the most critical issues first.
Generates self-contained HTML reports and machine-parseable JSON. Every finding includes evidence, severity, MITRE ATT&CK reference, and step-by-step remediation.
Zero write operations to AD. No credential dumping. No exploitation. Service account with Domain User rights only. Hard guarantees enforced in code.
Fully self-contained. No internet connectivity needed during audits. All packages and OS pre-loaded on NVMe SSD. Designed for isolated laboratory environments.
Every auditor is read-only. Every finding maps to a specific MITRE ATT&CK technique with a PowerShell fix.
T1558.003KerberoastingT1558.004AS-REP RoastingT1003.006DCSyncT1557.001LLMNR / SMB RelayT1098Account ManipulationT1552.006GPP CredentialsT1649ADCS AbuseEverything runs on a Raspberry Pi 5 with 8GB RAM, 256GB NVMe SSD, and an optional Hailo-8 AI accelerator. Total cost: under RM 2,500.
No. Supernova is strictly read-only. There is no code path that writes to AD, dumps credentials, or executes commands on your systems. It only runs LDAP search and SMB read operations.
No. The appliance is fully air-gapped. The operating system, Python packages, and AI models are pre-loaded on the NVMe SSD. It runs entirely within your isolated lab network.
Only a standard Domain User account. No domain admin rights, no schema changes, no agents installed on any machine. That's enough for comprehensive read-only auditing.
The architecture is designed for ARM64 single-board computers. The Raspberry Pi 5 is the reference platform, but the code runs on any Linux ARM64 system with Python 3.11+.
Final Year Project 2026. Supervised by Mohamad Aiman Hanif Apandi.