Active Directory

Active Directory

Responder and Internal Name-Resolution Poisoning

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

CrackMapExec/NetExec for Internal Network Assessment

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Kerberos Bronze Bit Attack (CVE-2020-17049) Explained

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Pre-Created Computer Accounts and Pre-Windows 2000 Compatibility Risks

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Kerberos Encryption Types: RC4 vs AES and Downgrade Risks

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Active Directory Trust Attacks: SID History and Cross-Forest Escalation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

LAPS Internals: Storing, Reading, and Attacking Local Admin Passwords

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Group Managed Service Accounts (gMSA) and the KDS Root Key

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Timeroasting: Abusing NTP Authentication in Active Directory

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

sAMAccountName Spoofing: noPac (CVE-2021-42278 / CVE-2021-42287)

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Kerberoasting and AS-REP Roasting Detection Deep Dive

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Pass-the-Hash: Authenticating with NTLM Hashes

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Golden Ticket Attacks: Forging TGTs with the KRBTGT Hash

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Kerberos Constrained Delegation (KCD) and S4U Abuse

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Targeted Kerberoasting with Write Access

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

NTLM Relay to LDAP and SMB: Coercion to Compromise

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

LDAP Reconnaissance for Active Directory Attack Paths

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

GPO Abuse: Code Execution via Group Policy

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

DACL Abuse in Active Directory: GenericAll and WriteDACL

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Shadow Credentials: Key Trust Account Takeover

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

AD CS ESC1: Vulnerable Certificate Template Enrollment

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Resource-Based Constrained Delegation (RBCD) Abuse

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Unconstrained Delegation Abuse and TGT Capture

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Overpass-the-Hash: From NT Hash to Kerberos TGT

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Silver Ticket Attacks: Forging Service Tickets Offline

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Kerberoasting: The Complete Guide to Mechanics, Attack, and Defense

A complete guide to Kerberoasting: how SPNs and TGS-REP enable offline cracking, plus detection and defense.
Active Directory

AS-REP Roasting: Abusing Accounts Without Kerberos Pre-Authentication

How attackers extract and crack Kerberos AS-REP hashes from accounts with pre-authentication disabled, and how blue teams defend.
Active Directory

DCSync Attack and Defense: Abusing Directory Replication Rights

How DCSync abuses AD replication rights via DRSUAPI to dump credentials, and how blue teams can detect and stop it.
Active Directory

NTLM Relay Attacks in Practice: Hands-On with ntlmrelayx

A practical walkthrough of NTLM relay attacks with Responder and ntlmrelayx, covering SMB and LDAP relay plus blue-team defenses.
Active Directory

Pass-the-Hash and Pass-the-Ticket in Practice

A hands-on guide to NTLM Pass-the-Hash and Kerberos Pass-the-Ticket attacks, with practical tooling and Blue Team defenses.
Active Directory

Golden Ticket Attacks: Abusing krbtgt for Domain Persistence

How attackers forge Kerberos TGTs with the krbtgt hash to gain persistent domain dominance, and how blue teams detect and defend.
Active Directory

Silver Ticket Attacks: Forging Kerberos Service Tickets

How attackers forge Kerberos TGS service tickets using a service account hash, and how blue teams detect and prevent it.
Active Directory

Abusing Unconstrained Delegation: From Printer Bug to Domain Compromise

How attackers abuse Kerberos Unconstrained Delegation to capture TGTs and pivot to Domain Admin, plus blue-team defenses.
Active Directory

Abusing Kerberos Constrained Delegation: S4U2Self and S4U2Proxy

A practical walkthrough of abusing Kerberos Constrained Delegation via S4U2Self and S4U2Proxy to impersonate privileged users.
Active Directory

Resource-Based Constrained Delegation (RBCD) Attack: From a Single Computer Account to Domain Compromise

A practical walkthrough of the Resource-Based Constrained Delegation attack, abusing msDS-AllowedToActOnBehalfOfOtherIdentity for privilege escalation.
Active Directory

ADCS Attacks: A Practical Overview of ESC1 Through ESC8

A field guide to Active Directory Certificate Services attacks ESC1-ESC8, with Certipy commands and Blue Team defenses.
Active Directory

Introduction to Attack Path Analysis with BloodHound

Learn how to collect AD data with SharpHound and use BloodHound, neo4j, and Cypher to find the shortest path to Domain Admins.
Active Directory

LDAP Enumeration Techniques: ldapsearch and windapsearch

A practical guide to enumerating Active Directory over LDAP with ldapsearch, windapsearch, and bloodyAD, plus blue-team defenses.
Active Directory

SMB Enumeration and Null Session Exploitation

A practical guide to enumerating SMB and abusing null sessions with enum4linux-ng, smbclient, rpcclient, and RID cycling.
Active Directory

Inside Kerberos: A Deep Dive into the Protocol Internals

A practical breakdown of Kerberos internals: AS-REQ, TGS-REQ, the PAC, and why RC4 vs AES etypes matter for attackers and defenders.