Active Directory

Active Directory

Abusing Group Policy Objects for Privilege Escalation and Lateral Movement

How attackers weaponize editable Group Policy Objects with SharpGPOAbuse and GPP cpassword, plus blue-team detection and hardening.
Active Directory

Abusing Active Directory DACLs: GenericAll, WriteDACL, and the Path to Domain Compromise

How attackers abuse GenericAll and WriteDACL ACEs in Active Directory, and how blue teams detect and prevent it.
Active Directory

Shadow Credentials: Abusing msDS-KeyCredentialLink for AD Persistence and Privilege Escalation

Abuse msDS-KeyCredentialLink to forge Key Trust certificates, authenticate via PKINIT, and recover NTLM hashes.
Active Directory

Password Spraying Active Directory Without Tripping Lockouts

A practical, lockout-aware guide to password spraying Active Directory with kerbrute, plus detection and defense.
Active Directory

PetitPotam and Coercion Attacks: Forcing Authentication and Relaying to AD CS

How PetitPotam coerces machine authentication via MS-EFSRPC and relays it to AD CS for domain compromise — with detection and defense.