Active Directory

Active Directory

Kerberos Bronze Bit Attack (CVE-2020-17049) Explained

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Pre-Created Computer Accounts and Pre-Windows 2000 Compatibility Risks

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Kerberos Encryption Types: RC4 vs AES and Downgrade Risks

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Active Directory Trust Attacks: SID History and Cross-Forest Escalation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

LAPS Internals: Storing, Reading, and Attacking Local Admin Passwords

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Group Managed Service Accounts (gMSA) and the KDS Root Key

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Timeroasting: Abusing NTP Authentication in Active Directory

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

sAMAccountName Spoofing: noPac (CVE-2021-42278 / CVE-2021-42287)

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Kerberoasting and AS-REP Roasting Detection Deep Dive

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Kerberoasting: The Complete Guide to Mechanics, Attack, and Defense

A complete guide to Kerberoasting: how SPNs and TGS-REP enable offline cracking, plus detection and defense.
Active Directory

AS-REP Roasting: Abusing Accounts Without Kerberos Pre-Authentication

How attackers extract and crack Kerberos AS-REP hashes from accounts with pre-authentication disabled, and how blue teams defend.
Active Directory

DCSync Attack and Defense: Abusing Directory Replication Rights

How DCSync abuses AD replication rights via DRSUAPI to dump credentials, and how blue teams can detect and stop it.
Active Directory

NTLM Relay Attacks in Practice: Hands-On with ntlmrelayx

A practical walkthrough of NTLM relay attacks with Responder and ntlmrelayx, covering SMB and LDAP relay plus blue-team defenses.
Active Directory

Golden Ticket Attacks: Abusing krbtgt for Domain Persistence

How attackers forge Kerberos TGTs with the krbtgt hash to gain persistent domain dominance, and how blue teams detect and defend.
Active Directory

Silver Ticket Attacks: Forging Kerberos Service Tickets

How attackers forge Kerberos TGS service tickets using a service account hash, and how blue teams detect and prevent it.
Active Directory

Abusing Unconstrained Delegation: From Printer Bug to Domain Compromise

How attackers abuse Kerberos Unconstrained Delegation to capture TGTs and pivot to Domain Admin, plus blue-team defenses.
Active Directory

Abusing Kerberos Constrained Delegation: S4U2Self and S4U2Proxy

A practical walkthrough of abusing Kerberos Constrained Delegation via S4U2Self and S4U2Proxy to impersonate privileged users.
Active Directory

Resource-Based Constrained Delegation (RBCD) Attack: From a Single Computer Account to Domain Compromise

A practical walkthrough of the Resource-Based Constrained Delegation attack, abusing msDS-AllowedToActOnBehalfOfOtherIdentity for privilege escalation.
Active Directory

ADCS Attacks: A Practical Overview of ESC1 Through ESC8

A field guide to Active Directory Certificate Services attacks ESC1-ESC8, with Certipy commands and Blue Team defenses.
Active Directory

Introduction to Attack Path Analysis with BloodHound

Learn how to collect AD data with SharpHound and use BloodHound, neo4j, and Cypher to find the shortest path to Domain Admins.
Active Directory

LDAP Enumeration Techniques: ldapsearch and windapsearch

A practical guide to enumerating Active Directory over LDAP with ldapsearch, windapsearch, and bloodyAD, plus blue-team defenses.
Active Directory

SMB Enumeration and Null Session Exploitation

A practical guide to enumerating SMB and abusing null sessions with enum4linux-ng, smbclient, rpcclient, and RID cycling.
Active Directory

Inside Kerberos: A Deep Dive into the Protocol Internals

A practical breakdown of Kerberos internals: AS-REQ, TGS-REQ, the PAC, and why RC4 vs AES etypes matter for attackers and defenders.
Active Directory

Abusing Group Policy Objects for Privilege Escalation and Lateral Movement

How attackers weaponize editable Group Policy Objects with SharpGPOAbuse and GPP cpassword, plus blue-team detection and hardening.
Active Directory

Abusing Active Directory DACLs: GenericAll, WriteDACL, and the Path to Domain Compromise

How attackers abuse GenericAll and WriteDACL ACEs in Active Directory, and how blue teams detect and prevent it.
Active Directory

Shadow Credentials: Abusing msDS-KeyCredentialLink for AD Persistence and Privilege Escalation

Abuse msDS-KeyCredentialLink to forge Key Trust certificates, authenticate via PKINIT, and recover NTLM hashes.
Active Directory

Password Spraying Active Directory Without Tripping Lockouts

A practical, lockout-aware guide to password spraying Active Directory with kerbrute, plus detection and defense.
Windows Privesc

Lateral Movement and Persistence with WMI

How attackers abuse WMI for remote code execution and stealthy persistence, plus the detection and defenses blue teams need.
Windows Privesc

PrintNightmare: Abusing the Windows Print Spooler for Privilege Escalation and RCE

A practical walkthrough of CVE-2021-1675 and CVE-2021-34527 (PrintNightmare): abusing AddPrinterDriverEx for SYSTEM-level code execution, plus blue-team defenses.
Windows Privesc

Abusing SeBackupPrivilege and SeRestorePrivilege for Windows Privilege Escalation

How attackers abuse SeBackupPrivilege/SeRestorePrivilege to dump SAM, SYSTEM, and ntds.dit, plus blue-team detection and defense.
Tools & Defense

Mastering the Impacket Suite: From Lateral Movement to Credential Extraction

A practical tour of Impacket's psexec, wmiexec, secretsdump, GetUserSPNs and smbserver, plus blue-team detection.
Tools & Defense

NetExec (CrackMapExec) in Practice: SMB Enumeration, SAM Dumping, and Password Spraying

A practical guide to NetExec (nxc) for SMB enumeration, SAM dumping, password spraying, and modules — plus blue-team detection.
Tools & Defense

Active Directory Defense and Monitoring: Tiering, LAPS, and Detection Engineering

A practical defender's guide to AD tiering, LAPS, honeypot accounts, ADCS hardening, and the event IDs that catch attackers.
Vulnlab

Vulnlab Baby Walkthrough by Yunolay (LDAP Enumeration, SMB Password Spraying, Privilege escalation using SeBackupPrivilege and SeRestorePrivilege)

OverviewActive Directory PentestingBaby (Solo, Windows)Junior Level Windows Active Directory MachineYou will learn about...