Active Directory

Active Directory

AD is the gravity well of every internal engagement. Understand the directory, the auth protocols, and the trust model — then everything else is pattern matching.

Prereqs

  • network-pentesting stages 1–2.
  • A lab: GOAD, build your own forest with at least one child domain, or an HTB Pro Lab.

Stage 1 — fundamentals

Stage 2 — intermediate

Kerberos abuse:

ACL & object abuse:

Credential primitives:

Stage 3 — advanced

When you’re “done”

  • You can describe every step in the path from a domain user to Enterprise Admin, including which detection rules each step trips and what the safer alternative is.
  • You can read a BloodHound graph in seconds and pick the lowest-noise edge.

References