Active Directory study guide
My Active Directory notes, organized into eight chapters. Read in order or jump to the topic you need.
Start with chapter 01Inside the collection
Choose a chapter- 01
Enumeration & Fundamentals
Active Directory enumeration techniques for penetration testers - DNS, SMB, LDAP, RPC, and initial domain reconnaissance
- 02
Kerberos Attacks
Complete guide to Kerberos-based attacks - Kerberoasting, AS-REP Roasting, Golden/Silver Tickets, Pass-the-Ticket, and Delegation abuse
- 03
ADCS & Certificate Attacks
Active Directory Certificate Services exploitation - ESC1 through ESC16, Certifried, enumeration and attack chains
- 04
ACE Abuse & Lateral Movement
Active Directory ACL exploitation, DPAPI secrets, credential dumping, Shadow Credentials, and remote access techniques
- 05
NTLM Relay Attacks
Complete NTLM relay guide - poisoning, coercion, SMB/LDAP/ADCS relay, and cross-protocol exploitation
- 06
Trust Exploitation
Active Directory trust attacks - intra-forest and cross-forest exploitation, ExtraSids, SID History, PAM Trust abuse
- 07
MSSQL, Exchange & SCCM
Exploiting enterprise services in Active Directory - MSSQL lateral movement, Exchange phishing, and SCCM takeover
- 08
BloodyAD & Advanced Tooling
BloodyAD command reference and advanced Active Directory tooling for penetration testers