← All collections
Study collection / 8 chapters

Active Directory study guide

My Active Directory notes, organized into eight chapters. Read in order or jump to the topic you need.

Start with chapter 01

Inside the collection

Choose a chapter
  1. 01

    Enumeration & Fundamentals

    Active Directory enumeration techniques for penetration testers - DNS, SMB, LDAP, RPC, and initial domain reconnaissance

    Guide · 9 min read
  2. 02

    Kerberos Attacks

    Complete guide to Kerberos-based attacks - Kerberoasting, AS-REP Roasting, Golden/Silver Tickets, Pass-the-Ticket, and Delegation abuse

    Guide · 12 min read
  3. 03

    ADCS & Certificate Attacks

    Active Directory Certificate Services exploitation - ESC1 through ESC16, Certifried, enumeration and attack chains

    Guide · 17 min read
  4. 04

    ACE Abuse & Lateral Movement

    Active Directory ACL exploitation, DPAPI secrets, credential dumping, Shadow Credentials, and remote access techniques

    Guide · 10 min read
  5. 05

    NTLM Relay Attacks

    Complete NTLM relay guide - poisoning, coercion, SMB/LDAP/ADCS relay, and cross-protocol exploitation

    Guide · 16 min read
  6. 06

    Trust Exploitation

    Active Directory trust attacks - intra-forest and cross-forest exploitation, ExtraSids, SID History, PAM Trust abuse

    Guide · 14 min read
  7. 07

    MSSQL, Exchange & SCCM

    Exploiting enterprise services in Active Directory - MSSQL lateral movement, Exchange phishing, and SCCM takeover

    Guide · 17 min read
  8. 08

    BloodyAD & Advanced Tooling

    BloodyAD command reference and advanced Active Directory tooling for penetration testers

    Guide · 10 min read