An educational Active Directory attack-and-defense guide focused on understanding how common Active Directory attack paths work, how they are executed in controlled lab environments, what evidence they generate, and how defenders can detect and mitigate them.
Author: BackdoorAli - Github.com/BackdoorAli
Active Directory remains one of the most important technologies to understand when studying enterprise penetration testing, red teaming, identity security, and Windows network defense.
This repository is designed as a practical educational reference covering Active Directory reconnaissance, enumeration, credential attacks, privilege escalation, lateral movement, domain compromise, persistence, detection, and defensive hardening.
The project combines four perspectives:
Theory
|
v
Enumeration
|
v
Controlled Exploitation
|
v
Detection and Remediation
The goal is to not just simply listen to commands!
Each technique is intended to explain:
- What the technique is
- Why it works
- Which Active Directory components are involved
- What permissions or conditions are required
- How the environment can be enumerated
- How the technique can be reproduced in an authorised lab
- What commands and tools are commonly used
- What happens internally when those commands execute
- What evidence is generated
- How defenders can detect the activity
- How the underlying weakness can be mitigated
- How the technique maps to MITRE ATT&CK
This repository intentionally includes practical command-driven walkthroughs.
The general progression used throughout the guide is:
Identify the target condition
|
v
Enumerate the environment
|
v
Confirm the misconfiguration
|
v
Run command X
|
v
Run command Y
|
v
Obtain the intended lab objective
For some lab scenarios, the educational objective may ultimately resemble:
run command X
run command Y
get Domain Admin
However, the commands will not be presented without context while using my guide, read thoroughly, this is an educational guide after all, I assume you're here to learn :)
Every practical section will explain why a command is being executed, what it communicates with, what permissions it requires, what successful and unsuccessful output means, and what defensive telemetry may be produced.
This project aims to provide a structured learning path for:
- Active Directory fundamentals
- Windows domain architecture
- LDAP
- Kerberos
- NTLM
- Active Directory reconnaissance
- Domain enumeration
- BloodHound attack-path analysis
- Credential access techniques
- Kerberos-related attacks
- Active Directory ACL abuse
- Local privilege escalation
- Domain privilege escalation
- Lateral movement
- Active Directory Certificate Services
- Delegation abuse
- Domain Controller security
- Forest and domain trusts
- Persistence concepts
- Windows security logging
- Detection engineering
- Identity hardening
- Active Directory remediation
Active-Directory-Exploitation-Educational-Guide/
|
|-- README.md
|-- LICENSE
|-- ETHICS.md
|-- SECURITY.md
|
|-- docs/
| |
| |-- 00-ad-fundamentals/
| |
| |-- 01-enumeration/
| |
| |-- 02-credential-access/
| |
| |-- 03-privilege-escalation/
| |
| |-- 04-lateral-movement/
| |
| |-- 05-domain-compromise/
| |
| |-- 06-persistence/
| |
| `-- 07-detection-and-hardening/
|
|-- labs/
|
|-- diagrams/
|
|-- detection/
| |
| |-- sigma/
| |-- powershell/
| `-- queries/
|
|-- scripts/
| |
| |-- lab-setup/
| `-- defensive-auditing/
|
`-- references/
The repository will be expanded incrementally.
Each directory will be introduced only when the material required for that section is added, so naturally some material might still be in production as I've been working on this for a little while now, most of summer 2026 :P
Before exploring exploitation techniques, the guide establishes the technologies that make Active Directory work.
Topics will include:
Active Directory architecture
Domains
Forests
Trees
Organizational Units
Users
Groups
Computers
Domain Controllers
Global Catalog
LDAP
Kerberos
NTLM
DNS (the usual suspect imho)
Group Policy
Access Control Lists
Security Identifiers
Trust relationships
Understanding these components is important because Active Directory attacks generally abuse intended functionality, excessive permissions, weak configurations, exposed credentials, or trust relationships rather than a single software vulnerability.
Enumeration is the process of understanding the environment before attempting exploitation.
Topics will include:
Domain discovery
Domain Controller discovery
User enumeration
Group enumeration
Computer enumeration
Privileged group discovery
Service Principal Names
Group Policy enumeration
Network shares
Logged-on users
Sessions
ACLs
Organizational Units
Trust relationships
BloodHound collection
BloodHound attack-path analysis
Tools may include:
Native Windows commands
PowerShell
PowerView
SharpHound
BloodHound
LDAP utilities
Impacket
This module examines how credentials and authentication material can become exposed or abused inside Active Directory environments.
Topics will include:
Kerberos ticket fundamentals
Service accounts
Service Principal Names
Kerberoasting
AS-REP Roasting
Credential exposure
Password policy analysis
Authentication material
NTLM concepts
Kerberos ticket analysis
Each technique will include both attacker and defender perspectives.
Privilege escalation in Active Directory frequently involves discovering permissions that provide unintended control over another object.
Topics will include:
Local privilege escalation
Group membership abuse
Active Directory ACLs
GenericAll
GenericWrite
WriteDACL
WriteOwner
ForceChangePassword
AddMember
Delegation
Resource-Based Constrained Delegation
Active Directory Certificate Services
Misconfigured service accounts
BloodHound privilege paths
Lateral movement covers techniques used to move between systems after obtaining valid credentials or sufficient access.
Topics will include:
SMB
WinRM
PowerShell Remoting
WMI
RDP
Remote service concepts
Credential reuse (you can read more about this in on of my other repos "azure-red-team-abuse-scenarios at: https://github.com/BackdoorAli/azure-red-team-abuse-scenarios)
Administrative shares
Remote authentication
The emphasis will be on understanding which credentials, privileges, protocols, and network conditions make each method possible.
This module examines attack paths that can lead to highly privileged Active Directory access.
Topics will include:
Domain Admin pathways
DCSync
Directory replication permissions
Kerberos ticket abuse
Domain Controller compromise concepts
Credential material on Domain Controllers
Privileged ACL relationships
Trust abuse
Forest-level attack concepts
The guide will distinguish between obtaining a privileged account and obtaining permissions that are effectively equivalent to privileged access.
Persistence techniques can allow access to survive credential changes, system reboots, administrative cleanup, or other defensive actions.
Topics will include:
Persistence through directory permissions
Privileged group persistence
Kerberos persistence concepts
Account-based persistence
ACL persistence
Authentication persistence
Domain-level persistence indicators
The emphasis will include both how persistence mechanisms work and how defenders can identify them.
Every offensive technique covered by this repository will ultimately connect to defensive guidance.
Topics will include:
Windows Security Event Logs
PowerShell logging
Kerberos logging
NTLM monitoring
LDAP visibility
Domain Controller auditing
BloodHound remediation
Privileged account management
Service account security
Credential hygiene
Tiered administration
Attack-path reduction
Active Directory Certificate Services hardening
Trust hardening
Detection engineering
Sigma rules
Security monitoring queries
Where practical, individual attack techniques will follow a common structure.
1. Overview
2. Why the Technique Works
3. Active Directory Components Involved
4. Required Conditions
5. Lab Scenario
6. Enumeration
7. Exploitation Walkthrough
8. Command Breakdown
9. Internal Technical Explanation
10. Expected Results
11. Evidence Generated
12. Detection
13. Mitigation
14. MITRE ATT&CK Mapping
15. References
A simplified Active Directory attack path might resemble:
Initial Domain User
|
v
Domain Enumeration
|
v
Identify Service Account
|
v
Kerberos Enumeration
|
v
Credential Access
|
v
Discover ACL Relationship
|
v
Privilege Escalation
|
v
Lateral Movement
|
v
Privileged Domain Access
Real environments vary significantly.
The purpose of the repository is to understand the relationships that make these paths possible.
Techniques will frequently be presented from both perspectives.
Enumeration
|
v
Identify Weakness
|
v
Validate Access
|
v
Exploit Misconfiguration
|
v
Expand Access
Authentication Logs
|
v
Directory Activity
|
v
Process Activity
|
v
Network Activity
|
v
Correlation
|
v
Detection
Understanding both perspectives is essential for learning how Active Directory attacks actually appear in enterprise environments.
Practical exercises in this repository are intended for controlled environments such as:
Personal Active Directory labs
Hack The Box
TryHackMe
Authorized penetration tests
Authorized red-team engagements
Capture-the-Flag environments
Purpose-built vulnerable networks
Systems where explicit permission has been granted
Do not perform the techniques described in this repository against systems, networks, domains, accounts, or organisations without authorisation.
The project may reference widely used Active Directory security tools including:
BloodHound
SharpHound
PowerView
PowerSploit
Impacket
Rubeus
Mimikatz
Certipy
Certify
NetExec
CrackMapExec
LDAP utilities
Native PowerShell
Windows administrative utilities
Tools are included to demonstrate the underlying Active Directory concepts.
Understanding the protocol, permission, or configuration being abused is more important than memorizing a tool command.
Where appropriate, techniques will be mapped to relevant MITRE ATT&CK tactics and techniques.
Example categories include:
Discovery
Credential Access
Privilege Escalation
Lateral Movement
Persistence
Defense Evasion
Collection
MITRE mappings will be included primarily to connect practical lab activity with terminology commonly used by security teams.
The repository will eventually contain a dedicated detection section:
detection/
|
|-- sigma/
|
|-- powershell/
|
`-- queries/
Detection material may include:
Windows Event ID analysis
Sigma rules
PowerShell detection examples
Authentication analysis
Kerberos monitoring
LDAP monitoring concepts
Domain Controller telemetry
Privilege modification detection
Suspicious group membership changes
Attack-path remediation
Architecture and attack-path diagrams will be used where visual explanations improve understanding.
Planned diagram categories include:
Active Directory architecture
Kerberos authentication
NTLM authentication
LDAP communication
BloodHound attack paths
ACL relationships
Delegation
Domain trusts
Forest trusts
Credential attack flows
Lateral movement paths
Domain compromise paths
The repository follows a simple principle:
Do not only learn the command.
Learn why the command works.
A security tester should understand:
What am I querying?
Why does the server answer?
Which protocol is being used?
Which credentials are being presented?
Which permissions allow this action?
What changes inside Active Directory?
What logs are created?
What would a defender see?
How can the weakness be removed?
This approach turns individual commands into reusable knowledge.
[Some section still in development]
Phase 1 - Repository foundation
Phase 2 - Active Directory fundamentals
Phase 3 - Enumeration
Phase 4 - Credential access
Phase 5 - Privilege escalation
Phase 6 - Lateral movement
Phase 7 - Domain compromise
Phase 8 - Persistence
Phase 9 - Detection and hardening
Phase 10 - Labs, diagrams, and detection content
This repository is an independent educational project.
Technical information will be cross-referenced against authoritative documentation and established security research where appropriate.
Reference material will include:
Microsoft documentation
MITRE ATT&CK
SpecterOps research
BloodHound documentation
Impacket documentation
Tool documentation
Security research publications
Active Directory security research
Additional project references will be maintained under:
references/
All offensive-security material in this repository is intended for education, authorised security testing, and defensive research.
A dedicated ETHICS.md document will define the project's rules of use.