Skip to content

About

Educational Active Directory exploitation and defence guide covering enumeration, credential access, privilege escalation, lateral movement, persistence, detection and hardening.

Topics

Resources

Security policy

Stars

1 star

Watchers

0 watching

Forks

Latest commit

 

History

6 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Active Directory Exploitation Educational Guide

An educational Active Directory attack-and-defense guide focused on understanding how common Active Directory attack paths work, how they are executed in controlled lab environments, what evidence they generate, and how defenders can detect and mitigate them.

Author: BackdoorAli - Github.com/BackdoorAli


Project Overview

Active Directory remains one of the most important technologies to understand when studying enterprise penetration testing, red teaming, identity security, and Windows network defense.

This repository is designed as a practical educational reference covering Active Directory reconnaissance, enumeration, credential attacks, privilege escalation, lateral movement, domain compromise, persistence, detection, and defensive hardening.

The project combines four perspectives:

Theory
   |
   v
Enumeration
   |
   v
Controlled Exploitation
   |
   v
Detection and Remediation

The goal is to not just simply listen to commands!

Each technique is intended to explain:

  • What the technique is
  • Why it works
  • Which Active Directory components are involved
  • What permissions or conditions are required
  • How the environment can be enumerated
  • How the technique can be reproduced in an authorised lab
  • What commands and tools are commonly used
  • What happens internally when those commands execute
  • What evidence is generated
  • How defenders can detect the activity
  • How the underlying weakness can be mitigated
  • How the technique maps to MITRE ATT&CK

Practical Command-Driven Learning

This repository intentionally includes practical command-driven walkthroughs.

The general progression used throughout the guide is:

Identify the target condition
        |
        v
Enumerate the environment
        |
        v
Confirm the misconfiguration
        |
        v
Run command X
        |
        v
Run command Y
        |
        v
Obtain the intended lab objective

For some lab scenarios, the educational objective may ultimately resemble:

run command X
run command Y
get Domain Admin

However, the commands will not be presented without context while using my guide, read thoroughly, this is an educational guide after all, I assume you're here to learn :)

Every practical section will explain why a command is being executed, what it communicates with, what permissions it requires, what successful and unsuccessful output means, and what defensive telemetry may be produced.


Repository Objectives

This project aims to provide a structured learning path for:

  • Active Directory fundamentals
  • Windows domain architecture
  • LDAP
  • Kerberos
  • NTLM
  • Active Directory reconnaissance
  • Domain enumeration
  • BloodHound attack-path analysis
  • Credential access techniques
  • Kerberos-related attacks
  • Active Directory ACL abuse
  • Local privilege escalation
  • Domain privilege escalation
  • Lateral movement
  • Active Directory Certificate Services
  • Delegation abuse
  • Domain Controller security
  • Forest and domain trusts
  • Persistence concepts
  • Windows security logging
  • Detection engineering
  • Identity hardening
  • Active Directory remediation

Planned Project Structure

Active-Directory-Exploitation-Educational-Guide/
|
|-- README.md
|-- LICENSE
|-- ETHICS.md
|-- SECURITY.md
|
|-- docs/
|   |
|   |-- 00-ad-fundamentals/
|   |
|   |-- 01-enumeration/
|   |
|   |-- 02-credential-access/
|   |
|   |-- 03-privilege-escalation/
|   |
|   |-- 04-lateral-movement/
|   |
|   |-- 05-domain-compromise/
|   |
|   |-- 06-persistence/
|   |
|   `-- 07-detection-and-hardening/
|
|-- labs/
|
|-- diagrams/
|
|-- detection/
|   |
|   |-- sigma/
|   |-- powershell/
|   `-- queries/
|
|-- scripts/
|   |
|   |-- lab-setup/
|   `-- defensive-auditing/
|
`-- references/

The repository will be expanded incrementally.

Each directory will be introduced only when the material required for that section is added, so naturally some material might still be in production as I've been working on this for a little while now, most of summer 2026 :P


Learning Path

Module 00 - Active Directory Fundamentals

Before exploring exploitation techniques, the guide establishes the technologies that make Active Directory work.

Topics will include:

Active Directory architecture
Domains
Forests
Trees
Organizational Units
Users
Groups
Computers
Domain Controllers
Global Catalog
LDAP
Kerberos
NTLM
DNS (the usual suspect imho)
Group Policy
Access Control Lists
Security Identifiers
Trust relationships

Understanding these components is important because Active Directory attacks generally abuse intended functionality, excessive permissions, weak configurations, exposed credentials, or trust relationships rather than a single software vulnerability.


Module 01 - Active Directory Enumeration

Enumeration is the process of understanding the environment before attempting exploitation.

Topics will include:

Domain discovery
Domain Controller discovery
User enumeration
Group enumeration
Computer enumeration
Privileged group discovery
Service Principal Names
Group Policy enumeration
Network shares
Logged-on users
Sessions
ACLs
Organizational Units
Trust relationships
BloodHound collection
BloodHound attack-path analysis

Tools may include:

Native Windows commands
PowerShell
PowerView
SharpHound
BloodHound
LDAP utilities
Impacket

Module 02 - Credential Access

This module examines how credentials and authentication material can become exposed or abused inside Active Directory environments.

Topics will include:

Kerberos ticket fundamentals
Service accounts
Service Principal Names
Kerberoasting
AS-REP Roasting
Credential exposure
Password policy analysis
Authentication material
NTLM concepts
Kerberos ticket analysis

Each technique will include both attacker and defender perspectives.


Module 03 - Privilege Escalation

Privilege escalation in Active Directory frequently involves discovering permissions that provide unintended control over another object.

Topics will include:

Local privilege escalation
Group membership abuse
Active Directory ACLs
GenericAll
GenericWrite
WriteDACL
WriteOwner
ForceChangePassword
AddMember
Delegation
Resource-Based Constrained Delegation
Active Directory Certificate Services
Misconfigured service accounts
BloodHound privilege paths

Module 04 - Lateral Movement

Lateral movement covers techniques used to move between systems after obtaining valid credentials or sufficient access.

Topics will include:

SMB
WinRM
PowerShell Remoting
WMI
RDP
Remote service concepts
Credential reuse (you can read more about this in on of my other repos "azure-red-team-abuse-scenarios at: https://github.com/BackdoorAli/azure-red-team-abuse-scenarios)
Administrative shares
Remote authentication

The emphasis will be on understanding which credentials, privileges, protocols, and network conditions make each method possible.


Module 05 - Domain Compromise

This module examines attack paths that can lead to highly privileged Active Directory access.

Topics will include:

Domain Admin pathways
DCSync
Directory replication permissions
Kerberos ticket abuse
Domain Controller compromise concepts
Credential material on Domain Controllers
Privileged ACL relationships
Trust abuse
Forest-level attack concepts

The guide will distinguish between obtaining a privileged account and obtaining permissions that are effectively equivalent to privileged access.


Module 06 - Persistence

Persistence techniques can allow access to survive credential changes, system reboots, administrative cleanup, or other defensive actions.

Topics will include:

Persistence through directory permissions
Privileged group persistence
Kerberos persistence concepts
Account-based persistence
ACL persistence
Authentication persistence
Domain-level persistence indicators

The emphasis will include both how persistence mechanisms work and how defenders can identify them.


Module 07 - Detection and Hardening

Every offensive technique covered by this repository will ultimately connect to defensive guidance.

Topics will include:

Windows Security Event Logs
PowerShell logging
Kerberos logging
NTLM monitoring
LDAP visibility
Domain Controller auditing
BloodHound remediation
Privileged account management
Service account security
Credential hygiene
Tiered administration
Attack-path reduction
Active Directory Certificate Services hardening
Trust hardening
Detection engineering
Sigma rules
Security monitoring queries

Standard Technique Format

Where practical, individual attack techniques will follow a common structure.

1. Overview

2. Why the Technique Works

3. Active Directory Components Involved

4. Required Conditions

5. Lab Scenario

6. Enumeration

7. Exploitation Walkthrough

8. Command Breakdown

9. Internal Technical Explanation

10. Expected Results

11. Evidence Generated

12. Detection

13. Mitigation

14. MITRE ATT&CK Mapping

15. References

Example Attack Flow

A simplified Active Directory attack path might resemble:

Initial Domain User
        |
        v
Domain Enumeration
        |
        v
Identify Service Account
        |
        v
Kerberos Enumeration
        |
        v
Credential Access
        |
        v
Discover ACL Relationship
        |
        v
Privilege Escalation
        |
        v
Lateral Movement
        |
        v
Privileged Domain Access

Real environments vary significantly.

The purpose of the repository is to understand the relationships that make these paths possible.


Attacker and Defender Perspective

Techniques will frequently be presented from both perspectives.

Attacker View

Enumeration
    |
    v
Identify Weakness
    |
    v
Validate Access
    |
    v
Exploit Misconfiguration
    |
    v
Expand Access

Defender View

Authentication Logs
        |
        v
Directory Activity
        |
        v
Process Activity
        |
        v
Network Activity
        |
        v
Correlation
        |
        v
Detection

Understanding both perspectives is essential for learning how Active Directory attacks actually appear in enterprise environments.


Lab-Only Testing

Practical exercises in this repository are intended for controlled environments such as:

Personal Active Directory labs
Hack The Box
TryHackMe
Authorized penetration tests
Authorized red-team engagements
Capture-the-Flag environments
Purpose-built vulnerable networks
Systems where explicit permission has been granted

Do not perform the techniques described in this repository against systems, networks, domains, accounts, or organisations without authorisation.


Tools Covered

The project may reference widely used Active Directory security tools including:

BloodHound
SharpHound
PowerView
PowerSploit
Impacket
Rubeus
Mimikatz
Certipy
Certify
NetExec
CrackMapExec
LDAP utilities
Native PowerShell
Windows administrative utilities

Tools are included to demonstrate the underlying Active Directory concepts.

Understanding the protocol, permission, or configuration being abused is more important than memorizing a tool command.


MITRE ATT&CK

Where appropriate, techniques will be mapped to relevant MITRE ATT&CK tactics and techniques.

Example categories include:

Discovery
Credential Access
Privilege Escalation
Lateral Movement
Persistence
Defense Evasion
Collection

MITRE mappings will be included primarily to connect practical lab activity with terminology commonly used by security teams.


Detection Engineering

The repository will eventually contain a dedicated detection section:

detection/
|
|-- sigma/
|
|-- powershell/
|
`-- queries/

Detection material may include:

Windows Event ID analysis
Sigma rules
PowerShell detection examples
Authentication analysis
Kerberos monitoring
LDAP monitoring concepts
Domain Controller telemetry
Privilege modification detection
Suspicious group membership changes
Attack-path remediation

Diagrams

Architecture and attack-path diagrams will be used where visual explanations improve understanding.

Planned diagram categories include:

Active Directory architecture
Kerberos authentication
NTLM authentication
LDAP communication
BloodHound attack paths
ACL relationships
Delegation
Domain trusts
Forest trusts
Credential attack flows
Lateral movement paths
Domain compromise paths

Educational Philosophy

The repository follows a simple principle:

Do not only learn the command.

Learn why the command works.

A security tester should understand:

What am I querying?

Why does the server answer?

Which protocol is being used?

Which credentials are being presented?

Which permissions allow this action?

What changes inside Active Directory?

What logs are created?

What would a defender see?

How can the weakness be removed?

This approach turns individual commands into reusable knowledge.


Project Status

[Some section still in development]

Phase 1 - Repository foundation
Phase 2 - Active Directory fundamentals
Phase 3 - Enumeration
Phase 4 - Credential access
Phase 5 - Privilege escalation
Phase 6 - Lateral movement
Phase 7 - Domain compromise
Phase 8 - Persistence
Phase 9 - Detection and hardening
Phase 10 - Labs, diagrams, and detection content

References

This repository is an independent educational project.

Technical information will be cross-referenced against authoritative documentation and established security research where appropriate.

Reference material will include:

Microsoft documentation
MITRE ATT&CK
SpecterOps research
BloodHound documentation
Impacket documentation
Tool documentation
Security research publications
Active Directory security research

Additional project references will be maintained under:

references/

Ethics

All offensive-security material in this repository is intended for education, authorised security testing, and defensive research.

A dedicated ETHICS.md document will define the project's rules of use.


A little extra note, if you're actually planning on reading and paying attention throughout the entirety of this repository, you'll see a few extra "easter egg" notes I'll be dropping throughout the various files, just to remember you're reading something that took months to get together, hundreds of hours of research, preparation and structure, and also, a little inside preview at what an OCD brain looks like trying to get something close to perfection, in my own perspective! I hope you enjoy the guide and hopefully find this helpful on your own learning journey, trust me, it's a long and never ending one! :P

About

Educational Active Directory exploitation and defence guide covering enumeration, credential access, privilege escalation, lateral movement, persistence, detection and hardening.

Topics

Resources

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors