~ / methodology / active-directory

Active Directory

Enumerate, escalate, and move laterally through a Windows domain.

Enumeration

  • Users, groups, GPOs, trusts, and ACLs
  • Kerberos: SPNs, delegation, pre-auth settings
  • ADCS templates and certificate abuse paths

Credential access

  • Kerberoasting and AS-REP roasting
  • Password spraying within lockout policy
  • LSASS / DPAPI where in scope

Lateral movement & escalation

  • Pass-the-hash / pass-the-ticket
  • Abuse of ACLs and delegation
  • ADCS ESC1–ESC8 where applicable

Domain dominance

  • DCSync, golden / silver tickets
  • Persistence and clean-up