Active Directory Attacks
- Course Duration15 HRS
- Course LanguageEnglish
What you'll learn
- Understand Active Directory architecture, Kerberos, and NTLM authentication
- Build a realistic Windows AD attack lab from scratch
- Enumerate domains and map attack paths with BloodHound and PowerView
- Poison LLMNR/NBT-NS and relay credentials with Responder
- Perform password spraying, Kerberoasting, and AS-REP Roasting
- Dump and crack credentials with Mimikatz and LSASS extraction
- Move laterally using Pass-the-Hash, Pass-the-Ticket, and PsExec
- Escalate privileges by abusing ACLs, delegation, and Group Policy
- Forge Golden and Silver Tickets and achieve domain persistence
- Exploit AD Certificate Services (AD CS) to reach Domain Admin
- Detect, harden, and defend Active Directory against these attacks
Active Directory is the identity backbone of nearly every enterprise on earth — and that makes it the single most valuable target in a corporate network. This course takes a practical, hands-on approach to attacking Active Directory environments the way real adversaries and red teams do, walking you through the full attack chain from initial reconnaissance to complete domain dominance.
Using a fully-featured lab built on Windows Server with realistic misconfigurations, you will learn to enumerate the domain, capture and crack credentials, move laterally between hosts, escalate privileges, and abuse Kerberos, delegation, and AD Certificate Services to seize Domain Admin. Every attack is paired with its corresponding detection and defensive strategy, so you understand both how the attack works and how to stop it.
By the end of this course, you will be able to conduct a complete Active Directory penetration test, map attack paths with BloodHound, execute the techniques used in real-world breaches, and deliver a professional report with actionable remediation — leaving you fluent in both offense and defense.
Disclaimer: This course is intended strictly for educational and authorised security testing purposes. All attacks are performed within isolated lab environments. Unauthorised use of any technique taught in this course is illegal and strictly prohibited.
Course content
01Welcome to the Course2 lectures
- Important Before You Start
- Course Roadmap & Objectives
02Active Directory Fundamentals8 lectures
- What Is Active Directory?
- Domains, Trees & Forests
- Organizational Units & Objects
- Domain Controllers & Global Catalog
- Authentication: NTLM vs Kerberos
- LDAP & the Directory Structure
- Group Policy (GPO) Explained
- Domain Trusts Overview
03Building Your AD Attack Lab8 lectures
- Introduction to Virtualization
- Installing Windows Server as a Domain Controller
- Promoting the Domain Controller
- Joining Windows Clients to the Domain
- Creating Users, Groups & OUs
- Setting Up Kali Linux as the Attacker
- Introducing Vulnerable Misconfigurations
- Very Important
04Reconnaissance & Enumeration7 lectures
- Network Discovery & Host Scanning
- SMB & Null Session Enumeration
- Enumerating Users with enum4linux
- LDAP Enumeration
- Domain Enumeration with PowerView
- Mapping Attack Paths with BloodHound
- Analyzing BloodHound Data
05Gaining Initial Access7 lectures
- Introduction to Initial Access
- LLMNR / NBT-NS Poisoning with Responder
- Capturing & Cracking NetNTLM Hashes
- SMB Relay Attacks
- Password Spraying
- Abusing Default & Weak Credentials
- Very Important
06Credential Access & Harvesting7 lectures
- AS-REP Roasting
- Kerberoasting Explained
- Cracking Kerberos Tickets
- Dumping Credentials with Mimikatz
- Extracting Secrets from LSASS
- Harvesting Credentials from SAM & SYSTEM
- Very Important
07Lateral Movement7 lectures
- Introduction to Lateral Movement
- Pass-the-Hash
- Pass-the-Ticket
- Overpass-the-Hash (Pass-the-Key)
- Remote Execution with PsExec
- Lateral Movement via WMI & WinRM
- Using CrackMapExec
08Privilege Escalation6 lectures
- Local Privilege Escalation on Windows
- Abusing ACLs & Object Permissions
- Unconstrained Delegation
- Constrained Delegation
- Resource-Based Constrained Delegation (RBCD)
- Abusing Group Policy for Escalation
09Kerberos Attacks5 lectures
- How Kerberos Authentication Works
- Silver Ticket Attack
- Golden Ticket Attack
- Kerberos Delegation Abuse
- Very Important
10AD Certificate Services (AD CS) Attacks4 lectures
- Introduction to AD CS
- Enumerating Certificate Templates with Certipy
- Exploiting Vulnerable Templates (ESC1–ESC4)
- Escalating to Domain Admin via Certificates
11Domain Dominance & Persistence6 lectures
- DCSync Attack
- Dumping the Entire Domain (NTDS.dit)
- Golden Ticket Persistence
- AdminSDHolder & ACL Backdoors
- DSRM & Skeleton Key Persistence
- Very Important
12Trust & Forest Attacks4 lectures
- Understanding Domain & Forest Trusts
- Abusing SID History
- Cross-Domain Attacks
- Escalating Across Forest Trusts
13Defense Evasion4 lectures
- Evading Antivirus & EDR
- Obfuscating PowerShell Payloads
- Bypassing AMSI
- Operational Security for Red Teams
14Detection & Defense (Blue Team)5 lectures
- Detecting Common AD Attacks
- Hardening Active Directory
- Implementing LAPS
- Tiered Administration Model
- Monitoring & Event Logging
15Reporting & Remediation3 lectures
- Writing a Professional AD Pentest Report
- Risk Rating & Prioritization
- Remediation Recommendations
Requirements
- A computer with a virtualization-capable processor and at least 16GB RAM (32GB recommended)
- At least 100GB of free disk space for the Windows lab environment
- Basic familiarity with Windows and networking concepts
- A stable internet connection to download tools and operating systems
Who this course is for
- Penetration testers and red teamers who want to specialise in Active Directory
- SOC analysts and blue teamers who want to understand and detect AD attacks
- System administrators responsible for securing Windows domains
- Cybersecurity students and enthusiasts aiming to break into enterprise security