🏢 Active Directory Security
Comprehensive Active Directory penetration testing guide. Learn AD enumeration, Kerberos attacks, credential harvesting, privilege escalation, and domain domination techniques.
Kerberoasting
HighRequest TGS tickets for service accounts, crack offline to find weak passwords.
Full GuideAS-REP Roasting
HighRequest AS-REP tickets for accounts with "Do not require Kerberos preauthentication".
Full GuideGolden Ticket
CriticalForge TGT using KRBTGT hash. Persistent domain admin access that lasts years.
Full GuidePass the Hash
HighAuthenticate using NTLM hash instead of password. Over-pass-the-hash techniques.
Full GuidePass the Ticket
HighUse extracted Kerberos tickets for lateral movement and privilege escalation.
Full GuideNTLM Relay
CriticalLLMNR/NBT-NS poisoning, SMB relay attacks, credential capture and relay.
Full GuideDCSync Attack
CriticalReplicate domain credentials using DRS (Directory Replication Service).
Full Guide🛠️ Essential Tools
BloodHound
AD attack path analysis. Graph database for finding privilege escalation paths to DA.
Mimikatz
Credential extraction, pass-the-hash, pass-the-ticket, golden ticket, DCSync.
Rubeus
Kerberos attack toolkit. Kerberoasting, AS-REP roasting, ticket manipulation.
Responder
LLMNR/NBT-NS/mDNS poisoner. SMB relay, HTTP auth capture, credential stealing.
CrackMapExec
Swiss army knife for AD pentesting. Network attacking, credential dumping.
SharpHound
BloodHound data collector for AD enumeration. User, group, ACL collection.