- Description
- Full AD compromise path · from domain user to Domain Admin.
- Best For
- Internal engagements with Windows domain environments, OSCP/OSEP AD labs, HTB Pro Labs.
- Strength
- Complete attack chain from unauthenticated enumeration through DCSync, Golden Ticket, and persistence · with exact commands for every step.
in this domain 16 sections
- 01 Decision Tree: Low-Priv Domain Creds → What First?
- 02 Initial Enumeration
- 03 BloodHound
- 04 Kerberoasting
- 05 AS-REP Roasting
- 06 Password Spraying (Safe)
- 07 Pass-the-Hash (PTH)
- 08 Pass-the-Ticket (PTT)
- 09 Lateral Movement
- 10 DCSync
- 11 NTDS.dit Extraction (Offline)
- 12 Golden Ticket
- 13 ACL / Misconfiguration Exploitation
- 14 AD CS Abuse (ESC1)
- 15 NTLM Relay & Coercion
- 16 Delegation Abuse (Constrained / RBCD)