OPSECTLAS you are here: Active Directory
Active Directory

Active Directory

domain 16 sections

Description
Full AD compromise path · from domain user to Domain Admin.
Best For
Internal engagements with Windows domain environments, OSCP/OSEP AD labs, HTB Pro Labs.
Strength
Complete attack chain from unauthenticated enumeration through DCSync, Golden Ticket, and persistence · with exact commands for every step.
in this domain 16 sections
  1. 01 Decision Tree: Low-Priv Domain Creds → What First?
  2. 02 Initial Enumeration
  3. 03 BloodHound
  4. 04 Kerberoasting
  5. 05 AS-REP Roasting
  6. 06 Password Spraying (Safe)
  7. 07 Pass-the-Hash (PTH)
  8. 08 Pass-the-Ticket (PTT)
  9. 09 Lateral Movement
  10. 10 DCSync
  11. 11 NTDS.dit Extraction (Offline)
  12. 12 Golden Ticket
  13. 13 ACL / Misconfiguration Exploitation
  14. 14 AD CS Abuse (ESC1)
  15. 15 NTLM Relay & Coercion
  16. 16 Delegation Abuse (Constrained / RBCD)