Nearly every corporate network runs AD, and nearly every serious breach touches it. Understand the game board before learning the moves.
Imagine onboarding 5,000 employees. You don’t create accounts on 5,000 PCs — you centralize identity in Active Directory. A domain controller (DC) holds the database of users, groups, computers and policies. Join a machine to the domain and one login works everywhere.
Why attackers love it: compromise one workstation creds → query AD → find who’s admin where → climb. Why defenders must know it: that same map tells them what a compromised account can actually reach.
Kerberos = ticket system so you never send passwords around:
The attacks write themselves once you see the trust assumptions: steal a TGT session (pass-the-ticket); crack service tickets offline to recover service-account passwords (Kerberoasting — any domain user can request tickets); request tickets for accounts with no pre-auth required (AS-REP roasting); and if you ever capture the krbtgt hash itself, you can forge wristbands for life — the infamous Golden Ticket. Defenders counter with gMSA accounts, long random passwords, tiered admin models and twice-a-year krbtgt resets after breaches.
This lesson is pure Security+ gold and daily SOC reality at once.
Breaches rarely hit the crown jewels first. The rhythm is: foothold → enumerate → move sideways → escalate → persist.
Defensive design principles that break this whole chain: tiered administration (never browse email from a DC), local admin password uniqueness (LAPS), just-in-time elevation, and assuming breach — monitor for movement, not just entry. Explore the site’s AD technique cheatsheets next.