all modules module 06 · intermediate

Windows & Active Directory

Nearly every corporate network runs AD, and nearly every serious breach touches it. Understand the game board before learning the moves.

01Domains, forests & why AD exists~5 min

Imagine onboarding 5,000 employees. You don’t create accounts on 5,000 PCs — you centralize identity in Active Directory. A domain controller (DC) holds the database of users, groups, computers and policies. Join a machine to the domain and one login works everywhere.

  • OUs organize objects; Group Policy pushes settings to them.
  • Forests/domains: big orgs chain multiple domains with trusts — each trust is a potential attack path.
  • Everything is an object with attributes; LDAP queries read them anonymously in many misconfigured setups (instant recon).

Why attackers love it: compromise one workstation creds → query AD → find who’s admin where → climb. Why defenders must know it: that same map tells them what a compromised account can actually reach.

02Kerberos without tears~6 min

Kerberos = ticket system so you never send passwords around:

  1. You ask the DC’s authentication service for access → get a TGT (ticket-granting ticket), encrypted with the krbtgt account’s hash. Think theme-park wristband.
  2. For each service (file share, SQL) you exchange the TGT for a service ticket, encrypted with the service account’s hash.
  3. The service, knowing its own secret, validates your ticket. No password ever traveled.

The attacks write themselves once you see the trust assumptions: steal a TGT session (pass-the-ticket); crack service tickets offline to recover service-account passwords (Kerberoasting — any domain user can request tickets); request tickets for accounts with no pre-auth required (AS-REP roasting); and if you ever capture the krbtgt hash itself, you can forge wristbands for life — the infamous Golden Ticket. Defenders counter with gMSA accounts, long random passwords, tiered admin models and twice-a-year krbtgt resets after breaches.

03Credential attacks: hashes, relays & spraying~5 min
  • NTLM hashes & pass-the-hash: older auth sends a hash challenge-response. Tools can use the stolen hash directly without knowing the password. Fix at scale: disable NTLM where possible.
  • LLMNR/NBT-NS poisoning (Responder): Windows broadcasts name lookups when DNS fails; an attacker answers “that’s me” and captures hash handshakes to crack. Mitigation: disable LLMNR/NBT-NS, enable SMB signing.
  • Password spraying: one common password against hundreds of usernames (opposite of brute force: few passwords, many accounts). Beats lockouts by pacing; defenders watch for it via failed-auth analytics across many accounts.
  • Credential dumps: LSASS memory holds logged-on secrets (Mimikatz territory). Protected by Credential Guard, EDR, least privilege.

This lesson is pure Security+ gold and daily SOC reality at once.

04Lateral movement & escalation: patterns, not tools~5 min

Breaches rarely hit the crown jewels first. The rhythm is: foothold → enumerate → move sideways → escalate → persist.

  • Lateral movement: reusing valid creds/tickets over WMI, WinRM, PsExec-style services, RDP. Detection correlate: one account logging into 20 hosts it never touched before.
  • Privilege escalation: finding paths — a helpdesk group with local-admin on a server, unconstrained delegation quirks, GPO abuse. BloodHound visualizes these paths as graphs; defenders run it on their own networks first.
  • Persistence: golden/silver tickets, DSRM accounts, malicious GPOs, skeleton keys.

Defensive design principles that break this whole chain: tiered administration (never browse email from a DC), local admin password uniqueness (LAPS), just-in-time elevation, and assuming breach — monitor for movement, not just entry. Explore the site’s AD technique cheatsheets next.