For Ethical Use Only

All content is intended for educational purposes, authorized penetration testing, and security research. Techniques are presented with the aim of understanding and defending against attacks.

Security Research Expertise Resources About Vid Grosek

Frequently Asked Questions

What is Kerberoasting?

Kerberoasting is an Active Directory attack in which an attacker requests service tickets for accounts that have a Service Principal Name and then cracks their passwords offline to recover service account credentials.

What is ADCS abuse?

ADCS abuse exploits misconfigurations in Active Directory Certificate Services, where an attacker uses vulnerable certificate templates to issue certificates for other users, impersonate them, and escalate privileges up to domain administrator.

What is AMSI and EDR evasion?

AMSI and EDR evasion are techniques red teams use to bypass security controls such as the Antimalware Scan Interface and endpoint detection and response tools, using command obfuscation and living-off-the-land techniques to test how effectively an attack is actually detected.

Are these techniques legal to use?

These techniques are legal to use only during authorized penetration testing with written permission from the system owner; they are meant for education, security research, and defense, never for unauthorized attacks.