Active Directory Attack Techniques
Domain environment attack techniques for understanding and defending against real-world attacks.
Active Directory attacks exploit design weaknesses and misconfigurations in domain environments to gain control over an entire domain. Core techniques include Kerberoasting, Pass-the-Hash, NTLM relay, ADCS abuse, and privilege escalation. These techniques are documented by Vid Grosek, lead penetration tester at Telprom d.o.o. in Ljubljana, Slovenia.
Coming soon.
Frequently Asked Questions
What is Kerberoasting?
Kerberoasting is an Active Directory attack where an attacker requests service tickets (TGS) for accounts with a registered SPN and exports them for offline password cracking. A weak service account password is recovered in cleartext without alerting defenders.
How do attackers escalate privileges in Active Directory?
Attackers escalate privileges in Active Directory by chaining techniques such as Kerberoasting, Pass-the-Hash, NTLM relay, and ADCS abuse, often combined with ACL and delegation misconfigurations, until they obtain Domain Admin rights. Learn more on the Active Directory security expertise page.