Skip to content
HackIndex logo

HackIndex

Active Directory
Platform

Active Directory

Active Directory is Microsoft's directory service for managing users, computers, and policies in Windows networks. It is the central authentication and authorization backbone of most enterprise environments.

52 guides 8 phases
2 min read Updated: Jul 13, 2026

Active Directory is Microsoft's directory service for managing users, computers, and policies in Windows networks. It is the central authentication and authorization backbone of most enterprise environments.

An AD environment runs across multiple protocols simultaneously. Understanding which service handles what helps you approach an engagement systematically — each protocol is an entry point, an enumeration surface, or an exploitation channel depending on its configuration.

These services run on every domain controller and form the attack surface of an Active Directory environment. Each has its own enumeration and exploitation techniques covered in the service guides below.

The two authentication protocols used across every AD environment. Kerberos is the primary protocol — ticket-based, used for all domain authentication. NTLM is the fallback — hash-based, used when Kerberos is unavailable or when authenticating by IP rather than hostname.

Kerberos
Port 88 · Kerberoasting · AS-REP Roasting · delegation abuse · ticket forging
View service
MSRPC
Port 135 · RPC endpoint mapper · SAMR · DRSR · DCSync via RPC
View service

LDAP is the query interface for all AD objects — users, groups, computers, GPOs, and ACLs. DNS is AD-integrated and exposes the internal network layout including domain controller hostnames, site subnets, and service records. NTP synchronisation is required for Kerberos and is often misconfigured.

LDAP
Port 389, 636 · anonymous bind · user/group enum · Kerberoasting · LAPS · relay
View service
DNS
Port 53 · AD-integrated zones · zone transfer · DNS enum · internal hostnames
View service
NTP
Port 123 · Kerberos clock skew · time sync requirement · NTP amplification
View service

SMB is the file sharing and remote execution protocol — used for lateral movement, credential capture, and share enumeration. NetBIOS is the legacy name resolution layer sitting under SMB. RDP and WinRM are the primary remote desktop and remote management interfaces on domain-joined hosts.

SMB
Port 139, 445 · share enum · Pass-the-Hash · relay · credential capture · lateral movement
View service
NetBIOS
Port 137, 138, 139 · name resolution · LLMNR poisoning · NBT-NS
View service
RDP
Port 3389 · credential reuse · session hijacking · BlueKeep · NLA bypass
View service
WinRM
Port 5985, 5986 · evil-winrm · PowerShell remoting · lateral movement
View service

Attack phases

Use the AD platform guides for domain-specific techniques that span multiple protocols — ACL abuse, BloodHound collection, Kerberos delegation attacks, DCSync, and persistence via ticket forging.

Reconnaissance

Discover AD domains, DCs, and users without credentials

2

AD Domain and DC Discovery

Techniques for enumerating AD domains and locating Domain Controllers using DNS, LDAP, and native Windows tools during initial reconnaissance.

Jun 9, 2026 4 min read

Unauthenticated User Enumeration

Identifies valid AD usernames without credentials using Kerberos pre-auth errors, LDAP null binds, and SMB probing to map attack surface.

Jun 9, 2026 3 min read

Enumeration

AD object, ACL, and attack path enumeration using BloodHound and more

5
ACL Enumeration

ACL Enumeration

Techniques for enumerating Access Control Lists in Active Directory to identify misconfigured permissions and potential privilege escalation paths.

Apr 5, 2026 4 min read
Object Enumeration

Object Enumeration

Enumerates AD objects including users, groups, OUs, and GPOs to map domain structure and identify privilege escalation paths.

Apr 5, 2026 8 min read

GPO Enumeration

Techniques for enumerating Group Policy Objects in Active Directory to identify misconfigurations, privileged settings, and potential attack paths.

Jun 11, 2026 5 min read
BloodHound and SharpHound Collection

BloodHound and SharpHound Collection

Covers deploying SharpHound to collect AD relationship data and ingesting results into BloodHound to visualise attack paths and privilege escalation routes.

Apr 5, 2026 6 min read
BloodHound Edge Reference

BloodHound Edge Reference

Maps AD attack paths via BloodHound edges, detailing exploitation techniques for ACL abuses, delegation flaws, and privilege escalation in domain environments.

Jun 9, 2026 11 min read

Vulnerability Discovery

Find ADCS flaws, password policies, and NTLM relay targets in AD

4

Delegation Misconfiguration Discovery

Identifies Kerberos delegation misconfigurations in Active Directory, including unconstrained, constrained, and resource-based delegation vulnerabilities enabling privilege escalation.

Jun 11, 2026 3 min read

Password Policy and Spray Surface

Enumerate AD password policies to identify weak settings and assess exposure to password spraying attacks across domain accounts.

Apr 30, 2026 3 min read

ADCS Misconfiguration Discovery

Techniques for identifying misconfigured Active Directory Certificate Services, including vulnerable certificate templates, enrollment permissions, and ESC attack paths.

Apr 30, 2026 7 min read

NTLM Relay Conditions

Covers conditions enabling NTLM relay attacks in AD environments, including signing requirements, EPA configurations, and protocol-level mitigations to assess.

Apr 30, 2026 3 min read

Exploitation

AD exploitation guides covering Kerberos attacks, NTLM relay, ADCS, and DCS

21
DCSync and Domain Takeover

DCSync and Domain Takeover

Exploits DCSync attack via replication privileges to extract password hashes from AD, enabling credential theft and full domain compromise.

Apr 5, 2026 4 min read

Coercion Attacks in Active Directory

Exploiting Windows authentication coercion techniques to capture or relay NTLM credentials via protocols like MS-RPRN, MS-EFSRPC, and PetitPotam.

Apr 30, 2026 4 min read

Credential Capture with Responder

Capture NTLM hashes by poisoning LLMNR/NBT-NS/mDNS traffic using Responder, enabling offline cracking or relay attacks against AD environments.

Jun 9, 2026 3 min read

GPO Abuse

Exploiting misconfigured Group Policy Objects in AD to push malicious settings, execute code, or escalate privileges across domain-joined systems.

Jun 9, 2026 3 min read

Group Membership Exploitation

Exploits misconfigured AD group memberships to escalate privileges, move laterally, or gain unauthorized access to resources within a domain environment.

Apr 5, 2026 4 min read

Post-Exploitation

AD post-exploitation: enum trusts, dump creds, abuse domain trusts

4
Credential Harvesting

Credential Harvesting

Techniques for extracting credentials from AD environments post-compromise, covering LSASS dumping, DCSync attacks, and Kerberoasting for lateral movement.

Apr 5, 2026 6 min read

Cross-Forest Trust Abuse

Exploiting Active Directory cross-forest trust relationships to escalate privileges, move laterally, and access resources across trusted forest boundaries.

Jun 11, 2026 6 min read

Domain Trust Abuse

Techniques for abusing AD domain trust relationships to escalate privileges, move laterally across forests, and compromise linked domains via ticket attacks.

Apr 30, 2026 4 min read

Situational Awareness

Enumerating AD objects, trusts, ACLs, and privilege paths post-compromise to map attack surface and identify lateral movement or escalation opportunities.

Apr 5, 2026 4 min read

Privilege Escalation

ACL abuse, Kerberos attacks, credential dumps, and operator group abuse

7
ACL Abuse Privilege Escalation

ACL Abuse Privilege Escalation

Exploiting misconfigured Active Directory ACLs to escalate privileges via WriteDACL, GenericAll, ForceChangePassword, and other abusable permissions.

Apr 5, 2026 5 min read
Password Attacks and Credential Abuse

Password Attacks and Credential Abuse

Techniques for exploiting weak, reused, or cached credentials in Active Directory to escalate privileges via spraying, stuffing, Kerberoasting, and hash abuse.

Apr 5, 2026 4 min read
AD Password Cracking Strategies

AD Password Cracking Strategies

Techniques for cracking AD password hashes using dictionary, brute-force, and rule-based attacks to escalate privileges within Active Directory environments.

Jun 11, 2026 5 min read

Privileged Group Abuse

Exploiting high-privileged AD groups (Domain Admins, Backup Operators, etc.) to escalate privileges, move laterally, and gain domain-wide control.

Jun 11, 2026 4 min read
Backup Operators and Server Operators Abuse

Backup Operators and Server Operators Abuse

Exploiting Backup Operators and Server Operators groups in AD to escalate privileges via registry manipulation, service abuse, and SAM database extraction.

Apr 30, 2026 3 min read

DNSAdmins Privilege Escalation

Exploit the DNSAdmins group in Active Directory to load a malicious DLL via DNS service, achieving SYSTEM-level privilege escalation on domain controllers.

Jun 9, 2026 3 min read

Lateral Movement

PTH, PTT, DCOM, and remote exec methods for AD lateral movement

5
Pass-the-Certificate

Pass-the-Certificate

Abuse stolen X.509 certificates to authenticate via PKINIT or SChannel, obtaining TGTs or session tokens without requiring plaintext credentials.

Jun 11, 2026 4 min read

Remote Execution in Active Directory

Techniques for executing commands on remote AD hosts via WMI, PsExec, WinRM, and scheduled tasks to facilitate lateral movement across the domain.

Apr 30, 2026 4 min read

DCOM Lateral Movement

Explores abusing Windows DCOM interfaces for lateral movement in AD environments, executing remote code via MMC20, ShellWindows, and ShellBrowserWindow objects.

Apr 30, 2026 3 min read
Pass-the-Hash and Pass-the-Ticket

Pass-the-Hash and Pass-the-Ticket

Explores credential-based lateral movement techniques in AD, covering PtH NTLM relay attacks and PtT Kerberos ticket hijacking to traverse network boundaries.

Apr 30, 2026 5 min read
Pass-the-Ticket and Overpass-the-Hash

Pass-the-Ticket and Overpass-the-Hash

Covers Kerberos-based lateral movement via stolen TGTs (Pass-the-Ticket) and NTLM-to-TGT abuse (Overpass-the-Hash) in Active Directory environments.

Jul 1, 2026 4 min read

Persistence

AD persistence via tickets, ACLs, shadow creds, and backdoor accounts

4

Account and ACL Persistence

Techniques for maintaining AD access via account manipulation, ACL abuse, and permission backdoors to ensure long-term persistence in compromised environments.

Apr 5, 2026 4 min read
ADCS Certificate Persistence

ADCS Certificate Persistence

Abuse AD Certificate Services to establish long-term persistence via certificate-based authentication, ESC techniques, and rogue template exploitation.

Jun 11, 2026 5 min read

DSRM and Skeleton Key

Covers DSRM password abuse and Skeleton Key injection for persistent stealthy access to Active Directory domain controllers, bypassing standard authentication.

Jun 11, 2026 4 min read
Golden and Silver Ticket Persistence

Golden and Silver Ticket Persistence

Forging Kerberos golden (krbtgt) and silver (service account) tickets for persistent AD access, bypassing standard authentication controls.

Apr 5, 2026 4 min read