AD Domain and DC Discovery
Techniques for enumerating AD domains and locating Domain Controllers using DNS, LDAP, and native Windows tools during initial reconnaissance.
HackIndex
Language
Active Directory is Microsoft's directory service for managing users, computers, and policies in Windows networks. It is the central authentication and authorization backbone of most enterprise environments.
An AD environment runs across multiple protocols simultaneously. Understanding which service handles what helps you approach an engagement systematically — each protocol is an entry point, an enumeration surface, or an exploitation channel depending on its configuration.
These services run on every domain controller and form the attack surface of an Active Directory environment. Each has its own enumeration and exploitation techniques covered in the service guides below.
The two authentication protocols used across every AD environment. Kerberos is the primary protocol — ticket-based, used for all domain authentication. NTLM is the fallback — hash-based, used when Kerberos is unavailable or when authenticating by IP rather than hostname.
LDAP is the query interface for all AD objects — users, groups, computers, GPOs, and ACLs. DNS is AD-integrated and exposes the internal network layout including domain controller hostnames, site subnets, and service records. NTP synchronisation is required for Kerberos and is often misconfigured.
SMB is the file sharing and remote execution protocol — used for lateral movement, credential capture, and share enumeration. NetBIOS is the legacy name resolution layer sitting under SMB. RDP and WinRM are the primary remote desktop and remote management interfaces on domain-joined hosts.
Use the AD platform guides for domain-specific techniques that span multiple protocols — ACL abuse, BloodHound collection, Kerberos delegation attacks, DCSync, and persistence via ticket forging.
Discover AD domains, DCs, and users without credentials
Techniques for enumerating AD domains and locating Domain Controllers using DNS, LDAP, and native Windows tools during initial reconnaissance.
Identifies valid AD usernames without credentials using Kerberos pre-auth errors, LDAP null binds, and SMB probing to map attack surface.
AD object, ACL, and attack path enumeration using BloodHound and more
Techniques for enumerating Access Control Lists in Active Directory to identify misconfigured permissions and potential privilege escalation paths.
Enumerates AD objects including users, groups, OUs, and GPOs to map domain structure and identify privilege escalation paths.
Techniques for enumerating Group Policy Objects in Active Directory to identify misconfigurations, privileged settings, and potential attack paths.
Covers deploying SharpHound to collect AD relationship data and ingesting results into BloodHound to visualise attack paths and privilege escalation routes.
Maps AD attack paths via BloodHound edges, detailing exploitation techniques for ACL abuses, delegation flaws, and privilege escalation in domain environments.
Find ADCS flaws, password policies, and NTLM relay targets in AD
Identifies Kerberos delegation misconfigurations in Active Directory, including unconstrained, constrained, and resource-based delegation vulnerabilities enabling privilege escalation.
Enumerate AD password policies to identify weak settings and assess exposure to password spraying attacks across domain accounts.
Techniques for identifying misconfigured Active Directory Certificate Services, including vulnerable certificate templates, enrollment permissions, and ESC attack paths.
Covers conditions enabling NTLM relay attacks in AD environments, including signing requirements, EPA configurations, and protocol-level mitigations to assess.
AD exploitation guides covering Kerberos attacks, NTLM relay, ADCS, and DCS
Exploits DCSync attack via replication privileges to extract password hashes from AD, enabling credential theft and full domain compromise.
Exploiting Windows authentication coercion techniques to capture or relay NTLM credentials via protocols like MS-RPRN, MS-EFSRPC, and PetitPotam.
Exploits Windows authentication coercion via MS-EFSRPC and other RPC protocols to force machine account credential relay attacks in AD environments.
Capture NTLM hashes by poisoning LLMNR/NBT-NS/mDNS traffic using Responder, enabling offline cracking or relay attacks against AD environments.
Exploiting misconfigured Group Policy Objects in AD to push malicious settings, execute code, or escalate privileges across domain-joined systems.
Exploits misconfigured AD group memberships to escalate privileges, move laterally, or gain unauthorized access to resources within a domain environment.
AD post-exploitation: enum trusts, dump creds, abuse domain trusts
Techniques for extracting credentials from AD environments post-compromise, covering LSASS dumping, DCSync attacks, and Kerberoasting for lateral movement.
Exploiting Active Directory cross-forest trust relationships to escalate privileges, move laterally, and access resources across trusted forest boundaries.
Techniques for abusing AD domain trust relationships to escalate privileges, move laterally across forests, and compromise linked domains via ticket attacks.
Enumerating AD objects, trusts, ACLs, and privilege paths post-compromise to map attack surface and identify lateral movement or escalation opportunities.
ACL abuse, Kerberos attacks, credential dumps, and operator group abuse
Exploiting misconfigured Active Directory ACLs to escalate privileges via WriteDACL, GenericAll, ForceChangePassword, and other abusable permissions.
Techniques for exploiting weak, reused, or cached credentials in Active Directory to escalate privileges via spraying, stuffing, Kerberoasting, and hash abuse.
Techniques for cracking AD password hashes using dictionary, brute-force, and rule-based attacks to escalate privileges within Active Directory environments.
Exploiting high-privileged AD groups (Domain Admins, Backup Operators, etc.) to escalate privileges, move laterally, and gain domain-wide control.
Exploiting Backup Operators and Server Operators groups in AD to escalate privileges via registry manipulation, service abuse, and SAM database extraction.
Exploit the DNSAdmins group in Active Directory to load a malicious DLL via DNS service, achieving SYSTEM-level privilege escalation on domain controllers.
PTH, PTT, DCOM, and remote exec methods for AD lateral movement
Abuse stolen X.509 certificates to authenticate via PKINIT or SChannel, obtaining TGTs or session tokens without requiring plaintext credentials.
Techniques for executing commands on remote AD hosts via WMI, PsExec, WinRM, and scheduled tasks to facilitate lateral movement across the domain.
Explores abusing Windows DCOM interfaces for lateral movement in AD environments, executing remote code via MMC20, ShellWindows, and ShellBrowserWindow objects.
Explores credential-based lateral movement techniques in AD, covering PtH NTLM relay attacks and PtT Kerberos ticket hijacking to traverse network boundaries.
Covers Kerberos-based lateral movement via stolen TGTs (Pass-the-Ticket) and NTLM-to-TGT abuse (Overpass-the-Hash) in Active Directory environments.
AD persistence via tickets, ACLs, shadow creds, and backdoor accounts
Techniques for maintaining AD access via account manipulation, ACL abuse, and permission backdoors to ensure long-term persistence in compromised environments.
Abuse AD Certificate Services to establish long-term persistence via certificate-based authentication, ESC techniques, and rogue template exploitation.
Covers DSRM password abuse and Skeleton Key injection for persistent stealthy access to Active Directory domain controllers, bypassing standard authentication.
Forging Kerberos golden (krbtgt) and silver (service account) tickets for persistent AD access, bypassing standard authentication controls.
We use cookies to improve your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. Privacy Policy.