Skip to content
HackIndex logo

HackIndex

Active Directory:

Exploitation

AD exploitation guides covering Kerberos attacks, NTLM relay, ADCS, and DCS

21 guides Updated May 6, 2026
21 guides
DCSync and Domain Takeover

DCSync and Domain Takeover

Exploits DCSync attack via replication privileges to extract password hashes from AD, enabling credential theft and full domain compromise.

Apr 5, 2026 4 min read

Coercion Attacks in Active Directory

Exploiting Windows authentication coercion techniques to capture or relay NTLM credentials via protocols like MS-RPRN, MS-EFSRPC, and PetitPotam.

Apr 30, 2026 4 min read

Credential Capture with Responder

Capture NTLM hashes by poisoning LLMNR/NBT-NS/mDNS traffic using Responder, enabling offline cracking or relay attacks against AD environments.

Jun 9, 2026 3 min read

GPO Abuse

Exploiting misconfigured Group Policy Objects in AD to push malicious settings, execute code, or escalate privileges across domain-joined systems.

Jun 9, 2026 3 min read

Group Membership Exploitation

Exploits misconfigured AD group memberships to escalate privileges, move laterally, or gain unauthorized access to resources within a domain environment.

Apr 5, 2026 4 min read

NTLM Relay in Active Directory

Exploit NTLM authentication weaknesses to relay captured credentials against AD services, bypassing direct password cracking to gain unauthorised access.

Apr 30, 2026 5 min read
Password Spraying

Password Spraying

Covers low-and-slow authentication attacks against AD accounts using common passwords to evade lockout policies and gain initial domain access.

Apr 30, 2026 3 min read

ADCS Exploitation: ESC2, ESC3, ESC5, ESC7

Exploiting misconfigured ADCS certificate templates and CA permissions (ESC2, ESC3, ESC5, ESC7) to escalate privileges or impersonate users in Active Directory.

Jun 11, 2026 6 min read

ADCS Exploitation: ESC9 and ESC10

Exploits ADCS misconfigurations ESC9 (no-security-extension) & ESC10 (weak mapping) to abuse certificate templates for privilege escalation in AD environments.

Jun 11, 2026 5 min read

ADCS Exploitation: ESC1, ESC4, ESC6, ESC8

Exploiting Active Directory Certificate Services misconfigurations (ESC1-ESC8) to escalate privileges or achieve domain compromise via certificate abuse.

Apr 30, 2026 5 min read
AS-REP Roasting

AS-REP Roasting

Exploit accounts with Kerberos pre-authentication disabled to capture AS-REP hashes offline for password cracking without domain credentials.

Apr 30, 2026 4 min read

bloodyAD Active Directory Attack Reference

Exploiting Active Directory misconfigurations using bloodyAD; covering privilege escalation, object manipulation, ACL abuse, and lateral movement techniques.

Jun 14, 2026 15 min read
Constrained Delegation Abuse – S4U Impersonation

Constrained Delegation Abuse – S4U Impersonation

Exploit Kerberos S4U2Proxy/S4U2Self extensions to impersonate privileged users via misconfigured constrained delegation, enabling lateral movement within Active Directory environments.

Jul 1, 2026 3 min read
Golden Ticket and Silver Ticket Attacks

Golden Ticket and Silver Ticket Attacks

Forge Kerberos TGTs (Golden) or service tickets (Silver) using stolen KRBTGT or service account hashes to achieve persistent, stealthy AD access.

Jul 1, 2026 4 min read
Kerberoasting

Kerberoasting

Exploits Kerberos TGS ticket encryption to extract and offline brute-force service account password hashes in Active Directory environments.

Apr 30, 2026 4 min read

NoPac: sAMAccountName Spoofing

Exploits CVE-2021-42278/42287 to spoof sAMAccountName, impersonate a DC, and obtain a TGT for privilege escalation in Active Directory.

Jun 11, 2026 4 min read

Shadow Credentials

Abuse msDS-KeyCredentialLink attribute to forge certificate-based authentication, enabling stealthy privilege escalation and persistence within Active Directory environments.

Jun 11, 2026 5 min read
Unconstrained Delegation Abuse – TGT Capture

Unconstrained Delegation Abuse – TGT Capture

Exploit unconstrained Kerberos delegation to capture TGTs from authenticating hosts, enabling lateral movement and privilege escalation within Active Directory environments.

Jul 1, 2026 3 min read