Active Directory:
Exploitation
AD exploitation guides covering Kerberos attacks, NTLM relay, ADCS, and DCS
DCSync and Domain Takeover
Exploits DCSync attack via replication privileges to extract password hashes from AD, enabling credential theft and full domain compromise.
Coercion Attacks in Active Directory
Exploiting Windows authentication coercion techniques to capture or relay NTLM credentials via protocols like MS-RPRN, MS-EFSRPC, and PetitPotam.
Coercer and PetitPotam — Active Directory Coercion Frameworks
Exploits Windows authentication coercion via MS-EFSRPC and other RPC protocols to force machine account credential relay attacks in AD environments.
Credential Capture with Responder
Capture NTLM hashes by poisoning LLMNR/NBT-NS/mDNS traffic using Responder, enabling offline cracking or relay attacks against AD environments.
GPO Abuse
Exploiting misconfigured Group Policy Objects in AD to push malicious settings, execute code, or escalate privileges across domain-joined systems.
Group Membership Exploitation
Exploits misconfigured AD group memberships to escalate privileges, move laterally, or gain unauthorized access to resources within a domain environment.
NTLM Relay in Active Directory
Exploit NTLM authentication weaknesses to relay captured credentials against AD services, bypassing direct password cracking to gain unauthorised access.
Password Spraying
Covers low-and-slow authentication attacks against AD accounts using common passwords to evade lockout policies and gain initial domain access.
ADCS Exploitation: ESC2, ESC3, ESC5, ESC7
Exploiting misconfigured ADCS certificate templates and CA permissions (ESC2, ESC3, ESC5, ESC7) to escalate privileges or impersonate users in Active Directory.
ESC8 — NTLM Relay to AD CS Web Enrollment
Exploit NTLM relay attacks targeting AD CS HTTP enrollment endpoints to obtain certificates for arbitrary principals and achieve privilege escalation.
ADCS Exploitation: ESC9 and ESC10
Exploits ADCS misconfigurations ESC9 (no-security-extension) & ESC10 (weak mapping) to abuse certificate templates for privilege escalation in AD environments.
ADCS Exploitation: ESC1, ESC4, ESC6, ESC8
Exploiting Active Directory Certificate Services misconfigurations (ESC1-ESC8) to escalate privileges or achieve domain compromise via certificate abuse.
AS-REP Roasting
Exploit accounts with Kerberos pre-authentication disabled to capture AS-REP hashes offline for password cracking without domain credentials.
bloodyAD Active Directory Attack Reference
Exploiting Active Directory misconfigurations using bloodyAD; covering privilege escalation, object manipulation, ACL abuse, and lateral movement techniques.
Constrained Delegation Abuse – S4U Impersonation
Exploit Kerberos S4U2Proxy/S4U2Self extensions to impersonate privileged users via misconfigured constrained delegation, enabling lateral movement within Active Directory environments.
Golden Ticket and Silver Ticket Attacks
Forge Kerberos TGTs (Golden) or service tickets (Silver) using stolen KRBTGT or service account hashes to achieve persistent, stealthy AD access.
Kerberoasting
Exploits Kerberos TGS ticket encryption to extract and offline brute-force service account password hashes in Active Directory environments.
NoPac: sAMAccountName Spoofing
Exploits CVE-2021-42278/42287 to spoof sAMAccountName, impersonate a DC, and obtain a TGT for privilege escalation in Active Directory.
RBCD – Resource-Based Constrained Delegation Abuse
Abuses msDS-AllowedToActOnBehalfOfOtherIdentity to gain delegated access, enabling impersonation of privileged users against target AD computer objects.
Shadow Credentials
Abuse msDS-KeyCredentialLink attribute to forge certificate-based authentication, enabling stealthy privilege escalation and persistence within Active Directory environments.
Unconstrained Delegation Abuse – TGT Capture
Exploit unconstrained Kerberos delegation to capture TGTs from authenticating hosts, enabling lateral movement and privilege escalation within Active Directory environments.