Skip to content
HackIndex logo

HackIndex

Active Directory:

Exploitation

AD exploitation guides covering Kerberos attacks, NTLM relay, ADCS, and DCS

21 guides Updated May 6, 2026
21 guides

DCSync and Domain Takeover

Exploits DCSync attack via replication privileges to extract password hashes from AD, enabling credential theft and full domain compromise.

Coercion Attacks in Active Directory

Exploiting Windows authentication coercion techniques to capture or relay NTLM credentials via protocols like MS-RPRN, MS-EFSRPC, and PetitPotam.

Coercer and PetitPotam — Active Directory Coercion Frameworks

Exploits Windows authentication coercion via MS-EFSRPC and other RPC protocols to force machine account credential relay attacks in AD environments.

Credential Capture with Responder

Capture NTLM hashes by poisoning LLMNR/NBT-NS/mDNS traffic using Responder, enabling offline cracking or relay attacks against AD environments.

GPO Abuse

Exploiting misconfigured Group Policy Objects in AD to push malicious settings, execute code, or escalate privileges across domain-joined systems.

Group Membership Exploitation

Exploits misconfigured AD group memberships to escalate privileges, move laterally, or gain unauthorized access to resources within a domain environment.

NTLM Relay in Active Directory

Exploit NTLM authentication weaknesses to relay captured credentials against AD services, bypassing direct password cracking to gain unauthorised access.

Password Spraying

Covers low-and-slow authentication attacks against AD accounts using common passwords to evade lockout policies and gain initial domain access.

ADCS Exploitation: ESC2, ESC3, ESC5, ESC7

Exploiting misconfigured ADCS certificate templates and CA permissions (ESC2, ESC3, ESC5, ESC7) to escalate privileges or impersonate users in Active Directory.

ESC8 — NTLM Relay to AD CS Web Enrollment

Exploit NTLM relay attacks targeting AD CS HTTP enrollment endpoints to obtain certificates for arbitrary principals and achieve privilege escalation.

ADCS Exploitation: ESC9 and ESC10

Exploits ADCS misconfigurations ESC9 (no-security-extension) & ESC10 (weak mapping) to abuse certificate templates for privilege escalation in AD environments.

ADCS Exploitation: ESC1, ESC4, ESC6, ESC8

Exploiting Active Directory Certificate Services misconfigurations (ESC1-ESC8) to escalate privileges or achieve domain compromise via certificate abuse.

AS-REP Roasting

Exploit accounts with Kerberos pre-authentication disabled to capture AS-REP hashes offline for password cracking without domain credentials.

bloodyAD Active Directory Attack Reference

Exploiting Active Directory misconfigurations using bloodyAD; covering privilege escalation, object manipulation, ACL abuse, and lateral movement techniques.

Constrained Delegation Abuse – S4U Impersonation

Exploit Kerberos S4U2Proxy/S4U2Self extensions to impersonate privileged users via misconfigured constrained delegation, enabling lateral movement within Active Directory environments.

Golden Ticket and Silver Ticket Attacks

Forge Kerberos TGTs (Golden) or service tickets (Silver) using stolen KRBTGT or service account hashes to achieve persistent, stealthy AD access.

Kerberoasting

Exploits Kerberos TGS ticket encryption to extract and offline brute-force service account password hashes in Active Directory environments.

NoPac: sAMAccountName Spoofing

Exploits CVE-2021-42278/42287 to spoof sAMAccountName, impersonate a DC, and obtain a TGT for privilege escalation in Active Directory.

RBCD – Resource-Based Constrained Delegation Abuse

Abuses msDS-AllowedToActOnBehalfOfOtherIdentity to gain delegated access, enabling impersonation of privileged users against target AD computer objects.

Shadow Credentials

Abuse msDS-KeyCredentialLink attribute to forge certificate-based authentication, enabling stealthy privilege escalation and persistence within Active Directory environments.

Unconstrained Delegation Abuse – TGT Capture

Exploit unconstrained Kerberos delegation to capture TGTs from authenticating hosts, enabling lateral movement and privilege escalation within Active Directory environments.