Skip to content
HackIndex logo

HackIndex

Active Directory:

Lateral Movement

PTH, PTT, DCOM, and remote exec methods for AD lateral movement

5 guides Updated Apr 30, 2026
5 guides
Pass-the-Certificate

Pass-the-Certificate

Abuse stolen X.509 certificates to authenticate via PKINIT or SChannel, obtaining TGTs or session tokens without requiring plaintext credentials.

Jun 11, 2026 4 min read

Remote Execution in Active Directory

Techniques for executing commands on remote AD hosts via WMI, PsExec, WinRM, and scheduled tasks to facilitate lateral movement across the domain.

Apr 30, 2026 4 min read

DCOM Lateral Movement

Explores abusing Windows DCOM interfaces for lateral movement in AD environments, executing remote code via MMC20, ShellWindows, and ShellBrowserWindow objects.

Apr 30, 2026 3 min read
Pass-the-Hash and Pass-the-Ticket

Pass-the-Hash and Pass-the-Ticket

Explores credential-based lateral movement techniques in AD, covering PtH NTLM relay attacks and PtT Kerberos ticket hijacking to traverse network boundaries.

Apr 30, 2026 5 min read
Pass-the-Ticket and Overpass-the-Hash

Pass-the-Ticket and Overpass-the-Hash

Covers Kerberos-based lateral movement via stolen TGTs (Pass-the-Ticket) and NTLM-to-TGT abuse (Overpass-the-Hash) in Active Directory environments.

Jul 1, 2026 4 min read