Skip to content
HackIndex logo

HackIndex

Active Directory:

Privilege Escalation

ACL abuse, Kerberos attacks, credential dumps, and operator group abuse

7 guides Updated Apr 30, 2026
7 guides

ACL Abuse Privilege Escalation

Exploiting misconfigured Active Directory ACLs to escalate privileges via WriteDACL, GenericAll, ForceChangePassword, and other abusable permissions.

Password Attacks and Credential Abuse

Techniques for exploiting weak, reused, or cached credentials in Active Directory to escalate privileges via spraying, stuffing, Kerberoasting, and hash abuse.

AD Password Cracking Strategies

Techniques for cracking AD password hashes using dictionary, brute-force, and rule-based attacks to escalate privileges within Active Directory environments.

Privileged Group Abuse

Exploiting high-privileged AD groups (Domain Admins, Backup Operators, etc.) to escalate privileges, move laterally, and gain domain-wide control.

Backup Operators and Server Operators Abuse

Exploiting Backup Operators and Server Operators groups in AD to escalate privileges via registry manipulation, service abuse, and SAM database extraction.

DNSAdmins Privilege Escalation

Exploit the DNSAdmins group in Active Directory to load a malicious DLL via DNS service, achieving SYSTEM-level privilege escalation on domain controllers.

Kerberos Abuse Privilege Escalation

Exploiting Kerberos authentication weaknesses in AD environments via techniques like Kerberoasting, AS-REP roasting, and ticket attacks to escalate privileges.