What problem does it solve?
Active Directory environments contain misconfigurations, weak credentials, and attack paths that let attackers escalate from a standard domain user to Domain Admin, and manual testing of every vector is slow and error-prone. This Skill provides a structured, phase-by-phase methodology to enumerate, exploit, and prove domain compromise with verifiable artifacts.
Core Features & Use Cases
- AD Enumeration & Attack Path Mapping: Enumerate domain objects, trusts, password policies, delegation settings, and GPP passwords with NetExec and ldapsearch, then map shortest paths to Domain Admin with BloodHound.
- Kerberos & ADCS Exploitation: Perform Kerberoasting, AS-REP roasting, delegation abuse (unconstrained, constrained, RBCD), and exploit certificate template misconfigurations (ESC1-ESC8) with Certipy.
- Privilege Escalation & Proof of Compromise: Execute DCSync, Golden/Silver Ticket attacks, and demonstrate persistence, validating each step with concrete artifacts like cracked hashes or a krbtgt dump.
- Use Case: A penetration tester with standard domain credentials runs the BloodHound collection and Certipy scan, discovers an ESC1-vulnerable template, mints a certificate for the administrator account, and proves domain compromise via a controlled DCSync.
Quick Start
Perform an Active Directory penetration test against the corp.local domain starting with the provided domain user credentials and enumerate attack paths with BloodHound.