Active Directory Enterprise Attack Paths
BloodHound graph analysis, Kerberoasting, AS-REP roasting, AD CS abuse, and Golden Ticket persistence.
Course Overview & Objectives
An elite red teaming masterclass dissecting Windows enterprise infrastructure. Discover how real-world attackers map privilege escalation graphs with BloodHound, abuse Kerberos delegation, exploit Active Directory Certificate Services (AD CS), and establish domain persistence.
What You Will Master
- Enumerate hidden enterprise trust paths using BloodHound and SharpHound
- Execute Kerberoasting and AS-REP roasting attacks to crack service account passwords
- Abuse vulnerable AD CS certificate templates (ESC1 through ESC8) for instant domain admin escalation
- Forge Golden and Silver Kerberos tickets for persistent stealth access
Prerequisites
- Strong understanding of Windows domains & Kerberos
- Basic PowerShell scripting
Platforms & Tools Covered
Detailed Curriculum Modules
1 modules structured from foundational theory through complex adversarial execution.
Active Directory Architecture & Kerberos In-Depth
TGTs, TGSs, SPNs, and the underlying mechanics of Windows authentication.
Hands-on Virtual Sandbox Labs
Zero local hardware dependencies. Provisioned in cloud containers via browser terminal.
AD CS ESC1 Exploitation Sandbox
Find misconfigured certificate templates and request a certificate on behalf of Domain Admin.
Golden Ticket Forgery & DCShadow Persistence
Dump KRBTGT hash and forge long-term valid Kerberos tickets.
Faculty & Lead Instructor
Direct weekly instruction, live office hours, and code-review feedback.
Kunal Singh
Thread Security EducationOffensive Security Lead
Certified Red Teamer with hundreds of successful domain compromise engagements across global corporate networks.
Frequently Asked Questions
Everything you need to know about scheduling, cohort admissions, and lab access.
Do I get access to a full Windows Active Directory lab?
Yes! You receive access to a multi-domain forest virtual lab with real Windows Server domain controllers.
Ready to Master Active Directory Enterprise Attack Paths?
Join the upcoming cohort. Seats are limited to maintain a high faculty-to-student ratio and rigorous sandbox feedback.