Nullpath
Offensive security · Active Directory · Kerberos

The Active Directory
attack reference.

Atomic, cross-linked notes written the way they get used — enumerate, exploit, escalate, persist. Every page carries the protocol mechanics, the exact commands, the detection footprint, and how each technique chains into the next.

137 pages
68 concepts
21 attack paths
13 sections

Topic map

by kill-chain phase
AD & Kerberos Fundamentals 20

The objects, protocols and stores an attacker reasons over: directory structure, Kerberos flow, NTLM, and where the secrets live.

kerberos ldap ntlm
Credential Access 9

Getting authentication material out of the domain: roasting, replication, and reusing hashes, keys, tickets and certs.

impacket rubeus hashcat
Kerberos Ticket Forgery 3

Once you hold a signing secret, forge tickets offline: Golden, Silver, Diamond, and SID-history injection.

mimikatz rubeus ticketer
Delegation Abuse 3

Unconstrained, constrained and resource-based delegation misconfigurations that turn into impersonation and privilege escalation.

rubeus impacket s4u
Coercion & NTLM Relay 5

Force a machine to authenticate, then relay it: PetitPotam, the printer bug, mitm6/WPAD, and Kerberos relay.

ntlmrelayx mitm6 coercer
AD CS / PKI (ESC) 1

Active Directory Certificate Services misconfigurations — the ESC1–ESC15 family — that mint authentication certificates.

certipy certify adcs
ACL & Object Control 2

Abusing DACLs on directory objects and GPOs — GenericAll, WriteDACL, WriteOwner — to walk edges toward Domain Admin.

bloodhound powerview gpoabuse
Lateral Movement & Execution 1

Turning credentials into code execution across hosts: SMB, WMI, WinRM, PSRemoting and RDP.

impacket crackmapexec evil-winrm
Persistence & Domain Dominance 3

Durable footholds once you own the domain: DCShadow, Skeleton Key, AdminSDHolder and DSRM backdoors.

mimikatz dcshadow adminsdholder
SCCM & Imaging 2

Attacking the deployment plane: SCCM/MECM network access accounts and WDS/MDT imaging shares.

sccmhunter pxethief
Forest & Trust Attacks 1

Crossing the domain and forest boundary: SID filtering, TREAT_AS_EXTERNAL and trust-key abuse.

impacket mimikatz
Detection & Hardening 2

The defender's side: tiering baselines, honeytokens and the log artifacts each technique leaves behind.

sigma 4769 honeytokens

Recently updated

Featured attack paths