Nullpath
20 pages

AD & Kerberos Fundamentals

The objects, protocols and stores an attacker reasons over: directory structure, Kerberos flow, NTLM, and where the secrets live.

Page Kind Updated
Active Directory Structure
objects, OUs, domains, trees, forests, sites
concept 06 Sept
Domain Controller & FSMO Roles
concept 06 Sept
LDAP / LDAPS
directory protocol
concept 06 Sept
SMB
Server Message Block
concept 06 Sept
SAM Database
Local Account Store
concept 06 Sept
NTDS.dit
AD Database
concept 06 Sept
LSASS
Local Security Authority Subsystem Service
concept 06 Sept
Service Accounts vs Machine Accounts
concept 06 Sept
Service Principal Name
SPN
concept 06 Sept
Kerberos Authentication
AD
concept 13 Jun
TGT and TGS
the two Kerberos tickets
concept 06 Sept
Kerberos Pre-Authentication
concept 06 Sept
Kerberos PAC
Privilege Attribute Certificate
concept 06 Sept
Kerberos Encryption Types
RC4 / AES128 / AES256
concept 06 Sept
KRBTGT Account
concept 06 Sept
NTLM Authentication
concept 06 Sept
ccache
Kerberos credential cache
concept 06 Sept
Group Managed Service Accounts
gMSA
concept 06 Sept
LAPS
Local Administrator Password Solution
concept 07 Sept
AD Tiering Model
Tier 0 / 1 / 2
concept 06 Sept
20 pages in this section