Back

Active Directory Pentesting Engineer

This intensive training course provides participants with hands-on experience in hacking techniques, specifically focusing on Active Directory exploitation.

Tarek

Lead Trainer

Course PriceFree
Description

Course Curriculum

Active Directory introduction

4 lessons

Active Directory components

Trees and forests in Active Directory

Interacting with AD (admin, client and hacker tools and commands)

Basic Active Directory enumeration

Entra ID Introduction

3 lessons

Why Entra ID?

Introduction to Entra ID

Difference between Entra ID and on-prem AD

User Accounts Deep Dive

4 lessons

Understanding security principles

Deep dive into security contexts

Understanding SID/RID and their abuses

Hunting for interesting users

Groups and OUs

3 lessons

What are groups and OUs and why do we need both

Understanding types, scopes and attributes

Enumerating and hunting for interesting groups and OUs

Access Control in Details

4 lessons

Understanding ACEs, ACLs, DACLs and SACLs

Practical examples of bad and exploitable permissions

Enumerating and honing on bad permissions

Abusing bad permissions for privilege escalation

Group Policy Objects

3 lessons

Understanding GPOs and their typical uses

Enumerating and identifying exploitable GPOs

Exploiting GPOs for persistence and escalation

Lateral Movement

2 lessons

How lateral movement happens in AD environments

Abusing different protocols for lateral movement

Bloodhound: Discovering Attacks Paths

3 lessons

Bloodhound for offense and defense

Bloodhound setup and basic queries

Custom queries with Bloodhound

On-prem Password Attacks

4 lessons

Password profiling

Understanding password policies

Enumerating password policies

Password spraying

Entra ID Password Attacks

3 lessons

Username enumeration in Entra ID

Safe password spraying

Conditional Access Policies and possible bypasses

Hashes and Authentication Protocols

6 lessons

Different types of hashes

Understanding MS-NLMP

Capturing NTLMv2 hashes

Understanding LSASS

Dumping LSASS

Pass-the-hash

Kerberos Attacks

6 lessons

Kerberos deep dive

Finding and exploiting AS-REP Roastable accounts

When and how to Kerberoast

Silver Ticket Attack

Golden Ticket Attack

Delegation Attacks