Skip to content
Paul Marinos
Menu

Active Directory & Identity

Graphing the domain with BloodHound, spraying and relaying with NetExec and Impacket, and the Kerberos and AD CS primitives — Kerberoasting, coercion-to-relay, and Certipy — most escalations are built from.

Active Directory is where a foothold becomes domain compromise, and the tooling is mature because the underlying protocol behaviors are decades old. Almost everything below is a legitimate feature used from the wrong side of the trust boundary — which is exactly why the defensive page frames these as design rather than defects. This is the offensive half of that pair.

bloodhound-python -d domain.local -u user -p pass -c all (or SharpHound on Windows): collect directory data. Output: users, groups, sessions, ACLs and trusts, as a graph. Next: the collection step, and the noisy one — session and ACL collection is what defenders watch for, so the collection method is an OPSEC decision.

BloodHound: compute attack paths across the collected graph. Output: shortest paths to Domain Admin and other high-value targets. Next: the canonical AD escalation tool — it turns a mess of ACLs (GenericAll, WriteDacl, AddMember) into a concrete route. Read from the other side, the same graph is the defender’s only honest privilege inventory, because group membership alone never shows the shadow admins.

netexec smb <targets> -u users.txt -p 'Season2026!' --continue-on-success: spray a credential across hosts. Output: which host-and-credential pairs authenticate, plus shares and sessions. Next: NetExec (formerly CrackMapExec) is the swiss-army knife across SMB, WinRM, LDAP and more — spraying, validation, and post-credential enumeration at scale. Account lockout is a real risk: one attempt per user per policy window, and know the threshold before you start.

kerbrute userenum -d domain.local users.txt: validate usernames via Kerberos pre-auth. Output: which usernames exist, without a single logon attempt. Next: pre-auth username enumeration produces no failed-logon events, so it is the quiet way to turn a name list into a valid-user list before any spraying.

Impacket is the suite most AD attacks are built from — scriptable implementations of the protocol primitives:

  • GetUserSPNs.py domain/user:pass -request — Kerberoasting. Requests service tickets for SPN accounts and returns crackable hashes. Any authenticated user can do this, offline, with no failed-logon telemetry — which is why the defense is removing SPNs and using gMSA, not detection.
  • secretsdump.py domain/user:pass@target — dump hashes, from SAM/LSA locally or via DRSUAPI (DCSync) against a domain controller with replication rights.
  • ntlmrelayx.py -t ldaps://dc --escalate-user user — relay coerced NTLM authentication to another service. The back half of a coercion chain.
  • psexec.py / wmiexec.py — authenticated code execution once you hold a credential or hash, the latter quieter than the former.

Responder -I eth0: answer LLMNR/NBT-NS/mDNS to capture authentication. Output: captured NetNTLM hashes from hosts that broadcast for name resolution. Next: pairs with ntlmrelayx — poison to coerce authentication, relay it to a target where that identity is privileged. The whole chain is misused name resolution plus misused NTLM.

certipy find -u user@domain -p pass -dc-ip <ip>: enumerate AD CS for vulnerable templates. Output: certificate templates flagged by ESC class. Next: the ESC findings (enrollee-supplied subject with a client-auth EKU is ESC1) let a low-privileged user request a certificate that authenticates as someone else. The most consequential recent AD finding class, because a certificate survives the password reset that would otherwise be remediation — see the defensive treatment for why. certipy req then requests and abuses the template find surfaced.

This is the tooling half of Active Directory & Hybrid Identity — every technique here has its structural mitigation there, and the two are best read as one. The telemetry these tools generate (ticket requests, replication, certificate issuance) is what threat hunting looks for, and it is the same activity a responder reconstructs after the fact in an incident.

Graph View

Last updated:

Spotted an error on this page? Report it.