Active Directory & Identity
Graphing the domain with BloodHound, spraying and relaying with NetExec and Impacket, and the Kerberos and AD CS primitives — Kerberoasting, coercion-to-relay, and Certipy — most escalations are built from.
Active Directory is where a foothold becomes domain compromise, and the tooling is mature because the underlying protocol behaviors are decades old. Almost everything below is a legitimate feature used from the wrong side of the trust boundary — which is exactly why the defensive page frames these as design rather than defects. This is the offensive half of that pair.
Graph the domain
Section titled “Graph the domain”bloodhound-python -d domain.local -u user -p pass -c all (or SharpHound on Windows):
collect directory data.
Output: users, groups, sessions, ACLs and trusts, as a graph.
Next: the collection step, and the noisy one — session and ACL collection is what defenders
watch for, so the collection method is an OPSEC decision.
BloodHound: compute attack paths across the collected graph.
Output: shortest paths to Domain Admin and other high-value targets.
Next: the canonical AD escalation tool — it turns a mess of ACLs (GenericAll, WriteDacl,
AddMember) into a concrete route. Read from the other side, the same graph is the defender’s
only honest privilege inventory, because group membership alone never
shows the shadow admins.
Spray, validate, enumerate
Section titled “Spray, validate, enumerate”netexec smb <targets> -u users.txt -p 'Season2026!' --continue-on-success: spray a
credential across hosts.
Output: which host-and-credential pairs authenticate, plus shares and sessions.
Next: NetExec (formerly CrackMapExec) is the swiss-army knife across SMB, WinRM, LDAP and
more — spraying, validation, and post-credential enumeration at scale. Account lockout is a
real risk: one attempt per user per policy window, and know the threshold before you start.
kerbrute userenum -d domain.local users.txt: validate usernames via Kerberos
pre-auth.
Output: which usernames exist, without a single logon attempt.
Next: pre-auth username enumeration produces no failed-logon events, so it is the quiet way to
turn a name list into a valid-user list before any spraying.
Kerberos and credential primitives
Section titled “Kerberos and credential primitives”Impacket is the suite most AD attacks are built from — scriptable implementations of the protocol primitives:
GetUserSPNs.py domain/user:pass -request— Kerberoasting. Requests service tickets for SPN accounts and returns crackable hashes. Any authenticated user can do this, offline, with no failed-logon telemetry — which is why the defense is removing SPNs and using gMSA, not detection.secretsdump.py domain/user:pass@target— dump hashes, from SAM/LSA locally or via DRSUAPI (DCSync) against a domain controller with replication rights.ntlmrelayx.py -t ldaps://dc --escalate-user user— relay coerced NTLM authentication to another service. The back half of a coercion chain.psexec.py/wmiexec.py— authenticated code execution once you hold a credential or hash, the latter quieter than the former.
Responder -I eth0: answer LLMNR/NBT-NS/mDNS to capture authentication.
Output: captured NetNTLM hashes from hosts that broadcast for name resolution.
Next: pairs with ntlmrelayx — poison to coerce authentication, relay it to a target where
that identity is privileged. The whole chain is misused name resolution plus misused NTLM.
AD Certificate Services
Section titled “AD Certificate Services”certipy find -u user@domain -p pass -dc-ip <ip>: enumerate AD CS for vulnerable templates.
Output: certificate templates flagged by ESC class.
Next: the ESC findings (enrollee-supplied subject with a client-auth EKU is ESC1) let a
low-privileged user request a certificate that authenticates as someone else. The most
consequential recent AD finding class, because a certificate survives the password reset
that would otherwise be remediation — see the defensive treatment for
why. certipy req then requests and abuses the template find surfaced.
Where this connects
Section titled “Where this connects”This is the tooling half of Active Directory & Hybrid Identity — every technique here has its structural mitigation there, and the two are best read as one. The telemetry these tools generate (ticket requests, replication, certificate issuance) is what threat hunting looks for, and it is the same activity a responder reconstructs after the fact in an incident.
Graph View
Spotted an error on this page? Report it.