Security Knowledge Base

Active Directory Pentest Notes

A structured field guide to Active Directory attacks, lateral movement, permission abuse, persistence and forest-level trust exploitation.

10Sections
199Topics
1388Command blocks
📘

Things To Understand Prior

Core Active Directory concepts: components, authentication, Kerberos, PAC, SAM/LSA, NTDS.dit, DPAPI and eKeys.

AD Components🧱 Active Directory ComponentsActive Directory StructureExample of Domain and Forest.AD AuthenticationKerberos Authentication+12 more
18 topics →
⚔️

Attacks + Lateral Movement

Offensive techniques & lateral movement: BloodHound, relay attacks, roasting, PtH/PtT/PtC, delegation abuse and more.

BloodHoundLocal Admin HuntingLLMNR/NBT-NS Poisoning🔍 Objective🧭 Overview📦 Purpose of LLMNR/NBT-NS+62 more
68 topics →
🔑

Permissions Abuse

DACL/SACL abuse: GenericAll, GenericWrite, WriteDACL, WriteOwner, OU & GPO abuse.

DACL & SACL🔐 GenericWriteGeneric AllWrite DACLAll Extended RightsWrite Owner+3 more
9 topics →
🔒

Persistence

Domain persistence: Golden/Silver/Diamond tickets, AdminSDHolder, DSRM, Skeleton Key.

Golden Ticket Attack🔧 How the Golden Ticket Attack Works (Step-by-Step)What if we impersonate a non-existing user?🔑 Step 1 — Obtain the krbtgt HashMethod 1 — Using DCSync (Most Common)Diamond Ticket Attack+7 more
13 topics →
🌲

Forest privilege escalation / trust abuse technique

Forest-level escalation & trust abuse: SID history, Extra SID, cross-forest golden tickets.

Golden Ticket Attack + SID Prime AttackExtra Sid Attack🧪 Alternative: Golden Ticket via Rubeus📤 Step 8: DCSync from Parent Domain (Privilege Confirm)
4 topics →
🖥️

TI interne

Test d'intrusion interne : AD CS (ESC1→ESC8), BloodHound, roasting, PtH, GPO abuse, Windows PrivEsc, exfiltration.

1ère étape – Découverte réseauBloodHoundEnum ACLÉnumération LDAPDomain computers (abus MachineAccountQuota)IPC$ / null session → enumération SID+19 more
25 topics →
🌐

Pentest web

Pentest web : énumération, Apache RCE, LFI/PHP wrappers, Tomcat, CMS, SQLi, XSS, XXE, SSTI, Docker registry.

ÉnumérationApache 2.4.49 – Path Traversal / RCE (CVE-2021-41773)PHP wrappers / LFITomcat – WAR reverse shellBypass auth – Brute forceCMS+11 more
17 topics →
☁️

Cloud & K8s

Cloud & conteneurs : Docker, Kubernetes, Azure DevOps, Terraform state abuse, checks IaC, OWASP CI/CD.

Docker (bases)Kubernetes (Kube)Azure CLI (DevOps)Scénarios d’attaque Azure DevOps / CI-CDTerraform state file → prise de contrôle pipeline (study case)Détection de vulnérabilités IaC (Checkov / Terra)+3 more
9 topics →
🧰

Priv escalation & Tools

Élévation Linux, reverse shells, pivoting, jails, désérialisation et boîte à outils du pentester.

Linux PrivEscReverse shellsUpgrade shell (TTY)Pivoting (rpivot)Port knockingPython jail escape+7 more
13 topics →

Web Vulnerability Checklist

Checklist d'audit web : 2FA, ATO, IDOR, CSRF, file upload, Jira, mass assignment, SQLi, RXSS et plus.

2FA Bypass403 BypassAccount Takeover (ATO)Admin panelAEM (Adobe Experience Manager)API Authentication / Authorization+17 more
23 topics →