Welcome to the hackherway Active Directory Attack Playbook _ Cyber Attack Catalog
Welcome to your central knowledge hub for understanding, simulating, and defending against enterprise-level security threats. This resource aims to combine offensive tactics and defensive strategy. It provides actionable and meaningful insights into how attackers compromise identity infrastructures and how you can stop them.
🛡️ Purpose of This Resource
Active Directory (AD) is the primary target for modern cyber attacks. It acts as the “keys to the kingdom” for enterprise networks.
This repository serves two core purposes:
- The Playbook: Maps out lulti-stage attack pathways used by real-world adversaries to gain domain dominance.
- The Catalog: Breaks down individual technical exploits, tools, and vulnerabilities into distinct, understandable components.
🔍 What You Will Find Inside
1. Active Directory Attack Playbook
- Complete walk-throughs of the attack lifecycle from initial access to full domain takeover.
- Step-by-step documentation of credential dumping, Kerberoasting, lateral movement, DCSync, and privilege escalation.
- Clear visual diagrams and mind maps of complex AD trust exploitation and delegation abuses.
2. Cyber Attack Catalog
- A comprehensive technical registry of specific attack vectors.
- Direct mappings of industry-standard frameworks like MITRE ATT&CK.
- Reproducible proof-of-concept commands alongside exact indicators of compromise (IOCs).
3. Practical Remediation Manuals
- Concrete hardening guides tailored for security professionals.
- Group Policy Object (GPO) configurations to block specific attack vectors.
- Custom SIEM logging rules and detection strategies to catch attackers early.
🚀 How to Navigate
- New to AD Security? Start with the Catalog to learn basic concepts like Kerberoasting, AS-REP Roasting, and LLMNR/NBT-NS Poisoning.
- Red, Blue, and Purple Teams: Dive into the Playbook to understand how these individual attacks chain together during a full-scale network breach.
- Looking for Hardening Guides? Every attack entry includes a dedicated Mitigation Section to help you patch vulnerabilities instantly.
- Stay Safe.
- Stay Vigilant.
- Stay Informed.
Happy hacking!
The Active Directory Attack Playbook and Cyber Attack Catalog are provided strictly for educational and ethical purposes. The information, methodologies, and tools detailed herein are designed to help and educate cybersecurity practitioners, security professionals, systems administrators, and red/blue/purple teams understand how malicious actors exploit Active Directory and broader network infrastructure to better defend them.
By accessing, reading, or utilizing any part of this playbook and catalog, you expressly agree to the following terms:
- Authorization is Mandatory: You must not attempt any of the attacks, techniques, or procedures outlined in this material on systems, networks, or domains for which you do not personally own and without explicit, written, and legal authorization from the rightful network/system owner(s).
- Strictly for Defensive Posture: The content provided is intended solely to assist in vulnerability identification, risk assessment, and the implementation of defensive controls (e.g., Tiered Administration, GPO hardening, and Continuous Monitoring).
- No Liability: The creator(s) and publisher(s) of this page accept no liability for any damage, unauthorized access, data loss or corruption, or legal consequences resulting from your misuse of this information. You have been warned.
- Risk of System Instability: Executing cyber attack simulations in live environments, especially those involving domain controllers and authentication systems, carries a high risk of service disruption, accidental lockouts, and system crashes.
For comprehensive, official guidance on defending and mitigating vulnerabilities within Active Directory, consider reviewing the official documentation and resources provided by the CISA Detecting and Mitigating Active Directory Compromises advisory.
Kerberoasting
ATT&CK: T1558.003 (Kerberoasting), T1021 (Remote Services), T1003.006 (DCSync)
Scope: Authorized Lab/Assessment Only
Objective
Obtain a service account credential via Kerberos TGT requests/analysis, and use it for lateral movement, and (if misconfiguration permits), perform directory replication using DCSync.
Environment (assumed)
- Domain:
hackherway.local - Domain Controller:
DC01– 10.8.10.225 - Service Host:
SVC01– 10.8.10.15 - Operator Box:
KALI– 10.8.10.50
Procedure (High-Level)
1. Enumerate SPN-bearing accounts; request TGS as a standard domain user.
2. Analyze TGS offline to recover weak service account credentials via brute-force.
3. Validate access; laterally move (e.g., WinRM/SMB) to SVC01.
4. If group/ACL misconfiguration allows, attempt directory replication (DCSync) from The recommended way to install is via your package manager of choice. For quick prototyping, you can also load directly from a CDN.DC01
Legal/Ethical: Commands below are examples that were performed in an authorized lab only.
Attack Command Examples (authorized lab)
Objective
Environment
hackherway.localDC01 — 10.8.10.225SVC01 — 10.8.10.15KALI — 10.8.10.50Procedure (High-Level)
SVC01.DC01.
Legal/Ethical: Commands below are documentation examples for authorized labs only.
Attack Command Examples (Authorized Lab)
Telemetry to Collect
SIEM Analytics (Splunk Examples)
Mitigations
Using NPM
Using CDN
Core Concepts
Understanding the fundamental concepts is essential before diving into implementation details. This section covers the architecture and design patterns used throughout the library.
Architecture
The system follows a modular architecture where each component is self-contained and can be used independently. The main entry point exports a factory function that creates instances with their own state.
State management is handled internally using a reactive proxy system. When data changes, dependent components automatically re-render without manual intervention.
Lifecycle
Every component goes through a well-defined lifecycle: initialization, mounting, updating, and destruction. Hooks are provided at each stage for custom logic.
Reactivity
The reactivity system uses Proxies to intercept property access and mutations. When a reactive property is read inside a computed function, that function is registered as a dependency.
Components
Components are the building blocks of any application built with this system. They encapsulate markup, styles, and behavior into reusable units.
Defining Components
A component is defined as a plain object with specific properties. The render function returns the virtual DOM representation.
Props & Events
Props are passed from parent to child and are read-only within the child component. For two-way communication, events are emitted upward through the component tree.
Validation can be added to ensure props meet expected types and constraints. Failed validation throws a descriptive error in development mode.
Slots
Slots allow content composition. A default slot receives any content placed between the component's opening and closing tags. Named slots enable multiple insertion points.
Routing
The router maps URLs to components. It supports dynamic segments, query parameters, and nested route definitions.
Basic Setup
Create a router instance and define your routes as an array of route objects. Each route specifies a path pattern and the component to render.
Programmatic Navigation
Beyond link clicks, you can navigate imperatively using the router instance methods. This is useful for redirects after form submission or conditional logic.
Navigation Guards
Guards intercept navigation and can prevent or redirect it. Use them for authentication checks, confirmation dialogs, or data preloading.
State Management
For complex applications, a centralized store helps manage shared state. The store follows a unidirectional data flow pattern.
Creating a Store
A store is created by defining an initial state object and a set of mutations that modify that state. Actions can contain asynchronous logic before committing mutations.
Getters
Getters compute derived state. They receive the state as an argument and return a computed value. Getters are cached and only re-evaluate when their dependencies change.
Actions
Actions are similar to mutations but can contain asynchronous operations. An action commits mutations rather than directly mutating state.
Advanced Topics
This section covers patterns and techniques for building production-grade applications.
Performance Optimization
Virtual scrolling, lazy loading, and code splitting are built-in features. The compiler also performs static analysis to eliminate dead code and optimize runtime performance.
Testing
The testing utilities provide helper functions for mounting components, triggering events, and asserting on rendered output. Tests run in a headless browser environment.
Deployment
Build for production with tree-shaking and minification. Static sites can be deployed to any CDN or static host. Server-side rendering requires a Node.js environment.