Active Directory Attack Playbooks

HackHerWay — AD Attack Playbooks
Offensive Security Operations

Active Directory
Attack Playbooks

Practical, step-by-step guides for red teamers, pentesters, and aspiring adversary emulators who are tired of reading documentation that assumes you already know what you’re doing.

01

AD Enumeration Playbook

A five-phase methodology for mapping Active Directory attack surfaces—because you can’t exploit what you can’t see, and half of you are running blind.

⚡ 5 Phases ⏱ 45 min read
→
02

Identity Threat Hunting Playbook

A defender’s guide to catching the techniques described in Playbook 01. Turn the tables and ruin someone’s day before they ruin yours.

🛡 4 Phases ⏱ 30 min read
→
03

Kerberos Abuse Playbook

Golden tickets, silver tickets, and all the other precious metals. A comprehensive guide to abusing the protocol that powers enterprise authentication.

⚡ 6 Phases ⏱ Coming Soon
→
04

Privilege Escalation Playbook

From standard user to Domain Admin. The paths, the pitfalls, and the post-exploitation activities that separate script kiddies from operators.

⚡ 7 Phases ⏱ Coming Soon
→
05

Persistence & Evasion Playbook

Staying in the network when they know you’re there. GPOs, scheduled tasks, service accounts, and the art of not getting caught.

⚡ 5 Phases ⏱ Coming Soon
→
06

AD CS Abuse Playbook

Active Directory Certificate Services: the attack surface nobody audits until it’s too late. ESC1 through ESC15 and beyond.

⚡ 8 Phases ⏱ Coming Soon
→

Active Directory Enumeration Playbook

A five-phase methodology for comprehensively mapping Active Directory attack surfaces. Because “I couldn’t find anything” is not an acceptable finding when you’re holding the right tools.

Difficulty Intermediate
Time Required 2-4 Hours
Prerequisites Domain Credentials
Last Updated Jul 2026
1

Domain Context & Trust Mapping

Before you touch a single tool, understand the terrain. Domain trusts are the highways between kingdoms—know where they lead before you start driving.

  • Enumerate domain and forest functional levels
  • Map parent-child, external, and forest trusts
  • Identify trust directions and transitivity
  • Document SID filtering status on external trusts
# Get domain trust relationships Get-ADTrust -Filter ‘*’ nltest /domain_trusts /all_trusts # BloodHound: ingest and analyze trust paths SharpHound.exe -c All –zipfilename trustmap.zip
2

User & Group Enumeration

Every user is a potential entry point. Every group is a privilege escalation waiting to happen. Map them all—yes, even the service accounts named after the intern who left three years ago.

  • Enumerate all domain users and their properties
  • Identify privileged groups and nested memberships
  • Hunt for accounts with SPNs (Kerberoast targets)
  • Find users with unconstrained delegation
# Enumerate privileged domain groups Get-ADGroupMember “Domain Admins” -Recursive Get-ADGroupMember “Enterprise Admins” -Recursive # Find Kerberoastable accounts Get-ADUser -Filter {ServicePrincipalName -ne “$null”} -Properties ServicePrincipalName
3

Computer & Service Discovery

Computers run services. Services have configurations. Configurations have vulnerabilities. This is not rocket science, but you’d be amazed how many people skip this phase.

  • Enumerate all domain-joined systems and OS versions
  • Identify systems with LAPS deployed (and those without)
  • Map service accounts to their host systems
  • Find pre-Windows 2000 computers (yes, they still exist)
# Enumerate computers via LDAP ldapsearch -x -H ldap://dc.corp.local -D “user@corp.local” -W -b “dc=corp,dc=local” “(objectClass=computer)” “name” “operatingSystem” # PowerView: find computers where current user has local admin Find-LocalAdminAccess -Delay 10
4

ACL & Permission Analysis

Access Control Lists are where the real magic happens. That low-priv user who can modify a Group Policy? That’s your golden ticket. Stop ignoring DACLs.

  • Enumerate object permissions with BloodHound
  • Find GenericAll, WriteDACL, and ForceChangePassword rights
  • Identify users who can read LAPS passwords
  • Map DCSync rights holders
# PowerView: find interesting ACLs Get-ObjectAcl -SamAccountName “Domain Admins” -ResolveGUIDs | Where-Object {$_.ActiveDirectoryRights -match “GenericAll|WriteDacl|GenericWrite”} # Check for DCSync rights Get-ObjectAcl -DistinguishedName “dc=corp,dc=local” -ResolveGUIDs | Where-Object {$_.ObjectAceType -match “Replication-Get”}
5

Data Synthesis & Attack Path Mapping

Raw data is worthless without context. Feed everything into BloodHound, identify the shortest paths to Domain Admin, and build your attack narrative. If you can’t explain it to yourself, you can’t explain it in a report.

  • Ingest all data into BloodHound for graph analysis
  • Run pre-built queries for high-value attack paths
  • Validate findings through targeted manual testing
  • Document attack chains with screenshots and evidence
// BloodHound: shortest path to Domain Admin MATCH (u:User {owned: true}), (g:Group {name: ‘DOMAIN ADMINS@CORP.LOCAL’}) MATCH p = shortestPath((u)-[*1..]->(g)) RETURN p

Connected Playbooks

🛡

Identity Threat Hunting

The blue team counterpart. Learn how defenders detect the exact techniques you just read about.

⚡

Kerberos Abuse

Golden tickets, silver tickets, and the art of forging enterprise authentication.

🔒

Privilege Escalation

From standard user to Domain Admin. The paths that get you there.

Identity Threat Hunting Playbook

A four-phase methodology for proactively hunting identity-based threats in Active Directory. Because waiting for alerts is how you end up reading about your own breach in the news.

Difficulty Advanced
Time Required Ongoing
Prerequisites SIEM / EDR Access
Last Updated Jul 2026
1

Hypothesis Development

Threat hunting without a hypothesis is just scrolling through logs hoping something jumps out. Spoiler: it won’t. Start with intelligence, not desperation.

  • Review MITRE ATT&CK techniques relevant to identity
  • Analyze recent threat actor TTPs from CTID / Mandiant
  • Develop testable hypotheses based on your environment
  • Prioritize by likelihood and business impact
# Example Hypotheses: “An attacker with valid credentials is using RDP to laterally move between workstations during off-hours to avoid detection.” “A compromised service account is performing DCSync operations from a non-domain-controller host.” “Kerberoasting activity is occurring against high-value SPNs outside of normal business hours.”
2

Data Collection & Query Construction

Your SIEM is only as good as the queries you feed it. Build detection logic that catches adversaries, not just noisy alerts that make you want to quit your job.

  • Identify relevant data sources: Windows Event Logs, AD replication logs, VPN logs
  • Construct Sigma rules for portable detection logic
  • Query for anomalous authentication patterns
  • Correlate identity events with endpoint telemetry
# Sigma: Detect DCSync from non-DC title: DCSync from Non-Domain Controller logsource: product: windows service: security detection: selection: EventID: 4662 ObjectType: ‘19195a5b-6da0-11d0-afd3-00c04fd930c9’ filter: SubjectUserName|endswith: ‘$’ condition: selection and not filter
3

Investigation & Triage

Alerts are suggestions. Investigations are facts. Every anomaly deserves scrutiny—yes, even the one that turned out to be the backup admin doing maintenance at 2 AM. Verify everything.

  • Correlate suspicious events across multiple data sources
  • Validate user context: Is this normal for this account?
  • Check for concurrent sessions from impossible geographies
  • Analyze command-line arguments and parent-child processes
# Check for anomalous logon events Get-WinEvent -FilterHashtable @{LogName=’Security’; ID=4624,4648,4672} | Where-Object {$_.TimeCreated -gt (Get-Date).AddDays(-7)} | Group-Object {$_.Properties[5].Value} | Where-Object {$_.Count -gt 100} # Hunt for Kerberoasting (Event ID 4769) Get-WinEvent -FilterHashtable @{LogName=’Security’; ID=4769} | Where-Object {$_.Properties[2].Value -match ‘0x17’}
4

Response & Hardening

Finding the threat is half the battle. The other half is making sure it doesn’t happen again. Document, remediate, and automate—or prepare to hunt the same adversary next quarter.

  • Contain compromised accounts and revoke active sessions
  • Reset passwords for affected service accounts
  • Implement detection-as-code for recurring hunt patterns
  • Update security controls based on findings
# Force password reset and revoke sessions Set-ADAccountPassword -Identity “svc_compromised” -Reset -NewPassword (ConvertTo-SecureString -AsPlainText “NewComplexP@ssw0rd!” -Force) Revoke-AzureADUserAllRefreshToken -ObjectId “user@corp.local” # Disable compromised account Disable-ADAccount -Identity “compromised.user”

Connected Playbooks

⚡

AD Enumeration

The red team counterpart. Understand what the attackers see before they see it.

🔒

Privilege Escalation

Know the paths attackers take so you can block them before they do.

🕰

Persistence & Evasion

Learn how attackers stay hidden so you can shine a light on them.