Active Directory
Attack Playbooks
Practical, step-by-step guides for red teamers, pentesters, and aspiring adversary emulators who are tired of reading documentation that assumes you already know what you’re doing.
AD Enumeration Playbook
A five-phase methodology for mapping Active Directory attack surfaces—because you can’t exploit what you can’t see, and half of you are running blind.
Identity Threat Hunting Playbook
A defender’s guide to catching the techniques described in Playbook 01. Turn the tables and ruin someone’s day before they ruin yours.
Kerberos Abuse Playbook
Golden tickets, silver tickets, and all the other precious metals. A comprehensive guide to abusing the protocol that powers enterprise authentication.
Privilege Escalation Playbook
From standard user to Domain Admin. The paths, the pitfalls, and the post-exploitation activities that separate script kiddies from operators.
Persistence & Evasion Playbook
Staying in the network when they know you’re there. GPOs, scheduled tasks, service accounts, and the art of not getting caught.
AD CS Abuse Playbook
Active Directory Certificate Services: the attack surface nobody audits until it’s too late. ESC1 through ESC15 and beyond.
Active Directory Enumeration Playbook
A five-phase methodology for comprehensively mapping Active Directory attack surfaces. Because “I couldn’t find anything” is not an acceptable finding when you’re holding the right tools.
Domain Context & Trust Mapping
Before you touch a single tool, understand the terrain. Domain trusts are the highways between kingdoms—know where they lead before you start driving.
- Enumerate domain and forest functional levels
- Map parent-child, external, and forest trusts
- Identify trust directions and transitivity
- Document SID filtering status on external trusts
User & Group Enumeration
Every user is a potential entry point. Every group is a privilege escalation waiting to happen. Map them all—yes, even the service accounts named after the intern who left three years ago.
- Enumerate all domain users and their properties
- Identify privileged groups and nested memberships
- Hunt for accounts with SPNs (Kerberoast targets)
- Find users with unconstrained delegation
Computer & Service Discovery
Computers run services. Services have configurations. Configurations have vulnerabilities. This is not rocket science, but you’d be amazed how many people skip this phase.
- Enumerate all domain-joined systems and OS versions
- Identify systems with LAPS deployed (and those without)
- Map service accounts to their host systems
- Find pre-Windows 2000 computers (yes, they still exist)
ACL & Permission Analysis
Access Control Lists are where the real magic happens. That low-priv user who can modify a Group Policy? That’s your golden ticket. Stop ignoring DACLs.
- Enumerate object permissions with BloodHound
- Find GenericAll, WriteDACL, and ForceChangePassword rights
- Identify users who can read LAPS passwords
- Map DCSync rights holders
Data Synthesis & Attack Path Mapping
Raw data is worthless without context. Feed everything into BloodHound, identify the shortest paths to Domain Admin, and build your attack narrative. If you can’t explain it to yourself, you can’t explain it in a report.
- Ingest all data into BloodHound for graph analysis
- Run pre-built queries for high-value attack paths
- Validate findings through targeted manual testing
- Document attack chains with screenshots and evidence
Connected Playbooks
Identity Threat Hunting
The blue team counterpart. Learn how defenders detect the exact techniques you just read about.
Kerberos Abuse
Golden tickets, silver tickets, and the art of forging enterprise authentication.
Privilege Escalation
From standard user to Domain Admin. The paths that get you there.
Identity Threat Hunting Playbook
A four-phase methodology for proactively hunting identity-based threats in Active Directory. Because waiting for alerts is how you end up reading about your own breach in the news.
Hypothesis Development
Threat hunting without a hypothesis is just scrolling through logs hoping something jumps out. Spoiler: it won’t. Start with intelligence, not desperation.
- Review MITRE ATT&CK techniques relevant to identity
- Analyze recent threat actor TTPs from CTID / Mandiant
- Develop testable hypotheses based on your environment
- Prioritize by likelihood and business impact
Data Collection & Query Construction
Your SIEM is only as good as the queries you feed it. Build detection logic that catches adversaries, not just noisy alerts that make you want to quit your job.
- Identify relevant data sources: Windows Event Logs, AD replication logs, VPN logs
- Construct Sigma rules for portable detection logic
- Query for anomalous authentication patterns
- Correlate identity events with endpoint telemetry
Investigation & Triage
Alerts are suggestions. Investigations are facts. Every anomaly deserves scrutiny—yes, even the one that turned out to be the backup admin doing maintenance at 2 AM. Verify everything.
- Correlate suspicious events across multiple data sources
- Validate user context: Is this normal for this account?
- Check for concurrent sessions from impossible geographies
- Analyze command-line arguments and parent-child processes
Response & Hardening
Finding the threat is half the battle. The other half is making sure it doesn’t happen again. Document, remediate, and automate—or prepare to hunt the same adversary next quarter.
- Contain compromised accounts and revoke active sessions
- Reset passwords for affected service accounts
- Implement detection-as-code for recurring hunt patterns
- Update security controls based on findings
Connected Playbooks
AD Enumeration
The red team counterpart. Understand what the attackers see before they see it.
Privilege Escalation
Know the paths attackers take so you can block them before they do.
Persistence & Evasion
Learn how attackers stay hidden so you can shine a light on them.