Active Directory Pentest Methodology

Welcome to my Active Directory penetration testing notes.

These notes are organized as a methodology‑first playbook, not a lab walkthrough. I use this notes to document how I approach Active Directory environments,

  • what I enumerate first
  • how trust and permissions usually break
  • and how small misconfigurations can be chained into full domain compromise.

Each section links to focused notes covering enumeration patterns, common abuse techniques, and attack decision points that I tend to see over and over again


Overview

  1. Pre-Authentication Attacks
  2. Authenticated Enumeration
  3. BloodHound & Graph-Based Analysis
  4. Credential Access
  5. Privilege Escalation
  6. Lateral Movement
  7. Kerberos & Ticket Abuse
  8. Domain & Forest Dominance
  9. Persistence
  10. OPSEC
  11. Evasion & Detection Awareness

1. Pre-Authentication Attacks (No Credentials)

Attacks possible with only network connectivity.


2. Authenticated Enumeration

Performed once any valid domain account is obtained.


3. BloodHound & Graph-Based Analysis

Mapping effective control paths, not just permissions.


4. Credential Access

Obtaining reusable authentication material.


5. Privilege Escalation

Abusing delegated trust and misconfiguration.


6. Lateral Movement

Using credentials, tickets, or delegated rights to move.


7. Kerberos Ticket Abuse (Deep Dive)

Forging, modifying, and abusing Kerberos tickets.


8. Domain & Forest Dominance

Actions requiring replication or forest-level trust.


9. Persistence Techniques

Maintaining long-term or stealth access.


10. OPSEC

Managing risk, noise, and exposure during Active Directory operations.


11. Evasion & Detection Awareness

Operational security considerations.


Usage Notes

  • This index is intentionally exhaustive.
  • Each linked page should focus on why an attack works, not just commands.
  • Tool usage is secondary to understanding trust relationships and control paths.
  • Treat this as a living playbook, not static documentation.

Comments
avatar
Haxinja
Read: to learn, Write: to improve, eXecute: to understand
Follow Me
Announcement
Every dawn takes a step closer to understanding.