Infrastructure & AD
Own Windows networks end-to-end. Active Directory enumeration, Kerberos attacks, lateral movement, domain dominance, and full red team operations.
Start Here — Foundations — no experience assumed
Active Directory Basics
AD enumeration with net commands, PowerShell, and LDAP queries.
SMB Enumeration
Enumerate SMB shares, null sessions, and users with enum4linux and smbclient.
Windows Command Line & PowerShell
CMD and PowerShell commands, scripts, and automation for enterprise environments.
Build Your Skills — Intermediate — hands-on
Active Directory Fundamentals
AD architecture, objects, Kerberos, NTLM, GPOs, and trusts before attacking AD.
Active Directory LDAP Enumeration
ldapsearch, windapsearch, and manual LDAP queries to map AD structure.
AD Enumeration with BloodHound
SharpHound collection, BloodHound graph analysis, and finding attack paths.
AD Enumeration with CrackMapExec
CME for SMB enumeration, credential testing, and lateral movement.
AD Enumeration with PowerView
PowerView functions for enumerating users, groups, ACLs, and SPNs.
Kerberos Attacks
Kerberoasting, ASREPRoasting, Pass-the-Ticket, and Golden/Silver tickets.
NTLM Relay Attacks
Responder, NTLMrelayx, and relay chains for credential capture and relay.
Privilege Escalation — Linux & Windows
SUID, sudo, services, tokens, DLL hijacking — complete privesc reference.
Windows Active Directory for Pentesters
Deep dive into AD administration, enumeration, and attack paths.
Windows Privilege Escalation
Services, tokens, registry, DLL hijacking, and AlwaysInstallElevated.
Go Advanced — Advanced — for practitioners
Active Directory Enumeration & Attacks
BloodHound, PowerView, Kerberoasting, ASREPRoasting, and DACL abuse.
Active Directory Trust Attacks
SID history injection, foreign principal abuse, and cross-forest attacks.
AD Certificate Services (ADCS) Attacks
ESC1–ESC8 ADCS misconfigurations for certificate-based domain compromise.
Application Whitelisting Bypass
AppLocker rule bypass via trusted paths, DLL side-loading, and COM objects.
Attacking Enterprise Networks
Full attack chain from external foothold to domain admin in a lab network.
Command & Control with Sliver
Deploy and operate the Sliver C2 framework for red team engagements.
DACL Attacks in Active Directory
GenericAll, WriteDACL, GenericWrite, and AddMember for privesc.
MSSQL, Exchange & SCCM Attacks
Linked server abuse, MSSQL xp_cmdshell, Exchange privilege escalation.
Pivoting, Tunneling & Port Forwarding
Proxychains, SSH tunneling, Chisel, and Ligolo for network pivoting.
Red Team Operations
C2 frameworks, tradecraft, OPSEC, persistence, and advanced lateral movement.
Supply Chain Attacks
Build process compromise, dependency confusion, and package hijacking.
Windows Evasion Techniques
AMSI bypass, PowerShell logging bypass, and process injection methods.
Windows Lateral Movement
PSExec, WMI, WinRM, DCOM, and token impersonation for lateral movement.
WMI Tradecraft & Analysis
WMI for persistence, lateral movement, and stealthy code execution.