Build Your Skills — Intermediate — hands-on

📖 WorkbookIntermediate✓ Free

Active Directory Fundamentals

AD architecture, objects, Kerberos, NTLM, GPOs, and trusts before attacking AD.

Read →
🧪 LabIntermediate✓ Free

Active Directory LDAP Enumeration

ldapsearch, windapsearch, and manual LDAP queries to map AD structure.

Start lab →⏱ 1.5 hours
🧪 LabIntermediate✓ Free

AD Enumeration with BloodHound

SharpHound collection, BloodHound graph analysis, and finding attack paths.

Start lab →⏱ 1.5 hours
🧪 LabIntermediate✓ Free

AD Enumeration with CrackMapExec

CME for SMB enumeration, credential testing, and lateral movement.

Start lab →⏱ 1.5 hours
🧪 LabIntermediate✓ Free

AD Enumeration with PowerView

PowerView functions for enumerating users, groups, ACLs, and SPNs.

Start lab →⏱ 1.5 hours
🧪 LabAdvanced✓ Free

Kerberos Attacks

Kerberoasting, ASREPRoasting, Pass-the-Ticket, and Golden/Silver tickets.

Start lab →⏱ 3 hours
🧪 LabAdvanced✓ Free

NTLM Relay Attacks

Responder, NTLMrelayx, and relay chains for credential capture and relay.

Start lab →⏱ 3 hours
📖 WorkbookIntermediate✓ Free

Privilege Escalation — Linux & Windows

SUID, sudo, services, tokens, DLL hijacking — complete privesc reference.

Read →
📖 WorkbookAdvanced🔒 Free account

Windows Active Directory for Pentesters

Deep dive into AD administration, enumeration, and attack paths.

Read →⏱ 5 hours
🧪 LabIntermediate✓ Free

Windows Privilege Escalation

Services, tokens, registry, DLL hijacking, and AlwaysInstallElevated.

Start lab →⏱ 1.5 hours

Go Advanced — Advanced — for practitioners

📖 WorkbookAdvanced🔒 Free account

Active Directory Enumeration & Attacks

BloodHound, PowerView, Kerberoasting, ASREPRoasting, and DACL abuse.

Read →⏱ ~5 hours
🧪 LabAdvanced✓ Free

Active Directory Trust Attacks

SID history injection, foreign principal abuse, and cross-forest attacks.

Start lab →⏱ 3 hours
🧪 LabAdvanced✓ Free

AD Certificate Services (ADCS) Attacks

ESC1–ESC8 ADCS misconfigurations for certificate-based domain compromise.

Start lab →⏱ 3 hours
🧪 LabAdvanced✓ Free

Application Whitelisting Bypass

AppLocker rule bypass via trusted paths, DLL side-loading, and COM objects.

Start lab →⏱ 3 hours
🧪 LabIntermediate✓ Free

Attacking Enterprise Networks

Full attack chain from external foothold to domain admin in a lab network.

Start lab →⏱ 1.5 hours
🧪 LabAdvanced✓ Free

Command & Control with Sliver

Deploy and operate the Sliver C2 framework for red team engagements.

Start lab →⏱ 3 hours
🧪 LabAdvanced✓ Free

DACL Attacks in Active Directory

GenericAll, WriteDACL, GenericWrite, and AddMember for privesc.

Start lab →⏱ 3 hours
🧪 LabAdvanced✓ Free

MSSQL, Exchange & SCCM Attacks

Linked server abuse, MSSQL xp_cmdshell, Exchange privilege escalation.

Start lab →⏱ 3 hours
🧪 LabIntermediate✓ Free

Pivoting, Tunneling & Port Forwarding

Proxychains, SSH tunneling, Chisel, and Ligolo for network pivoting.

Start lab →⏱ 1.5 hours
📖 WorkbookAdvanced🔒 Free account

Red Team Operations

C2 frameworks, tradecraft, OPSEC, persistence, and advanced lateral movement.

Read →⏱ ~5 hours
🧪 LabAdvanced✓ Free

Supply Chain Attacks

Build process compromise, dependency confusion, and package hijacking.

Start lab →⏱ 3 hours
🧪 LabAdvanced✓ Free

Windows Evasion Techniques

AMSI bypass, PowerShell logging bypass, and process injection methods.

Start lab →⏱ 3 hours
🧪 LabIntermediate✓ Free

Windows Lateral Movement

PSExec, WMI, WinRM, DCOM, and token impersonation for lateral movement.

Start lab →⏱ 1.5 hours
🧪 LabIntermediate✓ Free

WMI Tradecraft & Analysis

WMI for persistence, lateral movement, and stealthy code execution.

Start lab →⏱ 1.5 hours