Active Directory Penetration Testing
Testing Active Directory security — from enumeration (BloodHound) through Kerberos attacks, ACL abuse, domain privilege escalation, and forest trust attacks.
When to Use
- Assessing Active Directory security posture
- Identifying privilege escalation paths in AD
- Testing Kerberos delegation and trust relationships
- Simulating domain compromise scenarios
- Auditing AD ACLs and group memberships
AD Attack Techniques
AD_TECHNIQUES = {
'kerberoasting': 'Request TGS tickets for service accounts, crack offline',
'asrep_roasting': 'Request AS-REP for users without pre-authentication, crack offline',
'golden_ticket': 'Forge Kerberos TGT with KRBTGT hash — domain admin persistence',
'silver_ticket': 'Forge TGS for specific service — access without domain admin',
'dcom_exec': 'Execute commands via DCOM (MMC20.Application, ShellWindows)',
'wmi_exec': 'Execute commands remotely via WMI',
'sccm_pwn': 'Abuse System Center Configuration Manager for lateral movement',
'acl_abuse': 'Abuse WriteOwner, WriteDACL, ForceChangePassword, GenericAll ACEs',
}
BLOODHOUND_QUERIES = [
"Find all Domain Admins",
"Shortest path to Domain Admin from owned principals",
"Kerberoastable users",
"AS-REP roastable users",
"Users with admin count = 0 (shadow admin)",
"Computers with unconstrained delegation",
]
def kerberoast_demo(target_domain: str, username: str, password: str):
"""Request TGS tickets for kerberoasting (authorized testing only)."""
pass
Verification Checklist
- AD enumeration completed (BloodHound, LDAP queries)
- Kerberoasting attempted for service accounts
- AS-REP roasting attempted for users without pre-auth
- ACL analysis (Abusable ACEs: WriteOwner, WriteDACL, GenericAll, ForceChangePassword)
- Kerberos delegation abuse (unconstrained, constrained, resource-based)
- Domain trust relationships enumerated and attacked
- Golden/silver ticket attacks demonstrated
- DCSync attempt (DRS protocol replication)
- Findings documented with remediation guidance
- All testing on authorized domains only