Active Directory Attacks Cheatsheet

Quick reference for AD enumeration, Kerberos attacks, lateral movement, and domain compromise.

March 24, 2026 · 7 min

AD Attack Methodology — From Zero to Domain Admin

Step-by-step methodology for attacking Active Directory — the chain I follow on every AD box.

March 24, 2026 · 11 min

BloodHound — Setup and Usage Guide

How I set up and use BloodHound CE for AD enumeration — collection, import, and finding attack paths.

March 24, 2026 · 6 min

HTB Active Writeup — Kerberoasting & GPP Passwords (2026)

My first AD box ever. Null session on SMB → GPP password in SYSVOL → Kerberoasting the Administrator → Domain Admin.

March 24, 2026 · 2 min

HTB Blackfield Writeup — LSASS Dump & VSS Shadow Copies (2026)

Hard AD box. AS-REP Roasting → BloodHound → ForceChangePassword → lsass.DMP → SeBackupPrivilege → VSS snapshot → NTDS.dit → Domain Admin.

March 24, 2026 · 4 min

HTB Forest Writeup — AS-REP Roasting, BloodHound & DCSync (2026)

Second AD box. AS-REP Roasting with no creds, BloodHound attack path through 5 nested groups, ACL abuse to DCSync.

March 24, 2026 · 3 min

HTB Monteverde Writeup — Azure AD Connect Exploit (2026)

Active Directory box — password spraying → Azure AD Connect credential extraction → Domain Admin.

March 24, 2026 · 2 min

Impacket — The Tools I Actually Use

Quick reference for the Impacket tools I use most — mssqlclient, GetUserSPNs, GetNPUsers, secretsdump, psexec, and more.

March 24, 2026 · 8 min