Windows Active Directory has sat at the center of corporate infrastructure for decades, which makes it the environment every internal pentester has to understand deeply. This course takes you through a full real-world AD attack chain, starting from an adversary with only network-level access and no domain credentials, and ending at Enterprise Administrator.
The focus is on abusing legitimate domain features and misconfigurations rather than relying on software vulnerabilities. You work through external OSINT, initial access, situational awareness, privilege escalation, lateral movement, and domain dominance, mirroring how modern engagements actually unfold.
What the course covers
You start by deploying your own AD lab so every technique is practiced in a safe environment. From there you move through initial access methods like Kerberos password spraying, NTLM relay, NBNS/LLMNR abuse and AS-REP roasting. You enumerate the domain both manually and with tooling such as NetExec, BloodHound, ldapsearch and Impacket.
The privilege escalation and lateral movement sections dig into Kerberoasting, Kerberos delegation abuse (unconstrained, constrained and RBCD), and ACL attacks like ForceChangePassword, GenericWrite, WriteDACL and DCSync. Persistence is covered through Golden, Silver, Diamond and Sapphire tickets.
You also work through Active Directory Certificate Services abuse (ESC1, ESC2, ESC4) and cross-domain and cross-forest attacks, including trust key abuse and SID filtering bypass. The course closes with penetration test report writing and a full sample report walkthrough, so your findings are something a client can act on.
This is a hands-on, attack-driven course built on practical engagement experience, not theory. By the end, you will be able to plan and execute a complete internal Active Directory penetration test, escalate from zero access to full domain and forest compromise, and document your findings in a report that helps the client prioritize and fix what you found.
