Advanced Active Directory Penetration Testing: Attack Windows AD

Compromise a Windows AD environment end to end, from network-only access to Enterprise Admin, by abusing domain features, not just software bugs.

$6.00

  • Instant access after purchase
  • Lifetime access — free updates when platforms change
  • Video lessons, worksheets and templates included

Secure checkout · 30-day refund

Advanced Active Directory Penetration Testing: Attack Windows AD
AdvancedLevel
123Lessons
7.5Hours total
Certificate of completionUpdated Sep 2026

What you'll be able to do

  • Deploy an Active Directory lab to practice attacks in a safe environment
  • Run external OSINT to enumerate valid domain usernames before access
  • Gain initial access via Kerberos password spray, NTLM relay and AS-REP roasting
  • Enumerate domains manually and with NetExec, BloodHound and Impacket
  • Escalate privileges through Kerberoasting, Kerberos delegation and ACL abuse
  • Move laterally with PS-Remoting, RDP and pass-the-ccache techniques
  • Establish persistence using Golden, Silver, Diamond and Sapphire tickets
  • Abuse AD CS and forest trusts, then write an actionable pentest report

Description

Windows Active Directory has sat at the center of corporate infrastructure for decades, which makes it the environment every internal pentester has to understand deeply. This course takes you through a full real-world AD attack chain, starting from an adversary with only network-level access and no domain credentials, and ending at Enterprise Administrator.

The focus is on abusing legitimate domain features and misconfigurations rather than relying on software vulnerabilities. You work through external OSINT, initial access, situational awareness, privilege escalation, lateral movement, and domain dominance, mirroring how modern engagements actually unfold.

What the course covers

You start by deploying your own AD lab so every technique is practiced in a safe environment. From there you move through initial access methods like Kerberos password spraying, NTLM relay, NBNS/LLMNR abuse and AS-REP roasting. You enumerate the domain both manually and with tooling such as NetExec, BloodHound, ldapsearch and Impacket.

The privilege escalation and lateral movement sections dig into Kerberoasting, Kerberos delegation abuse (unconstrained, constrained and RBCD), and ACL attacks like ForceChangePassword, GenericWrite, WriteDACL and DCSync. Persistence is covered through Golden, Silver, Diamond and Sapphire tickets.

You also work through Active Directory Certificate Services abuse (ESC1, ESC2, ESC4) and cross-domain and cross-forest attacks, including trust key abuse and SID filtering bypass. The course closes with penetration test report writing and a full sample report walkthrough, so your findings are something a client can act on.

This is a hands-on, attack-driven course built on practical engagement experience, not theory. By the end, you will be able to plan and execute a complete internal Active Directory penetration test, escalate from zero access to full domain and forest compromise, and document your findings in a report that helps the client prioritize and fix what you found.

Who this course is for

  • Penetration testers and red teamers who want to sharpen internal AD attacks
  • Blue teamers and DFIR specialists who need to understand offensive AD tactics
  • IT security professionals extending their skills into Active Directory
  • System administrators responsible for hardening AD environments

What you need

  • Basic understanding of Active Directory concepts (users, groups, GPO, DNS)
  • Familiarity with networking fundamentals such as TCP/IP and segmentation
  • Comfort working in the Windows and Linux command line
  • Prior penetration testing experience, plus a machine with 32 GB RAM and 300 GB free disk

Every lesson is recorded on the current version of the platform. When an ad manager or checkout is redesigned we re-record that lesson and you get it free. Results depend on your offer, your market and your budget, so nothing here is a promise of income.

Questions

Do I need my own lab to follow along?

Yes. The course walks you through deploying an Active Directory lab from scratch, but you need a machine with at least 32 GB of RAM and 300 GB of free disk space to run the virtual machines.

Is this course about exploiting software vulnerabilities?

No. The focus is on abusing legitimate Active Directory features and common misconfigurations, such as delegation, ACLs, certificate services and trusts, which is how most real internal compromises happen.

Which tools will I be working with?

You use industry-standard tooling including NetExec, BloodHound, Impacket, Certipy, Responder, Hashcat, kerbrute and mitm6, alongside manual techniques with Dig, nslookup and ldapsearch.

Does this cover cross-domain and cross-forest attacks?

Yes. There are dedicated sections on domain and forest trust abuse, including golden ticket and trust key attacks, foreign group membership, AD CS ESC abuse across trusts, and SID filtering bypass.

Is there anything on reporting?

Yes. The final module covers penetration test report writing and includes a full walkthrough of a sample report so you can communicate findings in a way clients can prioritize and fix.

How long do I have access?

For as long as the site exists. There is no subscription.

Do I need to buy any software?

Only what is listed under Platforms covered. Most courses use free tools or ones you already pay for.

Is it for beginners?

Check the level badge above. Beginner means no prior experience; Intermediate means you have already sold something online.

How much will I earn?

We do not know, and anyone who tells you a number does not either. The course gives you a method that we have run ourselves; the result depends on your offer, your market and your budget.

What if the platform changes after I buy?

We re-record the affected lessons and you get the update free. The Updated date on this page shows when we last checked.

Refunds?

30 days, no questions. Email us.

Ship it this week.

Lifetime access · Works on any device · 30-day refund