Active Directory Fundamentals
Active Directory (AD) is the system almost every company uses to manage identities and resources on Windows networks: users, computers, groups, policies, and permissions, all centralized. It’s by far the largest attack surface in an internal pentest, and the whole Windows & AD area depends on first understanding these pieces. This card is the base vocabulary before attacking.
The pieces
Section titled “The pieces”- Domain: an administrative unit (e.g.
corp.local) with its users, computers, and common policy. - Domain Controller (DC): the server running AD; it holds the database (
NTDS.dit) and authenticates everyone. Compromise a DC = compromise the domain. - Forest: a set of domains sharing schema and trust. The forest, not the domain, is the real security boundary (see Trust and Forest Abuse).
- OU (Organizational Unit): a container to organize objects and apply policies (GPO) to them.
- Objects: users, computers (each machine is an
COMPUTER$account), groups, GPOs.
Privileged groups (the ones that matter)
Section titled “Privileged groups (the ones that matter)”Domain Admins full control of the domainEnterprise Admins control of the whole forestAdministrators local admin of the DCAccount Operators / Backup Operators / Server Operators / DnsAdmins "delegated" groups that are often escalation to DAReaching Domain Admin (or Enterprise Admin) is the typical goal of an internal pentest.
Authentication: Kerberos and NTLM
Section titled “Authentication: Kerberos and NTLM”- Kerberos (the modern one): the DC (KDC) issues tickets. You request a TGT on authenticating and with it request a TGS for each service. Basis of Kerberoasting, AS-REP roasting, Golden Ticket (see Kerberos Attacks).
- NTLM (legacy): challenge-response; its hash enables Pass-the-Hash and relay (see NTLM Relay).
LDAP and DNS in AD
Section titled “LDAP and DNS in AD”- LDAP (port 389): the protocol to query/modify the directory. Any authenticated user can read almost everything → the basis of enumeration (see Active Directory Enumeration).
- DNS: locates the DCs (SRV records
_ldap._tcp.dc._msdcs). AD doesn’t work without DNS.
GPO (Group Policy)
Section titled “GPO (Group Policy)”Policies applied to OUs/domain: security configuration, scripts, software, local group membership. Very powerful —and an attack vector if you can modify them (see GPO Abuse).
Trusts
Section titled “Trusts”Relationships that let users of one domain authenticate in another. Within a forest they’re automatic; across forests, configurable. Badly managed, they let you jump from one domain to another (see Trust and Forest Abuse).
Why it matters in security
Section titled “Why it matters in security”AD concentrates all corporate identity, so a single flaw (a weak password, a bad ACL, an insecure delegation) can escalate to full domain control. Understanding domain/DC/forest/OU, the privileged groups, and Kerberos/NTLM/LDAP is the absolute prerequisite for the whole Windows & AD area: without it, that section’s attacks make no sense.
Kerberos authentication flow (step by step)
Section titled “Kerberos authentication flow (step by step)”Understanding this flow is the basis of almost every AD attack (Kerberos Attacks):
1. AS-REQ the user requests a TGT from the KDC (DC), encrypting a timestamp with its hash (preauth)2. AS-REP the KDC returns the TGT (encrypted with the krbtgt key) + a session key3. TGS-REQ with the TGT, the user requests a service ticket (TGS) for "cifs/fileserver"4. TGS-REP the KDC returns the TGS encrypted with the SERVICE account's hash5. AP-REQ the user presents the TGS to the service -> accessThe attacks come from here: no preauth (step 1) -> AS-REP roasting; the step-4 TGS is encrypted with the service’s hash -> Kerberoasting (crackable offline); the TGT is encrypted with krbtgt -> whoever has its hash forges a Golden Ticket.
AD attack map (where each piece continues)
Section titled “AD attack map (where each piece continues)”Enumeration ad-enum, ad-bloodhound (graph of paths to DA)Credentials ad-llmnr (poisoning), ad-ntlm (relay), ad-spray, ad-creds (dumping)Kerberos ad-kerberos (roasting, golden/silver), ad-delegationEscalation/ACLs ad-delegation, ad-adcs (certificates), ad-gpo, ad-shadowcredsMovement ad-lateral (PtH, PsExec, WMI), ad-mssqlPersistence ad-persist (golden ticket, DCSync, skeleton key)Cross-domain ad-trusts (the forest is the security boundary)This card is just the vocabulary; each vector lives in its card in the Windows & AD area.
Mastery checklist
Section titled “Mastery checklist”- I can explain what a domain, DC, forest, and OU are
- I understand why compromising a DC = compromising the domain
- I know the privileged groups (Domain/Enterprise Admins and delegated)
- I distinguish Kerberos from NTLM and know what a TGT/TGS is
- I understand LDAP’s and DNS’s role in AD
- I know what GPOs and trusts are, and why they’re vectors
- I know any authenticated user can read much of the directory