Skip to content

Active Directory Fundamentals

Active Directory (AD) is the system almost every company uses to manage identities and resources on Windows networks: users, computers, groups, policies, and permissions, all centralized. It’s by far the largest attack surface in an internal pentest, and the whole Windows & AD area depends on first understanding these pieces. This card is the base vocabulary before attacking.

  • Domain: an administrative unit (e.g. corp.local) with its users, computers, and common policy.
  • Domain Controller (DC): the server running AD; it holds the database (NTDS.dit) and authenticates everyone. Compromise a DC = compromise the domain.
  • Forest: a set of domains sharing schema and trust. The forest, not the domain, is the real security boundary (see Trust and Forest Abuse).
  • OU (Organizational Unit): a container to organize objects and apply policies (GPO) to them.
  • Objects: users, computers (each machine is an COMPUTER$ account), groups, GPOs.
Domain Admins full control of the domain
Enterprise Admins control of the whole forest
Administrators local admin of the DC
Account Operators / Backup Operators / Server Operators / DnsAdmins
"delegated" groups that are often escalation to DA

Reaching Domain Admin (or Enterprise Admin) is the typical goal of an internal pentest.

  • Kerberos (the modern one): the DC (KDC) issues tickets. You request a TGT on authenticating and with it request a TGS for each service. Basis of Kerberoasting, AS-REP roasting, Golden Ticket (see Kerberos Attacks).
  • NTLM (legacy): challenge-response; its hash enables Pass-the-Hash and relay (see NTLM Relay).
  • LDAP (port 389): the protocol to query/modify the directory. Any authenticated user can read almost everything → the basis of enumeration (see Active Directory Enumeration).
  • DNS: locates the DCs (SRV records _ldap._tcp.dc._msdcs). AD doesn’t work without DNS.

Policies applied to OUs/domain: security configuration, scripts, software, local group membership. Very powerful —and an attack vector if you can modify them (see GPO Abuse).

Relationships that let users of one domain authenticate in another. Within a forest they’re automatic; across forests, configurable. Badly managed, they let you jump from one domain to another (see Trust and Forest Abuse).

AD concentrates all corporate identity, so a single flaw (a weak password, a bad ACL, an insecure delegation) can escalate to full domain control. Understanding domain/DC/forest/OU, the privileged groups, and Kerberos/NTLM/LDAP is the absolute prerequisite for the whole Windows & AD area: without it, that section’s attacks make no sense.

Kerberos authentication flow (step by step)

Section titled “Kerberos authentication flow (step by step)”

Understanding this flow is the basis of almost every AD attack (Kerberos Attacks):

1. AS-REQ the user requests a TGT from the KDC (DC), encrypting a timestamp with its hash (preauth)
2. AS-REP the KDC returns the TGT (encrypted with the krbtgt key) + a session key
3. TGS-REQ with the TGT, the user requests a service ticket (TGS) for "cifs/fileserver"
4. TGS-REP the KDC returns the TGS encrypted with the SERVICE account's hash
5. AP-REQ the user presents the TGS to the service -> access

The attacks come from here: no preauth (step 1) -> AS-REP roasting; the step-4 TGS is encrypted with the service’s hash -> Kerberoasting (crackable offline); the TGT is encrypted with krbtgt -> whoever has its hash forges a Golden Ticket.

AD attack map (where each piece continues)

Section titled “AD attack map (where each piece continues)”
Enumeration ad-enum, ad-bloodhound (graph of paths to DA)
Credentials ad-llmnr (poisoning), ad-ntlm (relay), ad-spray, ad-creds (dumping)
Kerberos ad-kerberos (roasting, golden/silver), ad-delegation
Escalation/ACLs ad-delegation, ad-adcs (certificates), ad-gpo, ad-shadowcreds
Movement ad-lateral (PtH, PsExec, WMI), ad-mssql
Persistence ad-persist (golden ticket, DCSync, skeleton key)
Cross-domain ad-trusts (the forest is the security boundary)

This card is just the vocabulary; each vector lives in its card in the Windows & AD area.

  • I can explain what a domain, DC, forest, and OU are
  • I understand why compromising a DC = compromising the domain
  • I know the privileged groups (Domain/Enterprise Admins and delegated)
  • I distinguish Kerberos from NTLM and know what a TGT/TGS is
  • I understand LDAP’s and DNS’s role in AD
  • I know what GPOs and trusts are, and why they’re vectors
  • I know any authenticated user can read much of the directory