Red TeamingExpert Level50 Hours Live

Active Directory Enterprise Attack Paths

BloodHound graph analysis, Kerberoasting, AS-REP roasting, AD CS abuse, and Golden Ticket persistence.

BloodHound Trust Graph Mining
Kerberos Ticket Forgery
EDR Evasion & Memory Unhooking
50 Hours Practical Workload
1 Core Modules
2 Sandboxed Labs
Cryptographic TS-ID Verifiable

Course Overview & Objectives

An elite red teaming masterclass dissecting Windows enterprise infrastructure. Discover how real-world attackers map privilege escalation graphs with BloodHound, abuse Kerberos delegation, exploit Active Directory Certificate Services (AD CS), and establish domain persistence.

What You Will Master

  • Enumerate hidden enterprise trust paths using BloodHound and SharpHound
  • Execute Kerberoasting and AS-REP roasting attacks to crack service account passwords
  • Abuse vulnerable AD CS certificate templates (ESC1 through ESC8) for instant domain admin escalation
  • Forge Golden and Silver Kerberos tickets for persistent stealth access

Prerequisites

  • Strong understanding of Windows domains & Kerberos
  • Basic PowerShell scripting

Platforms & Tools Covered

BloodHoundMimikatzRubeusCertifyImpacketPowerView

Detailed Curriculum Modules

1 modules structured from foundational theory through complex adversarial execution.

50 Total Workload Hours
MODULE 01

Active Directory Architecture & Kerberos In-Depth

2 Lessons

TGTs, TGSs, SPNs, and the underlying mechanics of Windows authentication.

Dissecting Kerberos Traffic in Wireshark
50m
Extracting and Cracking Service Tickets with Rubeus
60m

Hands-on Virtual Sandbox Labs

Zero local hardware dependencies. Provisioned in cloud containers via browser terminal.

LAB 01~60 mins

AD CS ESC1 Exploitation Sandbox

Find misconfigured certificate templates and request a certificate on behalf of Domain Admin.

Skills Tested:AD CS, PKI, Red Teaming
LAB 02~65 mins

Golden Ticket Forgery & DCShadow Persistence

Dump KRBTGT hash and forge long-term valid Kerberos tickets.

Skills Tested:Mimikatz, Kerberos, Persistence

Faculty & Lead Instructor

Direct weekly instruction, live office hours, and code-review feedback.

KS

Kunal Singh

Thread Security Education

Offensive Security Lead

Certified Red Teamer with hundreds of successful domain compromise engagements across global corporate networks.

Frequently Asked Questions

Everything you need to know about scheduling, cohort admissions, and lab access.

Do I get access to a full Windows Active Directory lab?

Yes! You receive access to a multi-domain forest virtual lab with real Windows Server domain controllers.

Ready to Master Active Directory Enterprise Attack Paths?

Join the upcoming cohort. Seats are limited to maintain a high faculty-to-student ratio and rigorous sandbox feedback.