Skip to main content
AD Academy

Attack cards

Eight common Active Directory attacks, ordered along the attacker's chain: requirements, detection and defense.

AS-REP Roasting

🟢 Easy
MITRE ATT&CK T1558.004
Requires
A list of usernames
Detection
4768 (RC4, no pre-authentication)4768
Defense
Never disable pre-authentication; strong passwords
GetNPUsers.py lab.local/ -usersfile users.txt

Leads to: Kerberoasting

AD CS (ESC1)

🟡 Medium
MITRE ATT&CK T1649
Requires
Vulnerable certificate template + enroll right
Detection
4886/4887, 4768488648874768
Defense
Audit templates, remove EDITF_ATTRIBUTESUBJECTALTNAME2, EPA
certipy req -template VulnTemplate -upn admin@lab.local

Leads to: DCSync

Delegation Abuse

🟡 Medium
MITRE ATT&CK T1134.001
Requires
An account with Unconstrained/Constrained Delegation
Detection
4768/4769 (S4U), 4624476847694624
Defense
RBCD instead of Unconstrained; audit delegated accounts
Rubeus s4u /user:svc /impersonateuser:admin

Leads to: DCSync

DCSync

🔴 Hard
MITRE ATT&CK T1003.006
Requires
Replicating Directory Changes (All) rights
Detection
4662 (GUID 1131f6aa-…)4662
Defense
Minimize replication rights; monitor 4662; reset krbtgt twice
mimikatz: lsadump::dcsync /user:krbtgt

Leads to: Golden Ticket

Golden Ticket

🔴 Hard
MITRE ATT&CK T1558.001
Requires
The krbtgt hash (after DCSync)
Detection
TGT with an anomalous lifetime
Defense
Reset krbtgt twice, Tiering, monitoring
mimikatz: kerberos::golden /user:admin /krbtgt:hash

End of the chain — full domain control

I have a problem — search by symptom →