Skip to main content
AD Academy
Tools
Advanced22 minLast updated: Topic 3 of 4

GOAD — Game of Active Directory

A vulnerable AD lab to practice all the attack chains you learned — in an isolated environment.

Not read

What you will learn here

  • What GOAD is and why it beats a simple home lab
  • How to install GOAD on VMware / VirtualBox
  • A practice roadmap mapped to the course modules

Worth reading first:Important Event IDs in AD

Theory

(Game of ) is a deliberately vulnerable lab: a large AD environment simulating a real organization — about 5 domains, dozens of servers and users, trust relationships and real configuration mistakes. The goal: practice every attack from the course in a safe and controlled environment.

Why GOAD specifically

  • The topology resembles a corporate network — you learn not only the attack but the privilege escalation chain across domains.
  • Built by Orange Cyberdefense — one of the leading security teams.
  • Comes with automated attack checks — you can verify you did it right.
  • There is also GOAD-Light — a slimmed-down version for basic practice with limited resources.

Root forest sevenkingdoms.local with child domains north and south, separate forest essos.local with a trust. Each domain contains different vulnerabilities: Kerberoasting, Unconstrained Delegation, ACL abuse and more. Practice path: enumeration, escalation, DCSync, cross-domain.

Short and clear

  • GOAD is a deliberately vulnerable AD environment with about 5 domains and trust relationships.
  • Each domain contains different vulnerabilities for varied practice.
  • Run in an isolated network only — the machines are vulnerable.
  • Enable Sysmon to learn which events each attack generates.

Real-life exampleAfter Kerberoasting in GOAD, check the logs: which Event ID fired? That turns you from someone who can attack into someone who can detect.

Setup

Minimum requirements: 16GB RAM (32GB recommended), a CPU with virtualization, and VMware Workstation / VirtualBox / Proxmox.

git clone https://github.com/Orange-Cyberdefense/GOAD.git
cd GOAD
# VMware
./goad.sh -t install -p vmware -l GOAD -a
# VirtualBox
./goad.sh -t install -p virtualbox -l GOAD -a
bash

The installation downloads ready-made VMs and runs Ansible playbooks that configure domains, users and vulnerabilities.

Practice roadmap (by course modules)

  • basics + Enumeration → reconnaissance: collection across all domains.
  • → , AS-REP Roasting, .
  • → find accounts with Constrained/ and exploit them.
  • → identify CA servers and trigger .
  • Defense → set up monitoring and capture the Event IDs of attacks in real time.

Detection — enable Sysmon

The truly important step: enable Sysmon + Windows Event Forwarding in the lab, and with every attack — check which events were generated. This is the tool that turns you from someone who can attack into someone who can catch the attacker.

Mitigation

  • After every attack: fix the issue in (remove a permission, rotate a password, disable delegation) and verify the attack is truly blocked.
  • Practice response too: which logs show exactly when the attack happened?

Check yourself

What is GOAD?

Why must GOAD be run in an isolated network?

What is the difference between GOAD and GOAD-Light?

What is the main value of enabling Sysmon in the lab?

Was this page helpful?