Theory
(Game of ) is a deliberately vulnerable lab: a large AD environment simulating a real organization — about 5 domains, dozens of servers and users, trust relationships and real configuration mistakes. The goal: practice every attack from the course in a safe and controlled environment.
Why GOAD specifically
- The topology resembles a corporate network — you learn not only the attack but the privilege escalation chain across domains.
- Built by Orange Cyberdefense — one of the leading security teams.
- Comes with automated attack checks — you can verify you did it right.
- There is also GOAD-Light — a slimmed-down version for basic practice with limited resources.
Root forest sevenkingdoms.local with child domains north and south, separate forest essos.local with a trust. Each domain contains different vulnerabilities: Kerberoasting, Unconstrained Delegation, ACL abuse and more. Practice path: enumeration, escalation, DCSync, cross-domain.
Setup
Minimum requirements: 16GB RAM (32GB recommended), a CPU with virtualization, and VMware Workstation / VirtualBox / Proxmox.
The installation downloads ready-made VMs and runs Ansible playbooks that configure domains, users and vulnerabilities.
Practice roadmap (by course modules)
- basics + Enumeration → reconnaissance: collection across all domains.
- → , AS-REP Roasting, .
- → find accounts with Constrained/ and exploit them.
- → identify CA servers and trigger .
- Defense → set up monitoring and capture the Event IDs of attacks in real time.
Detection — enable Sysmon
The truly important step: enable Sysmon + Windows Event Forwarding in the lab, and with every attack — check which events were generated. This is the tool that turns you from someone who can attack into someone who can catch the attacker.
Mitigation
- After every attack: fix the issue in (remove a permission, rotate a password, disable delegation) and verify the attack is truly blocked.
- Practice response too: which logs show exactly when the attack happened?