Topic map
No fixed order — jump straight to the topic you need. Marks are saved in your browser.
Move your progress to another device
Progress lives in this browser only. Copy the code and paste it on your other device.
Your transfer code
Paste a code from another device
Table of contents
Filter by group
CCNA — Cisco Networking Fundamentals
OSI/TCP-IP model, Switching and VLAN, Routing, IPv4/IPv6 addresses, Network services and security — The basis for the CCNA 200-301 exam.
OSI and TCP/IP Model
The seven layers, what happens in each layer, and how it helps troubleshoot problems.
Switching, VLAN and Trunk
MAC Table, VLANs, 802.1Q, Access vs. Trunk and STP.
IPv4 Addresses and Subnetting
Classes, CIDR, Subnet Calculation and VLSM — The most tested topic in CCNA.
Routing: Static, OSPF and Default Route
How a router chooses a route, routing table, static and dynamic routing.
Network Services: DHCP, DNS, NAT, and NTP
The services that run every enterprise network — and also every Active Directory environment.
Network Security in CCNA: Port Security, ACL, and 802.1X
Basic protections on the switch and router, and why they are also important for Active Directory.
IPv6: Global Unicast and Link-Local
Address structure, address types, SLAAC, and why IPv6 is important even in the AD world.
STP and RSTP: Root Bridge Election and Port Roles
How switches prevent loops, who is elected Root, and how to read show spanning-tree.
EtherChannel: LACP and PAgP
Uniting several cables into one logical link — more bandwidth and redundancy without loops.
OSPFv2: Router ID, Hello and DR/BDR
Dynamic routing that updates itself: how neighbor adjacency is built, who is elected DR, and how to diagnose issues.
ACL: Standard vs. Extended and Rule Order
Where to place an access list, why order is critical, and what the implicit deny any is.
Port Security, SSH and Device Hardening
Closing the entrance door: MAC restriction, encrypted management, and disabling unnecessary services.
Active Directory Basics
What is AD, what are Domains, Forests and Trees. Main objects and general structure.
Protocols and Authentication
LDAP, Kerberos, NTLM and how login to the domain actually happens.
Attacks on AD
How attackers may attack the domain and why these methods actually work.
Kerberoasting
An attack on SPN accounts with weak passwords.
Pass-the-Hash and Pass-the-Ticket
Attacks that use stolen Hashes or Tickets.
Shadow Credentials (msDS-KeyCredentialLink)
Writing a key credential to a victim account — a TGT via PKINIT without the password.
Diamond Ticket and Bronze Bit
Modifying a real TGT under the radar and exploiting Constrained Delegation even on Protected Users.
AD CS — ESC1–ESC8: Attacking the Certificate Authority
The internal certificate authority is the domain's «ID printer» — and a misconfigured template is a pass to Domain Admin.
DCSync — «I am a Domain Controller too»
Forged AD replication: anyone with Replicating Directory Changes rights asks the DC for all the hashes — without touching NTDS.dit.
NTLM Relay and LLMNR — Impersonating Without Cracking
Why crack a hash when you can simply pass it along? LLMNR poisoning and relaying NTLM authentication to unsigned services.
Delegation in Active Directory
Permission Delegation: Unconstrained, Constrained and Resource-Based — how it works, how it's exploited and how to defend against it.
What is Delegation
Why a server needs to impersonate a user, and what that means from a security standpoint.
Unconstrained Delegation
The server holds a full TGT of everyone who connects to it — and the danger in that.
Constrained Delegation (KCD)
Delegation restricted to a list of services, and what Protocol Transition is.
Resource-Based Constrained Delegation (RBCD)
Delegation determined by the resource itself — and why it's a popular attack path.
Defense and Monitoring
Practices, policies and tools for protecting the Domain.
Tools
What system administrators and information security professionals use.
Standard Tools for AD Admins
RSAT, ADUC, PowerShell and additional tools.
Important Event IDs in AD
Which events in Event Viewer are worth tracking.
GOAD — Game of Active Directory
A vulnerable AD lab to practice all the attack chains you learned — in an isolated environment.
Reading the BloodHound graph — from user to Domain Admin
Walking an attack path step by step — and using the same tool for defense.
Incident Response
What to do once the Domain has already been breached: detection, containment and recovery.
Practice and Learning
A home lab and hands-on practice of user management in AD.
DHCP and Network Preparation
How DHCP integrates with AD and DNS, what threats exist, and how to manage it all with PowerShell.
DHCP and Integration with Active Directory
Authorization in AD, Scopes, Options and Dynamic DNS Updates.
Rogue DHCP and Network Threats
DHCP Starvation, Rogue Server, DHCPv6, and mitm6 — and their defenses.
Managing DHCP with PowerShell
Installation, Authorization, Scopes, Options, backup and monitoring.
DNS in Windows Server: Zones and Records
Forward/Reverse, AD-Integrated, A/AAAA/CNAME/PTR/MX Records, Forwarders and Root Hints.
Scope, Reservations and Options in DHCP
Building a correct Scope: range, exclusions, Gateway, DNS, domain suffix and fixed reservations.
From Zero: Network, Server and Domain
No prior background needed: what is a network, IP, DNS, what is Windows Server, and how to set up your first Domain Controller.
Networking from zero: IP, Subnet, Gateway
The basic concepts without which you can't understand AD.
DNS — the heart of Active Directory
A, PTR, SRV records and why there's no Domain without DNS.
Workgroup vs Domain
Why an organization moves to centralized management and what it actually gives you.
Setting up the first Domain Controller
From a clean Windows Server to an active Domain, step by step.
Day-to-day administration of AD
OUs and groups, NTFS and Share permissions, password policy, RSAT and AD backup — the routine work of a system administrator.
OU, groups and the AGDLP model
How to organize objects and delegate permissions correctly.
NTFS permissions vs Share permissions
Two layers of permissions on a shared folder — and how they intersect.
Password policy and Fine-Grained Password Policy
Default Domain Policy, account lockout and PSO for special groups.
Backup and Restore of Active Directory
System State, Authoritative Restore, and AD Recycle Bin.
Advanced Protocols and Infrastructure
NTLM, SMB, LDAPS, SPN, Trusts, and Sites & Replication.
NTLM — the old protocol that's still alive
Challenge-Response, why it's weak, and how to mitigate it.
SPN and LDAPS
How services are identified in Kerberos and how LDAP is encrypted.
Trusts Between Domains and Forests
Trust types, direction, Transitivity, and SID Filtering.
Sites, Subnets, and Replication
How AD synchronizes between sites and how a client chooses a nearby DC.
Advanced Attacks and Modern Defenses
AS-REP Roasting, Golden and Silver Ticket, ACL abuse — and against them LAPS, Credential Guard, Tiering, and MDI.
AS-REP Roasting
Exploiting accounts without Pre-Authentication.
Golden Ticket and Silver Ticket
Forging Kerberos tickets and their implications.
ACL Abuse in Active Directory
GenericAll, WriteDACL, and quiet escalation paths.
Modern Defenses: LAPS, Credential Guard, MDI
The defense layers that break common attack paths.
SOC Analyst — Read traffic, logs, and attacks
Anatomy of a network packet in Wireshark, Windows Event ID map, interactive Cyber Kill Chain, and how SIEM connects everything.
Network Packet Anatomy — Where to look for an attacker
Ethernet / IP / TCP / Payload by OSI layers, and what to check in each layer in Wireshark.
Windows Event ID Map for the Analyst
The events that really matter: logins, user creation, protected groups, and process execution.
Cyber Kill Chain and SIEM
The seven stages of an attack with what is seen at each stage, and how a central log server connects the picture.
Cloud Computing: Architecture and Security
Public versus Private Cloud, IaaS/PaaS/SaaS service models, and Azure's Shared Responsibility Model.
Public Cloud vs. Private Cloud
The differences between cloud infrastructure deployment models.
Service Models: IaaS vs. PaaS vs. SaaS
Who manages what — from On-Premises to SaaS.
Shared Responsibility Model (Microsoft Azure)
What is always yours, what is always the provider's, and what changes according to the service model.
Identity in the Cloud: Entra ID vs. Active Directory
The difference between on-premises directory and cloud identity, and hybrid models.
Networking in the Cloud: VNet, Subnet, NSG, and On-Premises Connection
What a virtual network in the cloud looks like and who controls traffic.
Cloud Security Controls: Zero Trust, MFA, and Conditional Access
How to protect identities and permissions when there is no physical perimeter.
Storage, Backup, and Disaster Recovery (BCDR)
Redundancy levels, RPO/RTO, and the 3-2-1 rule in the cloud world.
Common Cloud Attacks and What to Identify in Logs
Misconfiguration, Token theft, Consent Phishing, and monitoring.
Microsoft Entra ID (Azure AD)
Cloud identity: how it differs from AD DS, how to connect an on-prem domain to the cloud, and how to protect access.
What Entra ID is and how it differs from AD DS
Cloud identity versus an on-prem domain controller — the core concepts.
Hybrid identity: Entra Connect, PHS, PTA and federation
How to connect an on-prem domain to Entra ID and how the sign-in methods differ.
Protecting access: Conditional Access, MFA and PIM
How cloud identities are protected and what to check when something looks suspicious.
PIM made simple: admin rights only when you need them
How Privileged Identity Management works — Eligible vs Active, activation, approval and audit.
Conditional Access in practice: your first four rules
A baseline rule set to start with, and how to test it without locking everyone out.
Attacks on Entra ID: what attackers do in the cloud
Password spray, MFA fatigue, token theft and malicious app consent — and how to spot them.
Network security: Fortinet
Infrastructure security foundations, firewall evolution, FSSO, AAA, 802.1X, detection and practical lab appendices.
Infrastructure security devices
Defense in depth, L2/L3/L7 and the CIA triad.
Firewall evolution — from stateless to NGFW
State tables, proxy firewalls, IDS/IPS and FortiGate.
What are FortiGate and FortiOS?
Intro to Fortinet's NGFW, the FortiOS operating system and the Security Fabric concept.
Firewall policies and objects
How a policy is built, the order it is evaluated in, and why objects save dozens of rules.
NAT on FortiGate: SNAT and VIP
Outbound address translation, IP pools and publishing an internal server with a Virtual IP.
VPN: IPsec site-to-site and SSL VPN
Connecting two offices and remote employee access, including the IPsec negotiation phases.
Security profiles and SSL inspection
AntiVirus, IPS, web filter, application control and Certificate vs Deep Inspection.
Logs and troubleshooting
A clear workflow: from the GUI log to CLI sniffer and debug flow.
FSSO — how the firewall knows who is who in AD
Mapping user-to-IP from DC logon events and firewall policies driven by AD groups.
FortiAuthenticator — RADIUS, TACACS+ and MFA with AD
An AAA server synced with AD: RADIUS for users, TACACS+ for admins, plus a second factor.
802.1X and NAC — only authenticated devices get in
Port-level authentication, EAP-TLS vs PEAP, dynamic VLAN assignment and the Evil Twin trap.
A network view of the course attacks — what Fortinet adds
What the network layer sees versus DC logs, and how segmentation limits lateral movement.
For the curious
Optional — feel free to skip. The core topics are above.
The ICAO/NATO spelling alphabet
Accurate voice communication of technical identifiers.
Envario lab rules
Session planning, RDP, protecting the environment and support.