{"id":13589512,"url":"https://github.com/DeanOfCyber/Active-Directory-Penetration-Testing-and-Security","last_synced_at":"2025-04-08T09:33:01.773Z","repository":{"id":208628395,"uuid":"380958348","full_name":"DeanOfCyber/Active-Directory-Penetration-Testing-and-Security","owner":"DeanOfCyber","description":"Resources for AD penetration testing and security","archived":false,"fork":false,"pushed_at":"2022-02-21T20:14:10.000Z","size":25,"stargazers_count":30,"open_issues_count":0,"forks_count":12,"subscribers_count":3,"default_branch":"main","last_synced_at":"2024-11-06T09:39:48.757Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/DeanOfCyber.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null}},"created_at":"2021-06-28T08:21:32.000Z","updated_at":"2024-10-11T16:37:42.000Z","dependencies_parsed_at":"2023-11-22T13:45:37.750Z","dependency_job_id":"72a39a5c-79a3-4fac-ad71-43d7ed3c8a2e","html_url":"https://github.com/DeanOfCyber/Active-Directory-Penetration-Testing-and-Security","commit_stats":null,"previous_names":["deanofcyber/active-directory-penetration-testing-and-security"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/DeanOfCyber%2FActive-Directory-Penetration-Testing-and-Security","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/DeanOfCyber%2FActive-Directory-Penetration-Testing-and-Security/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/DeanOfCyber%2FActive-Directory-Penetration-Testing-and-Security/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/DeanOfCyber%2FActive-Directory-Penetration-Testing-and-Security/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/DeanOfCyber","download_url":"https://codeload.github.com/DeanOfCyber/Active-Directory-Penetration-Testing-and-Security/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":247814242,"owners_count":21000528,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T16:00:31.050Z","updated_at":"2025-04-08T09:33:01.500Z","avatar_url":"https://github.com/DeanOfCyber.png","language":null,"funding_links":[],"categories":["Active Directory"],"sub_categories":["Azure"],"readme":"# Active Directory Penetration Testing and Security\nResources for AD penetration testing and security\n\n## Videos by yours truly\n\nSetup Domain Controller and Active Directory For Penetration Testing\nhttps://www.youtube.com/watch?v=j5AI-BKXmCw\n\nCreate and configure domain accounts for multiple password attacks\nhttps://www.youtube.com/watch?v=MigPswiQFOg\n\nKerberos AS-REP Roasting with HTB Sauna\nhttps://www.youtube.com/watch?v=3GvcfQSOj5E\n\n\nMore coming soon...\n\n## Pentest/Red Team General\nhttps://zer1t0.gitlab.io/posts/attacking_ad/\n\nhttps://gist.github.com/jivoi/c354eaaf3019352ce32522f916c03d70  \n\nhttps://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference/  \n\nhttps://lolbas-project.github.io/ \n\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Active%20Directory%20Attack.md#active-directory-recon \n\nhttps://adsecurity.org/?p=2362  \n\nhttps://www.blackhat.com/docs/us-15/materials/us-15-Metcalf-Red-Vs-Blue-Modern-Active-Directory-Attacks-Detection-And-Protection.pdf\n\n\n## General Active Directory Concepts \n\nhttps://docs.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview \n\nhttps://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-r2-and-2008/cc771568(v=ws.10) \n\nhttps://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc759186(v=ws.10) \n\nhttps://docs.microsoft.com/en-us/windows/security/identity-protection/access-control/active-directory-accounts \n\nhttps://docs.microsoft.com/en-us/windows/security/identity-protection/access-control/security-identifiers  \n\nhttps://docs.microsoft.com/en-US/troubleshoot/windows-server/identity/security-identifiers-in-windows  \n\nhttps://adsecurity.org/?p=2288  \n\n\n## Active Directory Enumeration \n\nhttp://woshub.com/get-aduser-getting-active-directory-users-data-via-powershell/ \n\nhttp://www.harmj0y.net/blog/redteaming/local-group-enumeration/  \n\nhttps://www.sans.org/security-resources/posters/bloodhound-cheat-sheet/430/download\n\n\n## Authentication Attacks\n**NTLM**\n\nhttps://www.crowdstrike.com/cybersecurity-101/ntlm-windows-new-technology-lan-manager/  \n\nhttps://infinitelogins.com/2020/11/16/capturing-relaying-net-ntlm-hashes-without-kali-linux-using-inveigh/\n\n\n**Kerberos Attacks**\n\nhttps://blog.redforce.io/windows-authentication-attacks-part-2-kerberos/  \n\nhttps://www.blackhat.com/docs/us-14/materials/us-14-Duckwall-Abusing-Microsoft-Kerberos-Sorry-You-Guys-Don't-Get-It-wp.pdf  \n\nhttps://stealthbits.com/blog/what-is-kerberos/\n\nhttp://www.harmj0y.net/blog/activedirectory/roasting-as-reps/\n\nhttps://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html \n\nhttps://stealthbits.com/blog/how-to-detect-pass-the-ticket-attacks/\n\nhttps://book.hacktricks.xyz/windows/active-directory-methodology/over-pass-the-hash-pass-the-key\n\n**Password Spraying**\n\nhttps://github.com/dafthack/DomainPasswordSpray \n\nhttps://medium.com/walmartglobaltech/windows-for-loop-password-spraying-made-easy-c8cd4ebb86b5 \n\n**Mimikatz**\n\nhttps://www.sentinelone.com/blog/windows-security-essentials-preventing-4-common-methods-of-credentials-exfiltration/  \n\nhttps://ivanitlearning.wordpress.com/2019/09/07/mimikatz-and-password-dumps/\n\nhttps://en.hackndo.com/remote-lsass-dump-passwords/#mimikatz-module\n\nhttps://www.hackingarticles.in/powershell-empire-for-pentester-mimikatz-module/\n\n\n## Lateral Movement \nhttps://posts.specterops.io/offensive-lateral-movement-1744ae62b14f  \n\nhttps://blog.ropnop.com/using-credentials-to-own-windows-boxes-part-3-wmi-and-winrm/ \n\n\n## ACLs\n\nhttps://www.blackhat.com/docs/us-17/wednesday/us-17-Robbins-An-ACE-Up-The-Sleeve-Designing-Active-Directory-DACL-Backdoors-wp.pdf\n\n\n## Lab Setup\nhttps://github.com/WazeHell/vulnerable-AD  \n\nhttps://thedarksource.com/setting-up-an-active-directory-lab-for-red-teaming/  \n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FDeanOfCyber%2FActive-Directory-Penetration-Testing-and-Security","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FDeanOfCyber%2FActive-Directory-Penetration-Testing-and-Security","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FDeanOfCyber%2FActive-Directory-Penetration-Testing-and-Security/lists"}