Home
Cybersecurity & AI Security / Part 28 — Active Directory Fundamentals and Attacks

Active Directory Fundamentals and Attacks

CAP, ACID vs BASE, latency numbers, back-of-envelope estimation, single points of failure — the vocabulary every system designer thinks in.


Core Philosophy: Most organizations don’t run their computers as a loose collection of independent machines. They run them as a managed, interconnected whole — and on Windows networks, the system that does this is Active Directory. It is the backbone of the corporate world. For an attacker, it is the grand prize: compromise Active Directory and you don’t own a machine, you own the organization. For a defender, it is the thing that most needs protecting.

Part 1: The Problem

So far in Phase 3 you’ve thought one machine at a time — scan a host, attack a service, get a foothold, escalate on that box. But real organizations have hundreds or thousands of machines and users, and they need to manage them centrally: one identity per employee, consistent policies, shared resources, unified administration.

On Windows networks — which is most corporate environments — the system providing all of this is Active Directory (AD). Because AD centralizes identity and access for the whole organization, it is also a centralized target. An attacker who fully compromises AD effectively controls every machine, every account, and every resource it governs. This is why nearly every internal penetration test and every red team engagement revolves around Active Directory — and why understanding it, at least at a foundational level, is essential.

This page is a foundational introduction — AD attacks are deep enough to be a specialization of their own. The goal here is genuine conceptual understanding plus guided practical exposure, so you grasp how single-machine compromise becomes whole-network compromise. Phase 5 and beyond is where AD can be taken to real depth.

Part 2: The Concept — What Active Directory Is

Active Directory is Microsoft’s directory service: a central system that stores and manages identities (users, computers, groups) and controls authentication and authorization across a Windows network.

Think of it as the organization’s central identity authority. The core ideas:

text
        THE DOMAIN  (managed as one whole)
   ┌───────────────────────────────────────────┐
   │   ┌──────────────────────┐                │
   │   │  DOMAIN CONTROLLER   │ ← runs AD;      │
   │   │  (runs Active Dir.)  │   the crown     │
   │   └──────────┬───────────┘   jewel         │
   │              │ authenticates & manages     │
   │     ┌────────┼────────┬─────────┐          │
   │     ▼        ▼        ▼         ▼          │
   │  user PCs  user PCs  servers  resources    │
   │  (all domain-joined, centrally managed)    │
   └───────────────────────────────────────────┘

Part 3: The Concept — Why AD Is an Attacker’s Grand Prize

Active Directory’s great strength — central management of an entire organization — is exactly what makes it such a high-value target. Several properties make it attractive to attackers:

The result: AD turns Phase 3’s single-machine skills into a network-wide campaign.

Part 4: The Concept — The Shape of an AD Attack

You don’t need the deep specifics yet, but you should understand the shape — the general pattern of how attackers progress through an Active Directory environment, because it ties together everything in Phase 3:

text
   1. FOOTHOLD          — compromise one domain machine, often
            │             via a service (3.2) or exploit (3.3) —
            │             frequently a regular user's PC
            ▼
   2. AD ENUMERATION    — from inside the domain, map it:
            │             users, computers, groups, who is
            │             privileged, how things are configured.
            │             AD is designed for members to query it,
            │             so an attacker inside can learn a LOT.
            ▼
   3. CREDENTIAL ACCESS — gather credentials / authentication
            │             material from compromised machines
            │             (links straight to 3.4's stored creds)
            ▼
   4. LATERAL MOVEMENT  — use those credentials to access OTHER
            │             machines; repeat: enumerate, gather
            │             more credentials, move again
            ▼
   5. PRIVILEGE ESCALATION — within the domain, work toward
            │             highly privileged accounts (a domain
            │             admin), abusing misconfigurations and
            │             trust relationships
            ▼
   6. DOMAIN COMPROMISE — gain control of the Domain Controller /
                          domain administration → the whole
                          organization is compromised

Notice how this is Phase 3, assembled: scanning and service attacks (3.1, 3.2) and exploitation (3.3) get the foothold; the enumeration mindset (3.4) maps the domain; privilege escalation (3.4) operates now at domain scale; and the whole thing is one long chain (the 2.11 lesson) — each compromised machine yielding credentials and position for the next. AD attacks are the capstone where every Phase 3 skill combines.

A central concept worth naming: lateral movement — moving from one compromised machine to another across the network. It’s the defining activity of an AD attack, and (Part 6) a primary thing defenders try to detect and contain.

Part 5: How AD Security Is Assessed

Active Directory assessment — a core part of internal penetration testing and red teaming — uses the pattern above, with a few defining characteristics:

The dedicated practice environment for this is important: AD attacks need a domain to practice on, which is more than the single victim VM of earlier pages. Hosted lab platforms (set up back in 0.5) provide ready-made vulnerable Active Directory environments designed exactly for learning these attacks safely and legally — the right place to get hands-on AD experience without building a whole domain yourself.

⚖️ AD attacks are powerful and far-reaching — lateral movement and domain compromise affect many systems and users at once. They are strictly for your own lab, hosted practice AD environments, or explicitly authorized and scoped engagements. The blast radius makes the 1.0 discipline more important here, not less.

Part 6: The Defense — A Preview of Phase 4

The offense/defense mirror. AD defense is a large discipline; the defensive principles from across Phase 4 (hardening 4.4, monitoring/detection 4.6, secure design 4.3, incident response 4.7) all apply directly. The shape:

🔑 The deep lesson: Active Directory shows, at full organizational scale, every theme of Phase 3 at once — attack surface, misconfiguration, abused trust, stored credentials, privilege escalation, and chaining. Its defense is correspondingly every Phase 4 theme at once: hardening, least privilege, segmentation, monitoring, patching, and assume-breach design. AD is where offense and defense both become organization-wide — which is exactly why it’s the final attacking page before Phase 4 turns the whole curriculum toward defense.

📓 Key Terms

Term Plain meaning
Active Directory (AD)Microsoft’s directory service — central identity and access management for Windows networks.
DomainA collection of users, computers, and resources managed together under one directory.
Domain Controller (DC)The server running Active Directory — the most critical machine in the domain.
GroupAn AD object bundling users together for assigning permissions.
Domain adminA highly privileged account with control over the domain.
AD enumerationMapping a domain’s users, computers, groups, and relationships from inside.
Lateral movementMoving from one compromised machine to others across a network.
Domain compromiseGaining control of the domain (typically via the Domain Controller).
Assumed breachTesting that starts from a foothold already inside the network.

🧪 Hands-On Lab

Practice AD attacks only on hosted practice AD environments built for it, your own lab, or explicitly authorized and scoped engagements. The wide blast radius of AD attacks makes authorization discipline critical.

Task 1 — Build the concept. Before any hands-on work, make sure Part 2 is solid. In your own words in Notion, explain: what a domain is, what a Domain Controller does, why the DC is the crown jewel, and what “domain compromise” means.

Task 2 — Get into a practice AD environment. Use a hosted lab platform (from your 0.5 setup) that offers beginner-friendly, deliberately vulnerable Active Directory environments. Choose a guided introductory AD path.

Task 3 — Enumerate a domain. From a starting foothold in the practice environment, perform AD enumeration: map users, computers, groups, and which accounts are privileged. Experience how much an attacker inside a domain can learn.

Task 4 — Visualize attack paths. Use an AD attack-path mapping/visualization tool against the practice environment. See it render the graph of routes from a low-privileged account toward a domain admin. Study how a path is built from individual misconfigurations.

Task 5 — Follow a guided attack chain. Work through a guided AD attack scenario end to end: foothold → enumeration → credential access → lateral movement → escalation → domain compromise. Focus on the shape (Part 4), not memorizing specifics.

Task 6 — Map it back to Phase 3. In Notion, annotate the chain you just followed: mark which step used scanning (3.1), which used service attacks (3.2) or exploitation (3.3), which used the enumeration mindset and escalation (3.4). See AD as Phase 3 assembled.

Task 7 — Write the defenses. For each step of the attack chain, write the corresponding Part 6 defense. Pay special attention to where least privilege and segmentation would have broken the chain. Add to your hardening checklist — this is a major input to Phase 4.

⚠️ Common Mistakes

✅ Recap & What’s Next

Next (3.6): Before Phase 3 closes, two more attack surfaces deserve awareness — wireless networks and the wider world of connected devices. Page 3.6 covers Wi-Fi and other attack surfaces at a conceptual level.

⁂ Back to all modules