Active Directory Fundamentals and Attacks
CAP, ACID vs BASE, latency numbers, back-of-envelope estimation, single points of failure — the vocabulary every system designer thinks in.
Core Philosophy: Most organizations don’t run their computers as a loose collection of independent machines. They run them as a managed, interconnected whole — and on Windows networks, the system that does this is Active Directory. It is the backbone of the corporate world. For an attacker, it is the grand prize: compromise Active Directory and you don’t own a machine, you own the organization. For a defender, it is the thing that most needs protecting.
Part 1: The Problem
So far in Phase 3 you’ve thought one machine at a time — scan a host, attack a service, get a foothold, escalate on that box. But real organizations have hundreds or thousands of machines and users, and they need to manage them centrally: one identity per employee, consistent policies, shared resources, unified administration.
On Windows networks — which is most corporate environments — the system providing all of this is Active Directory (AD). Because AD centralizes identity and access for the whole organization, it is also a centralized target. An attacker who fully compromises AD effectively controls every machine, every account, and every resource it governs. This is why nearly every internal penetration test and every red team engagement revolves around Active Directory — and why understanding it, at least at a foundational level, is essential.
This page is a foundational introduction — AD attacks are deep enough to be a specialization of their own. The goal here is genuine conceptual understanding plus guided practical exposure, so you grasp how single-machine compromise becomes whole-network compromise. Phase 5 and beyond is where AD can be taken to real depth.
Part 2: The Concept — What Active Directory Is
Active Directory is Microsoft’s directory service: a central system that stores and manages identities (users, computers, groups) and controls authentication and authorization across a Windows network.
Think of it as the organization’s central identity authority. The core ideas:
- Domain — the central unit: a collection of users, computers, and resources managed together under one directory. When an employee logs into their work computer, they’re authenticating against the domain, not just that one machine.
- Domain Controller (DC) — the server (or servers) that runs Active Directory. The DC holds the directory and handles authentication for the whole domain. The Domain Controller is the single most critical machine in the environment — compromising it generally means compromising the entire domain.
- Users, computers, and groups — AD stores every user account, every domain-joined computer, and groups that bundle users together for assigning permissions. Some groups are highly privileged — membership in a top administrative group is, effectively, control of the domain.
- Authentication — AD has its own authentication system so a user can log in once and access resources across the domain. (The underlying protocols have their own names and their own history of attackable weaknesses — depth for later study.)
- Policies — AD pushes configuration and security settings to machines centrally and consistently.
THE DOMAIN (managed as one whole)
┌───────────────────────────────────────────┐
│ ┌──────────────────────┐ │
│ │ DOMAIN CONTROLLER │ ← runs AD; │
│ │ (runs Active Dir.) │ the crown │
│ └──────────┬───────────┘ jewel │
│ │ authenticates & manages │
│ ┌────────┼────────┬─────────┐ │
│ ▼ ▼ ▼ ▼ │
│ user PCs user PCs servers resources │
│ (all domain-joined, centrally managed) │
└───────────────────────────────────────────┘
Part 3: The Concept — Why AD Is an Attacker’s Grand Prize
Active Directory’s great strength — central management of an entire organization — is exactly what makes it such a high-value target. Several properties make it attractive to attackers:
- It’s a single point of total control. Fully compromise AD (specifically, the Domain Controller / top-level domain administration) and you control everything the domain governs — every machine, every account, all the data.
- It’s built on trust relationships. AD works by machines and users trusting the domain and each other. Attackers abuse these trust relationships — a recurring theme you’ve now seen at every level (request forgery in 2.8, service trust in SSRF, and now domain trust).
- It’s complex. AD is large and intricate, with many features, settings, and relationships. Complexity breeds misconfiguration (the 2.9 lesson), and complex systems are hard to fully secure. Real AD environments accumulate misconfigurations over years.
- Credentials are everywhere. AD environments involve credentials and authentication material spread across many machines. An attacker who compromises one machine often finds credentials there that are useful elsewhere (directly connecting to 3.4’s “stored credentials” path).
- Lateral movement is the natural mode. Because everything is interconnected, an attacker who compromises one machine can often move sideways to others, gathering credentials and access, working steadily toward the Domain Controller.
The result: AD turns Phase 3’s single-machine skills into a network-wide campaign.
Part 4: The Concept — The Shape of an AD Attack
You don’t need the deep specifics yet, but you should understand the shape — the general pattern of how attackers progress through an Active Directory environment, because it ties together everything in Phase 3:
1. FOOTHOLD — compromise one domain machine, often
│ via a service (3.2) or exploit (3.3) —
│ frequently a regular user's PC
▼
2. AD ENUMERATION — from inside the domain, map it:
│ users, computers, groups, who is
│ privileged, how things are configured.
│ AD is designed for members to query it,
│ so an attacker inside can learn a LOT.
▼
3. CREDENTIAL ACCESS — gather credentials / authentication
│ material from compromised machines
│ (links straight to 3.4's stored creds)
▼
4. LATERAL MOVEMENT — use those credentials to access OTHER
│ machines; repeat: enumerate, gather
│ more credentials, move again
▼
5. PRIVILEGE ESCALATION — within the domain, work toward
│ highly privileged accounts (a domain
│ admin), abusing misconfigurations and
│ trust relationships
▼
6. DOMAIN COMPROMISE — gain control of the Domain Controller /
domain administration → the whole
organization is compromised
Notice how this is Phase 3, assembled: scanning and service attacks (3.1, 3.2) and exploitation (3.3) get the foothold; the enumeration mindset (3.4) maps the domain; privilege escalation (3.4) operates now at domain scale; and the whole thing is one long chain (the 2.11 lesson) — each compromised machine yielding credentials and position for the next. AD attacks are the capstone where every Phase 3 skill combines.
A central concept worth naming: lateral movement — moving from one compromised machine to another across the network. It’s the defining activity of an AD attack, and (Part 6) a primary thing defenders try to detect and contain.
Part 5: How AD Security Is Assessed
Active Directory assessment — a core part of internal penetration testing and red teaming — uses the pattern above, with a few defining characteristics:
- It starts from inside. Unlike Phase 2’s external web testing, AD assessment typically assumes the attacker already has some access inside the network (a foothold, or “assumed breach” — given a low-privileged domain account to start). The question being tested is: from a foothold, how far can an attacker get?
- Enumeration is central. As always (3.4), thorough enumeration drives everything. AD is designed to be queryable by its members, so an attacker or tester inside the domain can map users, computers, groups, privileges, and relationships in detail. Specialized tools exist that map AD environments and even visualize attack paths — graphically showing the route from a low-privileged account to a domain admin.
- It hunts for misconfigurations and weak trust. Real AD environments accumulate misconfigured permissions, over-privileged accounts, weak configurations, and exploitable trust relationships over years. The assessment finds the paths these create.
- It demonstrates the chain. The deliverable is showing the organization the realistic path from foothold to domain compromise — so they can break that chain. (This is the 2.11 reporting and chaining lesson, at domain scale.)
The dedicated practice environment for this is important: AD attacks need a domain to practice on, which is more than the single victim VM of earlier pages. Hosted lab platforms (set up back in 0.5) provide ready-made vulnerable Active Directory environments designed exactly for learning these attacks safely and legally — the right place to get hands-on AD experience without building a whole domain yourself.
⚖️ AD attacks are powerful and far-reaching — lateral movement and domain compromise affect many systems and users at once. They are strictly for your own lab, hosted practice AD environments, or explicitly authorized and scoped engagements. The blast radius makes the 1.0 discipline more important here, not less.
Part 6: The Defense — A Preview of Phase 4
The offense/defense mirror. AD defense is a large discipline; the defensive principles from across Phase 4 (hardening 4.4, monitoring/detection 4.6, secure design 4.3, incident response 4.7) all apply directly. The shape:
- Protect the Domain Controller above all. It’s the crown jewel; it gets the strictest hardening, the tightest access, and the closest monitoring.
- Least privilege, at domain scale. The master defense from 3.4, applied across the whole organization: minimize the number of privileged accounts; don’t give accounts more domain rights than they need; separate administrative accounts from everyday accounts. Most AD attack paths exist because too many accounts have too much privilege.
- Limit lateral movement. Network segmentation (4.3, 4.4) so a foothold on one machine can’t freely reach every other; configurations that stop credentials from being reusable across the whole environment. Make the attacker’s sideways step hard.
- Credential hygiene. Reduce credentials left exposed on machines (the 3.4 stored-credentials path); protect authentication material; strong password policies (the 2.6 lesson) across the domain.
- Fix misconfigurations and weak trust. Regularly audit AD for the misconfigured permissions, over-privileged accounts, and weak trust relationships that create attack paths — using the same attack-path-mapping tools attackers use, turned inward (the recurring offense/defense-mirror move).
- Monitor for AD attack activity. Enumeration, lateral movement, and credential attacks generate signals; detecting them (4.6) is how a defender catches an attacker moving through the domain before they reach the DC.
- Patch. Domain Controllers and domain machines kept current (the 3.3 / 2.10 lesson).
- Assume breach and plan response. Assume an attacker will get a foothold (1.1); design the domain so a foothold doesn’t easily become domain compromise, and have an incident-response plan for when it happens (4.7).
🔑 The deep lesson: Active Directory shows, at full organizational scale, every theme of Phase 3 at once — attack surface, misconfiguration, abused trust, stored credentials, privilege escalation, and chaining. Its defense is correspondingly every Phase 4 theme at once: hardening, least privilege, segmentation, monitoring, patching, and assume-breach design. AD is where offense and defense both become organization-wide — which is exactly why it’s the final attacking page before Phase 4 turns the whole curriculum toward defense.
📓 Key Terms
| Term | Plain meaning |
|---|---|
| Active Directory (AD) | Microsoft’s directory service — central identity and access management for Windows networks. |
| Domain | A collection of users, computers, and resources managed together under one directory. |
| Domain Controller (DC) | The server running Active Directory — the most critical machine in the domain. |
| Group | An AD object bundling users together for assigning permissions. |
| Domain admin | A highly privileged account with control over the domain. |
| AD enumeration | Mapping a domain’s users, computers, groups, and relationships from inside. |
| Lateral movement | Moving from one compromised machine to others across a network. |
| Domain compromise | Gaining control of the domain (typically via the Domain Controller). |
| Assumed breach | Testing that starts from a foothold already inside the network. |
🧪 Hands-On Lab
Practice AD attacks only on hosted practice AD environments built for it, your own lab, or explicitly authorized and scoped engagements. The wide blast radius of AD attacks makes authorization discipline critical.
Task 1 — Build the concept. Before any hands-on work, make sure Part 2 is solid. In your own words in Notion, explain: what a domain is, what a Domain Controller does, why the DC is the crown jewel, and what “domain compromise” means.
Task 2 — Get into a practice AD environment. Use a hosted lab platform (from your 0.5 setup) that offers beginner-friendly, deliberately vulnerable Active Directory environments. Choose a guided introductory AD path.
Task 3 — Enumerate a domain. From a starting foothold in the practice environment, perform AD enumeration: map users, computers, groups, and which accounts are privileged. Experience how much an attacker inside a domain can learn.
Task 4 — Visualize attack paths. Use an AD attack-path mapping/visualization tool against the practice environment. See it render the graph of routes from a low-privileged account toward a domain admin. Study how a path is built from individual misconfigurations.
Task 5 — Follow a guided attack chain. Work through a guided AD attack scenario end to end: foothold → enumeration → credential access → lateral movement → escalation → domain compromise. Focus on the shape (Part 4), not memorizing specifics.
Task 6 — Map it back to Phase 3. In Notion, annotate the chain you just followed: mark which step used scanning (3.1), which used service attacks (3.2) or exploitation (3.3), which used the enumeration mindset and escalation (3.4). See AD as Phase 3 assembled.
Task 7 — Write the defenses. For each step of the attack chain, write the corresponding Part 6 defense. Pay special attention to where least privilege and segmentation would have broken the chain. Add to your hardening checklist — this is a major input to Phase 4.
⚠️ Common Mistakes
- Skipping the fundamentals for the attacks. AD attacks make no sense without understanding domains, the DC, groups, and trust. Build Part 2 solidly before touching Task 2.
- Practicing AD attacks outside proper environments. The blast radius is huge — many machines and users. Hosted practice AD environments, your own lab, or explicitly authorized engagements only.
- Treating AD as separate from Phase 3. It isn’t — it’s Phase 3 assembled: scanning, service attacks, exploitation, enumeration, escalation, and chaining, at organizational scale. See the connections.
- Underestimating enumeration (again). As everywhere in Phase 3, thorough enumeration drives AD attacks. AD is highly queryable from inside — and defenders must enumerate their own AD just as carefully.
- Expecting full mastery from this one page. AD security is a deep specialization. This page builds genuine foundations and guided exposure; real depth is later study (Phase 5+).
- Forgetting the DC is the prize. Everything converges on the Domain Controller. Attackers aim for it; defenders protect it hardest.
✅ Recap & What’s Next
- Active Directory centrally manages identity and access for Windows networks; the Domain Controller runs it and is the crown jewel — compromising AD means compromising the whole organization.
- AD attacks follow a shape — foothold → AD enumeration → credential access → lateral movement → privilege escalation → domain compromise — which is all of Phase 3 assembled into one organization-wide chain.
- Defense (Phase 4) is every defensive theme at once — protect the DC, least privilege and segmentation to break attack chains, credential hygiene, fixing misconfigurations, monitoring, patching, and assume-breach design.
Next (3.6): Before Phase 3 closes, two more attack surfaces deserve awareness — wireless networks and the wider world of connected devices. Page 3.6 covers Wi-Fi and other attack surfaces at a conceptual level.
⁂ Back to all modules