Active Directory & Windows
AD attacks, Kerberos, WinRM, and Windows post-exploitation.
Active Directory Attacks
ActiveActive Directory attack workflow: enumeration, Kerberoasting, AS-REP roasting, credential dumping, and lateral movement on authorized engagements.
BloodHound
ActiveMap Active Directory attack paths from SharpHound/SharpHound data collectors.
CrackMapExec
ActiveSwiss-army SMB/WinRM/LDAP/MSSQL tool for AD enumeration and credential testing.
Evil-WinRM
ActiveWinRM shell and file transfer for post-exploitation on Windows hosts.
Impacket
ActivePython toolkit for SMB, Kerberos, and Windows protocol attacks.
Kerbrute
ActiveFast Kerberos user enumeration and password spraying without LDAP.
ldapdomaindump
ActiveDump and HTML-report Active Directory LDAP data for offline review.
Mimikatz
ActiveWindows credential extraction and Kerberos manipulation (lab-only).
NetExec
ActiveModern CrackMapExec successor for AD protocol abuse and automation.
Rubeus
ActiveKerberos abuse toolkit for ticket requests, roasting, and delegation attacks.