#tag

Active Directory

10 matching posts.

All tags
PentestAug 21, 202618 min read

The Model Found the Vulnerability. The Tool Call Became the Incident.

A balanced operating model for AI-assisted pentesting: where models improve coverage and evidence work, where excessive agency turns a valid test into a destructive action, and how to keep cloud, shell, and Domain Admin authority outside the model.

#ai-security#pentest#methodology#access-control#active-directory
PentestJun 18, 202631 min read

Active Directory Hardening Is a Sequence, Not a Score

A scanner score cannot tell you whether a helpdesk account can still reach Domain Admin. This is the order I use to turn AD hardening signals into broken attack paths, tested controls, and recoverable identity infrastructure.

#active-directory#identity-security#attack-paths#methodology
PentestMar 12, 202621 min read

AD CS ESC4: The Template Nobody Owned

How an ordinary AD CS permission becomes Domain Admin — and why ESC4 is the cause every ESC1 write-up skips.

#active-directory#identity-security#privilege-escalation#attack-paths
PentestJan 16, 20267 min read

The Blast Radius Is One Number. Almost Nobody Has Measured It.

Part four of testing the ransomware playbook: lateral movement runs on your own administrative tooling, so detection is a signal-to-noise problem — and the number that actually decides the outcome is how many hosts accept the same credential.

#ransomware#active-directory#detection#access-control
PentestDec 12, 20257 min read

Affiliates Do Not Find Novel Paths. They Find Yours.

Part three of testing the ransomware playbook: privilege escalation inside the domain uses a small, stable set of paths — the same ones already written up on this site — and the affiliate picks by reliability, not by cleverness.

#ransomware#active-directory#privilege-escalation#attack-paths
PentestNov 21, 20257 min read

Enumeration Cannot Be Prevented. Ask Whether It Was Seen.

Part two of testing the ransomware playbook: the affiliate's first hour is the same directory collection you run, it cannot be blocked, and the engagement usually destroys the only question worth asking about it on day one.

#ransomware#detection#active-directory#methodology
PentestSep 11, 20257 min read

SMB Signing Is On. That Closed One Edge, Not the Graph.

Signing is a per-protocol control, and NTLM over HTTP cannot be signed at all. The useful question is never whether signing is enabled — it is which relay edges are still open.

#active-directory#identity-security#access-control#pentest
PentestJun 19, 20257 min read

BloodHound Path Triage: The Shortest Path Is Usually the One That Expires First

BloodHound draws every edge the same width, but a DACL lasts for years and a session lasts for minutes. Shortest-path queries are biased toward exactly the edges least likely to still be there when you walk them.

#active-directory#attack-paths#privilege-escalation#methodology
PentestApr 24, 20258 min read

Delegation Triage: You Were Taught the Rare One

Unconstrained delegation gets the diagrams. Resource-based constrained delegation is what you actually find — because it is not a checkbox anyone audits, it is a side effect of who can write to a computer object.

#active-directory#identity-security#privilege-escalation#attack-paths
PentestFeb 13, 20257 min read

Kerberoasting Triage: Most Service Tickets Are a Waste of Your Time

Requesting every SPN in the domain is easy. Knowing which twelve tickets are worth cracking — and which ones will burn a week of GPU time for nothing — is the actual skill.

#active-directory#identity-security#methodology#pentest