Repository navigation
Home
Welcome to the AD-Lab-Research wiki!
Controlled offensive security research in enterprise-modeled Active Directory environments.
Focus: attack path realism, defensive telemetry, and control failure analysis — not tool tutorials.
All labs are independently reproducible from the setup guides and primary telemetry evidence documented in each writeup. All credentials, IPs, and environment-specific identifiers have been sanitized for public documentation.
- Lab Architecture
- Research Methodology
- Infrastructure Setup
- ADCS Exploitation (ESC Series)
- Kerberos Attack Chains
- DACL / ACL Attacks
- Credential Attacks
- Lateral Movement & Detection Gaps
- Network-Layer Attacks
- Windows Defense Evasion
- Detection Engineering
- AD Hardening
- Files Reference
Two isolated AD environments built on VMware Workstation Pro (Ubuntu host, LUKS FDE):
| Host | Role | IP |
|---|---|---|
| DC01 | Domain Controller – Server 2019 | 192.168.1.x |
| WIN-ATTACK | Attacker workstation – Server 2022 | 192.168.1.x |
| ELK Stack | Elasticsearch + Kibana log aggregation | 192.168.1.250 |
| Kali | Linux attack platform | 192.168.1.218 |
| Host | Role |
|---|---|
| WIN-G4OJKPN3TOV | Domain Controller – Server 2025 |
| WIN-ATTACK | Attacker workstation – Server 2022 |
Telemetry stack: Winlogbeat → Elasticsearch → Kibana 8.x
Sysmon config: SwiftOnSecurity base + custom NetworkConnect rule (must be ASCII-encoded; UTF-8/BOM causes silent rule rejection)
All research follows a three-phase loop:
- Offensive execution — reproduce a realistic attack chain from an authenticated low-privilege starting position
- Telemetry capture — record exact Event IDs, field values, and timing from Sysmon + Windows Security logs
- Detection gap analysis — identify what fired, what didn't, and why default configurations miss the technique
The key question driving every lab: "Would a defender actually see this?"
ad-lab-setup.md — Full AD domain provisioning for lab2019.local and badsuccessor.local. Covers VM networking, domain join, GPO baseline, and user/group seeding for attack chain reproduction.
AD_ADCS_Setup_Guide.md — Domain Controller + Certificate Authority provisioning. Required before running any ESC lab.
elk-lab-full-setup.md — End-to-end ELK stack deployment: Elasticsearch, Kibana, and Winlogbeat agent configuration. Covers index patterns, ILM, and Sysmon field mappings.
elk-setup-guide.md — Condensed ELK deployment reference for re-provisioning or new lab boxes.
Sysmon_Setup_Guide.md — Sysmon deployment, SwiftOnSecurity base config, and the custom NetworkConnect rule. Critical: config XML must be ASCII-encoded.
Reference for all ESC classes: adcs-esc-reference-guide.md
Full attack path documentation (sanitized): adcs-attack-paths-sanitized.md
ESC1_Lab_Setup.md
Template allows the requester to specify a Subject Alternative Name. A low-privileged user can request a certificate for any UPN (Administrator@domain), authenticate via PKINIT, and obtain a Domain Admin TGT.
Detection: EID 4886/4887 (certificate issued with custom SAN), EID 4768 PreAuthType 16 (PKINIT TGT)
ESC3_Attack_Chain.md
Two-template abuse: a low-privileged user holds enroll rights on a Certificate Request Agent template and uses it to request a certificate on behalf of a privileged user, then enrolls in a second template using that agent certificate. Results in impersonation of any domain account.
esc4-dual-eku-gotcha.md
Write permission on a certificate template allows modification of EKU values to enable client authentication. Lab finding: templates carrying dual EKUs require both to be correctly modified — partial modification produces a syntactically valid but functionally broken template that certutil rejects at enrollment time even after the ACL exploit succeeds.
ESC8_Lab_Setup.md, esc8-ntlm-relay.md
Web enrollment (/certsrv/) does not enforce HTTPS + Extended Protection for Authentication by default. Incoming NTLM authentication (coerced via PetitPotam/DFSCoerce) is relayed to the CA to obtain a certificate on behalf of a privileged account.
Full chain validated:
ARP spoof → mitm6 CNAME DNS poison → krbrelayx → ADCS ESC8
→ PKINIT → U2U → ESC1 → Domain Admin
Key finding: EPA/CBT protection is only effective over TLS. HTTPS + EPA=Require blocks the relay via Channel Binding Token enforcement. HTTP enrollment endpoints remain exploitable regardless of CBT configuration.
Detection: EID 4624 logon from unexpected IPv6 fe80:: source, EID 4768 PreAuthType 16
epa_kerberos_relay_lab.md, https-epa-validation-findings.md
Controlled validation of the EPA/CBT mitigation claim. Confirms that EPA=Require on the IIS web enrollment endpoint enforces CBT only when the session is wrapped in TLS. HTTP-based relay bypasses CBT entirely. Credit: Ben Zamir (Microsoft) for the original clarification.
ADCSYNC_README.md, ADCSync_Writeup.md, adcsync-homelab-analysis.md, adcsync_fixed26.py
Documents the ADCSync technique: obtaining replication privileges via ADCS certificate issuance, distinct from the traditional DCSync path through explicit DS-Replication-Get-Changes rights. Includes a fixed Python implementation (adcsync_fixed26.py) compatible with Python 3.6+.
kerberos-attack-chains-sanitized.md
Sanitized documentation of the full Kerberos attack surface validated in lab:
| Technique | Prerequisite | Outcome |
|---|---|---|
| AS-REP Roasting | Pre-auth disabled on account | Offline hash crack |
| Kerberoasting | SPN set on account | Offline TGS crack |
| Unconstrained Delegation |
TRUSTED_FOR_DELEGATION flag |
TGT harvesting from any authenticating account |
| Constrained Delegation | msDS-AllowedToDelegateTo |
Impersonate any user to target service |
| RBCD | Write msDS-AllowedToActOnBehalfOfOtherIdentity
|
S4U2Proxy → Domain Admin impersonation |
| S4U2Self / S4U2Proxy | Service account | Cross-service impersonation without password |
| Golden Ticket |
krbtgt NTLM hash |
Persistent domain-wide authentication |
| Silver Ticket | Service account NTLM hash | Forge TGS for specific service |
| Pass-the-Ticket | Harvested TGT/TGS | Lateral movement |
| PKINIT / U2U | Certificate with Client Auth EKU | Certificate → TGT → impersonation |
kerberos-cname-relay-lab.md, kerberos-cname-relay-epa-bypass-detection.md
Novel attack chain using mitm6 CNAME DNS poisoning to redirect Kerberos authentication to an attacker-controlled relay, bypassing NTLM relay mitigations by operating at the Kerberos layer.
Tools: mitm6-cname (/MITM6-Kerberos-CNAME-Abuse/), /krbrelayx/), krbrelayx (PKINITtools (~/PKINITtools/)
Detection: EID 4624 logon originating from IPv6 link-local (fe80::) where IPv6 is not operationally expected, EID 4768 PreAuthType 16
SHADOW CREDS OFFENSE ONLY
Offensive coverage of the Shadow Credentials technique: writing a msDS-KeyCredentialLink value to a target object (requires GenericWrite or WriteProperty on the attribute) to add an attacker-controlled certificate, then authenticating as the target via PKINIT without knowing their password.
shadow-credentials-dacl-detection.md, dacl-shadow-creds-writeup.md
Detection coverage for Shadow Credentials abuse: EID 4662 (msDS-KeyCredentialLink write) correlated with subsequent PKINIT authentication. Documents the detection gap where EID 4662 only fires when object-level auditing is explicitly enabled — not a default configuration in most AD deployments.
dacl_addmembers_attack_path.md
AddMember / WriteMember DACL privilege escalation: GenericAll, GenericWrite, or explicit Self-Membership on a group allows adding arbitrary accounts. Covers the full path from DACL enumeration (BloodHound) through group membership manipulation to privilege escalation.
dacl_blueteam_lab.md
Defensive counterpart: SACL-based auditing on high-value groups, validating that EID 4728/4732/4756 (member added to security group) fires correctly, and testing detection fidelity against AddMember exploitation.
nopac_attack_chain.md
Full NoPAC chain: combining the sAMAccountName spoofing vulnerability (42278) with the Kerberos PAC delegation flaw (42287) to impersonate a Domain Controller machine account and obtain a Domain Admin TGS. Validated on Server 2016 RTM with full blue team telemetry.
live-spn-jacking-linux.md
SPN Jacking via Impacket. Key findings: GenericAll is required — WriteSPN alone is not sufficient for SPN modification. Impacket's SMB implementation has incomplete mutual auth handling against Server 2022 targets (STATUS_ACCESS_DENIED at session setup), making the Windows attack path necessary for those targets.
bad-successor-lab-writeup-v3.md
Full writeup of the Bad Successor attack chain against Server 2025 (badsuccessor.local). Exploits successor delegation logic in newer AD builds via dNSHostName manipulation. Lab environment: WIN-G4OJKPN3TOV (DC, Server 2025) + WIN-ATTACK (Server 2022) + Kali.
responder_lab_writeup.md
Full LLMNR/NBT-NS poisoning lab: Responder capturing NTLMv2 hashes from unauthenticated broadcast traffic. Also covers ResponderGuard (CredDefense) as a honeypot detection mechanism — feeding fake credentials to Responder and detecting their downstream use.
Full telemetry chain documented: EID 8415, 4648, 4625, 4776
admin-share-detection.md
Detection coverage for admin share access (\\target\C$, ADMIN$, IPC$). Maps EID 5140 (share access) and EID 5145 (share object access check) to lateral movement and exfiltration scenarios. Covers the nxc --no-output evasion pattern and its detection gap.
nxc-wmiexec-detection-gap.md
Critical detection gap: Sysmon Binary Execution rules using CurrentDirectory as the detection field are blind to wmiexec and WinRM execution vectors, which change the working directory but not the binary's Image path. Fix: pivot the rule anchor to Image path. This was the core finding from Vector 2 of the lab series.
nxc-wmiexec-keepass-detection.md
Detection chain for KeePass .kdbx exfiltration via smbclient over SMB C$ (Vector 3). Key finding: nxc --no-output suppresses console output but does not suppress Sysmon EID 3 (NetworkConnect) or EID 11 (FileCreate) telemetry. The SMB share access is fully visible in EID 5140/5145.
scheduled-task-persistence-detection.md
Detection engineering for scheduled task persistence (Vector 1). Maps Sysmon EID 1 (Image path under \Tasks\) and EID 3 (outbound network from task binary) against attacker-created task artifacts. Covers schtasks CLI vs Task Scheduler COM API creation paths and their respective telemetry differences.
arp-spoof-lab.md
Layer 2 ARP cache poisoning as a prerequisite for NTLM relay and Kerberos CNAME relay chains. Validates traffic interception with arpspoof/bettercap and covers detection via ARP inspection and unexpected MAC-to-IP binding changes.
AMSI-Bypass-Research.md, amsi-bypass-research.md
Research into Antimalware Scan Interface bypass techniques. Covers in-memory amsiInitFailed flip, reflection-based bypasses, and obfuscation patterns.
Detection: EID 4104 (PowerShell script block logging capturing bypass attempts)
clm-bypass-purple-team.md
Constrained Language Mode bypass from a purple team perspective. Documents escape techniques (AppLocker/WDAC enforcement) and corresponding detection coverage. Covers __PSLockDownPolicy environment variable manipulation and unmanaged PowerShell host approaches.
defender-reconciliation-loop.md
Undocumented Windows Defender behavior: MsMpEng.exe reconciles the SubmitSamplesConsent registry value within seconds of any external write, reverting it to the policy-enforced value regardless of whether Tamper Protection is enabled. Validated on Server 2019. Implication: registry-based Defender disablement attempts are silently reverted with no user-visible alert.
windows-evasion-techniques.md
Consolidated evasion findings: unsigned binary detection (zeroed IMPHASH as EID 1 signal), Base64 staged loader detection (JAB* PowerShell pattern), WebClient/WebDAV coercion surface assessment.
Key finding: PetitPotam and DFSCoerce fail against Windows 11 26200 (SMB signing enforced by default, EFS RPC deprecated). Windows 10 22H2 remains the realistic enterprise coercion target.
| Rule | Event ID | Key Field | Technique |
|---|---|---|---|
| Binary Execution from Windows Tasks | EID 1 |
Image contains \Tasks\
|
Scheduled task persistence |
| WMI Remote Process Execution | EID 1 |
ParentImage = WmiPrvSE.exe
|
wmiexec lateral movement |
| Outbound Network from Task Binary | EID 3 |
RuleName = Tasks
|
C2 from task binary |
| Unsigned Binary (Zeroed IMPHASH) | EID 1 |
Hashes IMPHASH = 000...
|
Packed/obfuscated payloads |
| Base64 Payload in CommandLine | EID 1 |
CommandLine matches JAB*
|
PowerShell staged loaders |
| Shadow Credential Write | EID 4662 | Attribute = msDS-KeyCredentialLink
|
Shadow Credentials |
| Member Added to Security Group | EID 4728/4732/4756 | MemberName |
AddMember DACL abuse |
| PKINIT Authentication | EID 4768 |
PreAuthType = 16 |
Certificate-based TGT |
| Delegation Logon from IPv6 | EID 4624 | Source IP = fe80::
|
NTLM/Kerberos relay |
| Admin Share Access | EID 5140 |
ShareName = C$ / ADMIN$
|
Lateral movement / exfil |
| LLMNR Response | EID 8415 | — | Responder activity |
| AMSI Bypass Attempt | EID 4104 | Script content pattern | AMSI patch / reflection |
The original Binary Execution from Windows Tasks rule used CurrentDirectory as the detection anchor. This made it blind to wmiexec and WinRM, which execute binaries from arbitrary working directories. Correcting to Image path closed the gap. Lesson: always validate detection rules against the exact execution context of the attack vector, not just the happy-path scenario.
ad_hardening_reality_check.md
Control-failure analysis of common AD hardening recommendations versus operational detection reality. Covers: tiering model gaps, LAPS blind spots, GPO delegation misconfigurations, and the gap between checkbox compliance and effective security posture. Written from an adversarial validation perspective after executing the full attack chain corpus in this repository.
| File | Category |
|---|---|
README.md |
Meta |
ad-lab-setup.md |
Setup |
AD_ADCS_Setup_Guide.md |
Setup |
elk-lab-full-setup.md |
Setup |
elk-setup-guide.md |
Setup |
Sysmon_Setup_Guide.md |
Setup |
ESC1_Lab_Setup.md |
ADCS |
ESC3_Attack_Chain.md |
ADCS |
ESC8_Lab_Setup.md |
ADCS |
esc8-ntlm-relay.md |
ADCS |
esc4-dual-eku-gotcha.md |
ADCS |
adcs-esc-reference-guide.md |
ADCS |
adcs-attack-paths-sanitized.md |
ADCS |
epa_kerberos_relay_lab.md |
ADCS |
https-epa-validation-findings.md |
ADCS |
ADCSYNC_README.md |
ADCS |
ADCSync_Writeup.md |
ADCS |
adcsync-homelab-analysis.md |
ADCS |
adcsync_fixed26.py |
ADCS |
kerberos-attack-chains-sanitized.md |
Kerberos |
kerberos-cname-relay-lab.md |
Kerberos |
kerberos-cname-relay-epa-bypass-detection.md |
Kerberos |
bad-successor-lab-writeup-v3.md |
DACL/ACL |
SHADOW CREDS OFFENSE ONLY |
DACL/ACL |
shadow-credentials-dacl-detection.md |
DACL/ACL |
dacl-shadow-creds-writeup.md |
DACL/ACL |
dacl_addmembers_attack_path.md |
DACL/ACL |
dacl_blueteam_lab.md |
DACL/ACL |
nopac_attack_chain.md |
DACL/ACL |
live-spn-jacking-linux.md |
DACL/ACL |
responder_lab_writeup.md |
Credentials |
admin-share-detection.md |
Lateral Movement |
nxc-wmiexec-detection-gap.md |
Lateral Movement |
nxc-wmiexec-keepass-detection.md |
Lateral Movement |
scheduled-task-persistence-detection.md |
Detection |
arp-spoof-lab.md |
Network |
AMSI-Bypass-Research.md |
Evasion |
amsi-bypass-research.md |
Evasion |
clm-bypass-purple-team.md |
Evasion |
defender-reconciliation-loop.md |
Evasion |
windows-evasion-techniques.md |
Evasion |
ad_hardening_reality_check.md |
Hardening |