Skip to content
O.J. edited this page Apr 12, 2026 · 3 revisions

Welcome to the AD-Lab-Research wiki!

AD-Lab-Research Wiki

Controlled offensive security research in enterprise-modeled Active Directory environments.
Focus: attack path realism, defensive telemetry, and control failure analysis — not tool tutorials.

All labs are independently reproducible from the setup guides and primary telemetry evidence documented in each writeup. All credentials, IPs, and environment-specific identifiers have been sanitized for public documentation.


Table of Contents

  1. Lab Architecture
  2. Research Methodology
  3. Infrastructure Setup
  4. ADCS Exploitation (ESC Series)
  5. Kerberos Attack Chains
  6. DACL / ACL Attacks
  7. Credential Attacks
  8. Lateral Movement & Detection Gaps
  9. Network-Layer Attacks
  10. Windows Defense Evasion
  11. Detection Engineering
  12. AD Hardening
  13. Files Reference

Lab Architecture

Two isolated AD environments built on VMware Workstation Pro (Ubuntu host, LUKS FDE):

lab2019.local

Host Role IP
DC01 Domain Controller – Server 2019 192.168.1.x
WIN-ATTACK Attacker workstation – Server 2022 192.168.1.x
ELK Stack Elasticsearch + Kibana log aggregation 192.168.1.250
Kali Linux attack platform 192.168.1.218

badsuccessor.local

Host Role
WIN-G4OJKPN3TOV Domain Controller – Server 2025
WIN-ATTACK Attacker workstation – Server 2022

Telemetry stack: Winlogbeat → Elasticsearch → Kibana 8.x
Sysmon config: SwiftOnSecurity base + custom NetworkConnect rule (must be ASCII-encoded; UTF-8/BOM causes silent rule rejection)


Research Methodology

All research follows a three-phase loop:

  1. Offensive execution — reproduce a realistic attack chain from an authenticated low-privilege starting position
  2. Telemetry capture — record exact Event IDs, field values, and timing from Sysmon + Windows Security logs
  3. Detection gap analysis — identify what fired, what didn't, and why default configurations miss the technique

The key question driving every lab: "Would a defender actually see this?"


Infrastructure Setup

Lab Setup — AD Environment

ad-lab-setup.md — Full AD domain provisioning for lab2019.local and badsuccessor.local. Covers VM networking, domain join, GPO baseline, and user/group seeding for attack chain reproduction.

AD + ADCS Setup Guide

AD_ADCS_Setup_Guide.md — Domain Controller + Certificate Authority provisioning. Required before running any ESC lab.

ELK Lab Full Setup

elk-lab-full-setup.md — End-to-end ELK stack deployment: Elasticsearch, Kibana, and Winlogbeat agent configuration. Covers index patterns, ILM, and Sysmon field mappings.

ELK Setup Guide

elk-setup-guide.md — Condensed ELK deployment reference for re-provisioning or new lab boxes.

Sysmon Setup Guide

Sysmon_Setup_Guide.md — Sysmon deployment, SwiftOnSecurity base config, and the custom NetworkConnect rule. Critical: config XML must be ASCII-encoded.


ADCS Exploitation (ESC Series)

Reference for all ESC classes: adcs-esc-reference-guide.md
Full attack path documentation (sanitized): adcs-attack-paths-sanitized.md

ESC1 — Enrollee-Supplied SAN

ESC1_Lab_Setup.md

Template allows the requester to specify a Subject Alternative Name. A low-privileged user can request a certificate for any UPN (Administrator@domain), authenticate via PKINIT, and obtain a Domain Admin TGT.

Detection: EID 4886/4887 (certificate issued with custom SAN), EID 4768 PreAuthType 16 (PKINIT TGT)

ESC3 — Certificate Request Agent

ESC3_Attack_Chain.md

Two-template abuse: a low-privileged user holds enroll rights on a Certificate Request Agent template and uses it to request a certificate on behalf of a privileged user, then enrolls in a second template using that agent certificate. Results in impersonation of any domain account.

ESC4 — Template ACL Write (Dual-EKU Gotcha)

esc4-dual-eku-gotcha.md

Write permission on a certificate template allows modification of EKU values to enable client authentication. Lab finding: templates carrying dual EKUs require both to be correctly modified — partial modification produces a syntactically valid but functionally broken template that certutil rejects at enrollment time even after the ACL exploit succeeds.

ESC8 — NTLM Relay to AD CS HTTP Endpoint

ESC8_Lab_Setup.md, esc8-ntlm-relay.md

Web enrollment (/certsrv/) does not enforce HTTPS + Extended Protection for Authentication by default. Incoming NTLM authentication (coerced via PetitPotam/DFSCoerce) is relayed to the CA to obtain a certificate on behalf of a privileged account.

Full chain validated:

ARP spoof → mitm6 CNAME DNS poison → krbrelayx → ADCS ESC8
→ PKINIT → U2U → ESC1 → Domain Admin

Key finding: EPA/CBT protection is only effective over TLS. HTTPS + EPA=Require blocks the relay via Channel Binding Token enforcement. HTTP enrollment endpoints remain exploitable regardless of CBT configuration.

Detection: EID 4624 logon from unexpected IPv6 fe80:: source, EID 4768 PreAuthType 16

EPA/CBT Validation Lab

epa_kerberos_relay_lab.md, https-epa-validation-findings.md

Controlled validation of the EPA/CBT mitigation claim. Confirms that EPA=Require on the IIS web enrollment endpoint enforces CBT only when the session is wrapped in TLS. HTTP-based relay bypasses CBT entirely. Credit: Ben Zamir (Microsoft) for the original clarification.

ADCSync — DCSync via ADCS

ADCSYNC_README.md, ADCSync_Writeup.md, adcsync-homelab-analysis.md, adcsync_fixed26.py

Documents the ADCSync technique: obtaining replication privileges via ADCS certificate issuance, distinct from the traditional DCSync path through explicit DS-Replication-Get-Changes rights. Includes a fixed Python implementation (adcsync_fixed26.py) compatible with Python 3.6+.


Kerberos Attack Chains

kerberos-attack-chains-sanitized.md

Sanitized documentation of the full Kerberos attack surface validated in lab:

Technique Prerequisite Outcome
AS-REP Roasting Pre-auth disabled on account Offline hash crack
Kerberoasting SPN set on account Offline TGS crack
Unconstrained Delegation TRUSTED_FOR_DELEGATION flag TGT harvesting from any authenticating account
Constrained Delegation msDS-AllowedToDelegateTo Impersonate any user to target service
RBCD Write msDS-AllowedToActOnBehalfOfOtherIdentity S4U2Proxy → Domain Admin impersonation
S4U2Self / S4U2Proxy Service account Cross-service impersonation without password
Golden Ticket krbtgt NTLM hash Persistent domain-wide authentication
Silver Ticket Service account NTLM hash Forge TGS for specific service
Pass-the-Ticket Harvested TGT/TGS Lateral movement
PKINIT / U2U Certificate with Client Auth EKU Certificate → TGT → impersonation

Kerberos CNAME Relay (CVE-2026-20929)

kerberos-cname-relay-lab.md, kerberos-cname-relay-epa-bypass-detection.md

Novel attack chain using mitm6 CNAME DNS poisoning to redirect Kerberos authentication to an attacker-controlled relay, bypassing NTLM relay mitigations by operating at the Kerberos layer.

Tools: mitm6-cname (/MITM6-Kerberos-CNAME-Abuse/), krbrelayx (/krbrelayx/), PKINITtools (~/PKINITtools/)

Detection: EID 4624 logon originating from IPv6 link-local (fe80::) where IPv6 is not operationally expected, EID 4768 PreAuthType 16


DACL / ACL Attacks

Shadow Credentials — Offense

SHADOW CREDS OFFENSE ONLY

Offensive coverage of the Shadow Credentials technique: writing a msDS-KeyCredentialLink value to a target object (requires GenericWrite or WriteProperty on the attribute) to add an attacker-controlled certificate, then authenticating as the target via PKINIT without knowing their password.

Shadow Credentials — DACL Detection

shadow-credentials-dacl-detection.md, dacl-shadow-creds-writeup.md

Detection coverage for Shadow Credentials abuse: EID 4662 (msDS-KeyCredentialLink write) correlated with subsequent PKINIT authentication. Documents the detection gap where EID 4662 only fires when object-level auditing is explicitly enabled — not a default configuration in most AD deployments.

DACL AddMember Attack Path

dacl_addmembers_attack_path.md

AddMember / WriteMember DACL privilege escalation: GenericAll, GenericWrite, or explicit Self-Membership on a group allows adding arbitrary accounts. Covers the full path from DACL enumeration (BloodHound) through group membership manipulation to privilege escalation.

DACL Blue Team Lab

dacl_blueteam_lab.md

Defensive counterpart: SACL-based auditing on high-value groups, validating that EID 4728/4732/4756 (member added to security group) fires correctly, and testing detection fidelity against AddMember exploitation.

NoPAC (CVE-2021-42278/42287)

nopac_attack_chain.md

Full NoPAC chain: combining the sAMAccountName spoofing vulnerability (42278) with the Kerberos PAC delegation flaw (42287) to impersonate a Domain Controller machine account and obtain a Domain Admin TGS. Validated on Server 2016 RTM with full blue team telemetry.

Live SPN Jacking (Linux Path)

live-spn-jacking-linux.md

SPN Jacking via Impacket. Key findings: GenericAll is required — WriteSPN alone is not sufficient for SPN modification. Impacket's SMB implementation has incomplete mutual auth handling against Server 2022 targets (STATUS_ACCESS_DENIED at session setup), making the Windows attack path necessary for those targets.

Bad Successor

bad-successor-lab-writeup-v3.md

Full writeup of the Bad Successor attack chain against Server 2025 (badsuccessor.local). Exploits successor delegation logic in newer AD builds via dNSHostName manipulation. Lab environment: WIN-G4OJKPN3TOV (DC, Server 2025) + WIN-ATTACK (Server 2022) + Kali.


Credential Attacks

Responder / LLMNR-NBT-NS Poisoning

responder_lab_writeup.md

Full LLMNR/NBT-NS poisoning lab: Responder capturing NTLMv2 hashes from unauthenticated broadcast traffic. Also covers ResponderGuard (CredDefense) as a honeypot detection mechanism — feeding fake credentials to Responder and detecting their downstream use.

Full telemetry chain documented: EID 8415, 4648, 4625, 4776


Lateral Movement & Detection Gaps

Admin Share Detection

admin-share-detection.md

Detection coverage for admin share access (\\target\C$, ADMIN$, IPC$). Maps EID 5140 (share access) and EID 5145 (share object access check) to lateral movement and exfiltration scenarios. Covers the nxc --no-output evasion pattern and its detection gap.

NXC WMIExec Detection Gap

nxc-wmiexec-detection-gap.md

Critical detection gap: Sysmon Binary Execution rules using CurrentDirectory as the detection field are blind to wmiexec and WinRM execution vectors, which change the working directory but not the binary's Image path. Fix: pivot the rule anchor to Image path. This was the core finding from Vector 2 of the lab series.

NXC WMIExec + KeePass Detection

nxc-wmiexec-keepass-detection.md

Detection chain for KeePass .kdbx exfiltration via smbclient over SMB C$ (Vector 3). Key finding: nxc --no-output suppresses console output but does not suppress Sysmon EID 3 (NetworkConnect) or EID 11 (FileCreate) telemetry. The SMB share access is fully visible in EID 5140/5145.

Scheduled Task Persistence Detection

scheduled-task-persistence-detection.md

Detection engineering for scheduled task persistence (Vector 1). Maps Sysmon EID 1 (Image path under \Tasks\) and EID 3 (outbound network from task binary) against attacker-created task artifacts. Covers schtasks CLI vs Task Scheduler COM API creation paths and their respective telemetry differences.


Network-Layer Attacks

ARP Spoof Lab

arp-spoof-lab.md

Layer 2 ARP cache poisoning as a prerequisite for NTLM relay and Kerberos CNAME relay chains. Validates traffic interception with arpspoof/bettercap and covers detection via ARP inspection and unexpected MAC-to-IP binding changes.


Windows Defense Evasion

AMSI Bypass Research

AMSI-Bypass-Research.md, amsi-bypass-research.md

Research into Antimalware Scan Interface bypass techniques. Covers in-memory amsiInitFailed flip, reflection-based bypasses, and obfuscation patterns.

Detection: EID 4104 (PowerShell script block logging capturing bypass attempts)

CLM Bypass — Purple Team

clm-bypass-purple-team.md

Constrained Language Mode bypass from a purple team perspective. Documents escape techniques (AppLocker/WDAC enforcement) and corresponding detection coverage. Covers __PSLockDownPolicy environment variable manipulation and unmanaged PowerShell host approaches.

Defender Reconciliation Loop

defender-reconciliation-loop.md

Undocumented Windows Defender behavior: MsMpEng.exe reconciles the SubmitSamplesConsent registry value within seconds of any external write, reverting it to the policy-enforced value regardless of whether Tamper Protection is enabled. Validated on Server 2019. Implication: registry-based Defender disablement attempts are silently reverted with no user-visible alert.

Windows Evasion Techniques

windows-evasion-techniques.md

Consolidated evasion findings: unsigned binary detection (zeroed IMPHASH as EID 1 signal), Base64 staged loader detection (JAB* PowerShell pattern), WebClient/WebDAV coercion surface assessment.

Key finding: PetitPotam and DFSCoerce fail against Windows 11 26200 (SMB signing enforced by default, EFS RPC deprecated). Windows 10 22H2 remains the realistic enterprise coercion target.


Detection Engineering

Validated Kibana / Sysmon Detection Rules

Rule Event ID Key Field Technique
Binary Execution from Windows Tasks EID 1 Image contains \Tasks\ Scheduled task persistence
WMI Remote Process Execution EID 1 ParentImage = WmiPrvSE.exe wmiexec lateral movement
Outbound Network from Task Binary EID 3 RuleName = Tasks C2 from task binary
Unsigned Binary (Zeroed IMPHASH) EID 1 Hashes IMPHASH = 000... Packed/obfuscated payloads
Base64 Payload in CommandLine EID 1 CommandLine matches JAB* PowerShell staged loaders
Shadow Credential Write EID 4662 Attribute = msDS-KeyCredentialLink Shadow Credentials
Member Added to Security Group EID 4728/4732/4756 MemberName AddMember DACL abuse
PKINIT Authentication EID 4768 PreAuthType = 16 Certificate-based TGT
Delegation Logon from IPv6 EID 4624 Source IP = fe80:: NTLM/Kerberos relay
Admin Share Access EID 5140 ShareName = C$ / ADMIN$ Lateral movement / exfil
LLMNR Response EID 8415 — Responder activity
AMSI Bypass Attempt EID 4104 Script content pattern AMSI patch / reflection

Critical Detection Gap — Field Anchor Error

The original Binary Execution from Windows Tasks rule used CurrentDirectory as the detection anchor. This made it blind to wmiexec and WinRM, which execute binaries from arbitrary working directories. Correcting to Image path closed the gap. Lesson: always validate detection rules against the exact execution context of the attack vector, not just the happy-path scenario.


AD Hardening

AD Hardening Reality Check

ad_hardening_reality_check.md

Control-failure analysis of common AD hardening recommendations versus operational detection reality. Covers: tiering model gaps, LAPS blind spots, GPO delegation misconfigurations, and the gap between checkbox compliance and effective security posture. Written from an adversarial validation perspective after executing the full attack chain corpus in this repository.


Files Reference

File Category
README.md Meta
ad-lab-setup.md Setup
AD_ADCS_Setup_Guide.md Setup
elk-lab-full-setup.md Setup
elk-setup-guide.md Setup
Sysmon_Setup_Guide.md Setup
ESC1_Lab_Setup.md ADCS
ESC3_Attack_Chain.md ADCS
ESC8_Lab_Setup.md ADCS
esc8-ntlm-relay.md ADCS
esc4-dual-eku-gotcha.md ADCS
adcs-esc-reference-guide.md ADCS
adcs-attack-paths-sanitized.md ADCS
epa_kerberos_relay_lab.md ADCS
https-epa-validation-findings.md ADCS
ADCSYNC_README.md ADCS
ADCSync_Writeup.md ADCS
adcsync-homelab-analysis.md ADCS
adcsync_fixed26.py ADCS
kerberos-attack-chains-sanitized.md Kerberos
kerberos-cname-relay-lab.md Kerberos
kerberos-cname-relay-epa-bypass-detection.md Kerberos
bad-successor-lab-writeup-v3.md DACL/ACL
SHADOW CREDS OFFENSE ONLY DACL/ACL
shadow-credentials-dacl-detection.md DACL/ACL
dacl-shadow-creds-writeup.md DACL/ACL
dacl_addmembers_attack_path.md DACL/ACL
dacl_blueteam_lab.md DACL/ACL
nopac_attack_chain.md DACL/ACL
live-spn-jacking-linux.md DACL/ACL
responder_lab_writeup.md Credentials
admin-share-detection.md Lateral Movement
nxc-wmiexec-detection-gap.md Lateral Movement
nxc-wmiexec-keepass-detection.md Lateral Movement
scheduled-task-persistence-detection.md Detection
arp-spoof-lab.md Network
AMSI-Bypass-Research.md Evasion
amsi-bypass-research.md Evasion
clm-bypass-purple-team.md Evasion
defender-reconciliation-loop.md Evasion
windows-evasion-techniques.md Evasion
ad_hardening_reality_check.md Hardening