KVKGB Vision Groupinkgbvisiongroup.hashnode.dev·3d ago · 3 min readActive Directory for Small Businesses: A Practical Starter GuideIn many small companies, every computer has its own local accounts, passwords are shared on sticky notes, and when an employee leaves, nobody is quite sure which systems they still have access to. Act00
MM1Hinm1h.hashnode.dev·4d ago · 11 min readActive Directory Compromise via ACL Chains & ESC4 Certificate Template AbuseObjective: 404 Bank, a staple of the local financial community, is conducting its annual security assessment. To uphold their motto of being "Proven, Local, Strong" the bank has commissioned the Hack 10
RARafid Ahmedinrafidths.hashnode.dev·6d ago · 2 min readHack The Box (HTB) - Hercules writeupHercules is an Insane-level Windows Active Directory lab machine focused on advanced AD abuse, Active Directory Certificate Services (AD CS) exploitation, and Kerberos delegation attacks. Rather than 00
MManishinkeirsalterego.hashnode.dev·Oct 1 · 2 min readKerberoasting for People Who Hate KerberosKerberos is the authentication protocol Active Directory runs on, and everyone who meets it goes through the same three stages: confusion, deeper confusion, and then a single clean moment where it mak00
AGAditya Gadhaveinthetechexplorerbyadityagadhave.hashnode.dev·Sep 30 · 6 min readDay 9: PowerShell for Active Directory AdministrationIntroduction : Managing Active Directory through graphical tools like Active Directory Users and Computers (ADUC) is suitable for everyday tasks. However, when administrators need to automate repetiti00
Aarosioninarosion-labs.hashnode.dev·Sep 23 · 11 min readBabyTwoBabyTwo is a medium-difficulty Windows machine set in an Active Directory environment. The initial foothold is gained through password guessing and the abuse of Windows logon scripts. Privilege escala00
AGAditya Gadhaveinthetechexplorerbyadityagadhave.hashnode.dev·Sep 19 · 5 min readDay 8: DNS in Active Directory (AD) – Complete GuideIntroduction DNS (Domain Name System) is one of the most important services in an Active Directory environment. Active Directory depends heavily on DNS to locate Domain Controllers, authenticate use00
MPMeet Patelinmeet-tech.hashnode.dev·Sep 17 · 9 min readDeploying Windows Server 2025 Active Directory Domain Services from ScratchA hands-on walkthrough of preparing Windows Server 2025, deploying a new Active Directory forest, configuring DNS and reverse DNS, and verifying the domain controller. I'm currently working on a larg00
VNVũ Nhật Lâminblog.fiscybersec.com·Sep 16 · 19 min readTerminalFix: Change One Dialog Box, and the Payload Jumps From an Infostealer to a Tunnel Into the NetworkSummary Classic ClickFix directs victims to the Windows Run dialog. TerminalFix directs them to Windows Terminal or PowerShell. It sounds like a trivial detail. But the Run dialog accepts a single lin00
LTLưu Tuấn Anhinblog.fiscybersec.com·Sep 16 · 13 min readTerminalFix Campaign Analysis: Risk of Active Directory Hijacking from Risky Terminal OperationsExecutive Summary Recently, Microsoft Threat Intelligence published analysis of a wide-area attack campaign called TerminalFix — a dangerous evolution from the social engineering technique ClickFix. I00