Active Directory39 Hunting Active Directory Honeypots: Reading lastLogon as a Decoy Oracle
Decoy accounts in Active Directory look legitimate at the schema level but cannot fake behavioural history. This walkthrough shows how to read…
Active Directory39 Decoy accounts in Active Directory look legitimate at the schema level but cannot fake behavioural history. This walkthrough shows how to read…
Active Directory57 A walkthrough of a classic-but-still-effective Active Directory attack: how write access to an SMB share — plus a single .lnk file —…
Active Directory27 Windows Server 2025 quietly breaks a classic NTLM relay technique by enforcing changes inside msv1_0.dll. The update prevents attackers from abusing NTLMv1…
Active Directory40 The article explains how attackers dump credentials from the Windows LSASS process using tools like Mimikatz and ProcDump, extracting password hashes and…
Active Directory26 CVE-2025-33073 enables NTLM reflection attacks that give attackers SYSTEM access on vulnerable Windows hosts. When combined with unconstrained delegation, a single compromised…
Active Directory28 he article demonstrates an NTLM relay attack against Active Directory using tools like ntlmrelayx and PetitPotam. By relaying authentication to LDAP, attackers…
Active Directory35 The article explains how flat enterprise networks enable easy lateral movement and domain compromise. It shows how Active Directory tiering models segment…
Active Directory30 This article analyzes an Active Directory attack chain where password spraying reveals valid credentials, privileged accounts enable escalation, and Kerberoasting exposes service…
Active Directory16 SafeBreach Labs disclosed a critical RCE in the MS-EVEN RPC service (CVE-2025-29969) that lets low-privilege users write arbitrary files remotely on Windows…
Active Directory27 Windows authentication coercion is still a powerful AD primitive: it forces predictable auth flows and enables relay chains. Modern mitigations reduce easy…