Skip to content
Hacked By HimelHacked By Himel
  • Category
    • AI Security
    • Blue Team
    • Bug Bounty
    • cloud security
    • Ethical Hacking
    • Fundamentals
    • Network Pentesting
    • OSINT
    • Pentesting
    • Pentesting AI
  • Home
  • Courses
  • Blog
  • Contact Us
    • About US
    • Contact Us
    • Dashboard
0

Currently Empty: ৳ 0.00

Continue shopping

Join for Free
Hacked By HimelHacked By Himel
  • Home
  • Courses
  • Blog
  • Contact Us
    • About US
    • Contact Us
    • Dashboard
  • Home
  • Course
  • Active Directory Pentesting & Red Teaming

Active Directory Pentesting & Red Teaming

  • By mdhimelatikh
  • Network Pentesting
Breadcrumb Abstract Shape
Breadcrumb Abstract Shape
Breadcrumb Abstract Shape
  • Course Info
  • Instructor
  • More
    • Active Directory Pentesting & Red Teaming is a fully hands-on, lab-driven course built for aspiring and working penetration testers, red teamers, and cybersecurity professionals who want real, practical mastery of Active Directory (AD) attacks — not just theory.

      Active Directory runs the identity and access backbone of over 90% of enterprise networks worldwide, which makes it one of the most targeted — and most misunderstood — attack surfaces in offensive security. This course takes you from the fundamentals of how AD authentication, trusts, and Group Policy actually work, all the way to advanced real-world attack chains used by professional red teamers and adversaries alike.

      You won’t just watch slides — you’ll build your own AD lab from the ground up (Domain Controller, GPOs, victim workstations), intentionally misconfigure it, and then attack it step-by-step using the exact tools and techniques used in real penetration tests: Kerbrute, NetExec, ldapsearch, BloodHound CE, PowerView, Mimikatz, Rubeus, Impacket, Chisel, Ligolo-ng, and more.

      What You’ll Learn

      By the end of this course, you’ll be able to:

      • Understand AD fundamentals — users, computers, GPOs, Kerberos, NetNTLM, forests, and trust relationships
      • Build a fully functional vulnerable AD lab for practice and certification prep
      • Perform passive and active AD enumeration using LDAP, NetExec, PowerShell, MMC, and Command Prompt
      • Map attack paths visually with BloodHound CE, PingCastle, and Purple Knight
      • Execute real-world initial access attacks: LLMNR/NBT-NS poisoning, AS-REP Roasting, Password Spraying, SMB Relay, LDAP Pass-Back, PXE Boot Scraping, and IPv6 poisoning
      • Move laterally using PsExec, WMIExec, SMBExec, Pass-the-Hash, Pass-the-Ticket, Overpass-the-Hash, and Token Impersonation
      • Pivot through segmented networks using SSH tunneling, Socat, Chisel, and Ligolo-ng
      • Exploit AD misconfigurations: DACL abuse, ForceChangePassword, Kerberoasting, Printer Bug/NTLM Relay, and GPO abuse
      • Attack Active Directory Certificate Services (ADCS) — including ESC1 through ESC5 privilege escalation paths
      • Compromise forest trusts and execute Golden Ticket attacks
      • Exploit real CVEs like noPac against live AD environments
      • Establish persistence using DCSync, Golden Tickets, Silver Tickets, and ADCS certificate abuse

      Course Structure

      This course is organized into progressive modules covering AD fundamentals → lab setup → enumeration → initial access → lateral movement → pivoting → exploitation → ADCS attacks → trust exploitation → CVE exploitation → persistence — mirroring the exact methodology used in professional Active Directory penetration tests and red team engagements.

      Who This Course Is For

      • Penetration testers and red teamers who want to specialize in AD attacks
      • SOC analysts and blue teamers who want to understand attacker methodology to defend better
      • OSCP, CRTP, CRTE, and CPTS aspirants who need deep, practical AD attack experience
      • IT/security professionals responsible for securing enterprise Windows environments
      • Anyone serious about a career in offensive security or red teaming

      Requirements

      • Basic understanding of networking and Windows environments
      • A laptop capable of running virtual machines (VMware/VirtualBox)
      • Willingness to build and break your own AD lab

      Why Take This Course

      Unlike theory-heavy courses, every module here is anchored in practical, step-by-step lab exercises on a real Active Directory environment you build yourself. You’ll finish not just knowing what AD attacks are, but how to execute, chain, and pivot them like a professional penetration tester — skills directly transferable to real engagements, CTFs, and top-tier certifications like OSCP, CRTP, and CRTE.

       যেকোনো তথ্যের জন্য আমাদের সাথে যোগাযোগ করুন:

      •  টেলিগ্রাম (MD HIMEL ATIK): https://t.me/hackedbyhimel

      • হোয়াটসঅ্যাপ করুন: https://wa.me/+8801951045900

      • সরাসরি কল করুন: 01951045900

      প্রথম ৫ ঘণ্টা সম্পূর্ণ ফ্রি!

      কেনার আগে নিজেই যাচাই করে নিন — এই কোর্সের প্রথম ৫ ঘণ্টা কন্টেন্ট সম্পূর্ণ ফ্রিতে দেখতে পারবেন, কোনো পেমেন্ট বা কার্ড ইনফরমেশন ছাড়াই। AD Fundamentals থেকে শুরু করে Lab Setup পর্যন্ত পুরোটা ফ্রি প্রিভিউতে কভার করা হয়েছে, যাতে আপনি বুঝতে পারেন —

      • ইন্সট্রাক্টরের পড়ানোর স্টাইল আপনার জন্য উপযুক্ত কিনা
      • ল্যাব ও প্র্যাকটিক্যাল অ্যাপ্রোচ কেমন
      • কোর্সের ডেপথ ও প্রোডাকশন কোয়ালিটি
      • এই কোর্স আপনার লেভেলের জন্য পারফেক্ট কিনা
       নিচে ফ্রি প্রিভিউ ভিডিওটি দেখুন এবং নিজেই সিদ্ধান্ত নিন!
      Show More

      Course Content

      Module 1. Active Directory Fundamentals

      • What is Active Directory Pentesting
      • Fundamentals of Active Directory part 1
      • Fundamentals of Active Directory part 2
      • How to manage Users in Active Directory
      • Managing Computers & Group Policy Object in AD
      • AD Authentication Karberos & NetNTLM
      • Trees Forest Trust Relationship

      Module 2. Active Directory Pentesting Lab Setup

      • How to Setup Windows Server
      • AD Domain Controller Setup
      • Create GPO for our AD Lab
      • How to Setup Windows victim Workstation for AD

      Module 3. Reconnaissance on Active Directory

      • Pre-Engagement & Attacks Surface Briefing
      • Attack Launchpads Client-Provided Setups
      • Identifying Hosts – Passive Host Identification
      • Active Validation & Service Enumeration of AD
      • Enumerating Users of AD with Kerbrute
      • Create-AD-User Script for AD Lab
      • Enumerate AD Users with Netexec
      • Make our labs vulnerable using MakeAdVuln script
      • ldapsearch for AD Enumeration
      • Ldap Enumeration & Ldapdomdump for mapping AD

      Module 4. Getting Initial Foothold on Active Directory

      • Breaching Active Directory lab Setup
      • Practical LLMNR NBTNS Poisoning Attacks on AD (Kali)
      • Practical As-Rep Roasting Using impact-GetNpUser
      • Practical Password Spraying Attack on AD
      • Practical NetNTLM password spraying Attack
      • Practical SMB Relay Attack on Active Directory Network
      • Practical ldap pass back attack
      • Practical PXE Boot Password Scraping Attack on AD
      • Practical IPV6 Poisoning Attack on AD Networks

      Module 5. Active Directory Enumeration After Initial Foothold

      • Introduction to AD Enumeration & Lab Seutp
      • Credential Injection Attacks on Active Directory
      • AD Enumeration Using Microsoft Management Console
      • AD Enumeration Using Command Prompt
      • AD Enumeration Using Powershell
      • Bloodhound community edition install and setup
      • AD Enumeration Using Bloodhound CE part 1
      • AD Enumeration Using Bloodhound CE part 2
      • AD Enumeration Using Powerviews
      • AD Enumeration Using Ping Castle
      • AD Enumerate using Purple knight

      Module 6. Lateral Movements on Active Directory

      • Introduction to lateral movement on AD
      • Lateral Movement RPE Using psexec wmiexec & smbexec
      • Lateral Movement via Windows Services on AD
      • Lateral Movement on AD using WMIexec
      • Lateral Movement using WMI process creation
      • Lateral Movement Using WMI resources
      • Lateral Movement With Pass the Hash Attack
      • Pass-the-Hash Using Mimikatz
      • Pass the Ticket Using Rubeus tool
      • Pass_the_Ticket_Using_Rubeus resource
      • Pass the Ticket Using Mimikatz
      • Over Pass the Hash Using Mimikatz
      • Token Impersonation Attack
      • RDP Hijacking Attack on Active Directory

      Module 7. Pivoting & Tunneling on Active Directory

      • What is Pivoting Tunnelling & Port Forwarding Theory
      • What is Pivoting Tunnelling & Port Forwarding resource
      • Socat for pivoting or tunnelling
      • Local Port Forwarding Using SSH
      • Remote Port Forward using SSH
      • Dynamic Port Forwarding using SSH
      • Pivoting or Port Forwarding Using Chisel
      • Pivoting & Tunnelling lab setup
      • Pivoting Using Ligolo-ng

      Module 8. Exploiting Active Directory Services

      • Introduction to Active Directory Exploitation
      • Exploiting AD Permission Delegation
      • Exploiting Printer Bug & NTLM Relay
      • Exploiting AD USers
      • Exploiting AD Group Object Policy
      • Exlpoiting Kerberos Authentication (Kerberosting)
      • DACL Abuse shadow credentials Attack
      • Exploiting DACL Abuse ForceChangePassword

      Module 9. Exploiting Active Directory Certificate Services

      • Introduction to ADCS For Pentesting
      • Setup Vulnerable ADCS Labs For Pentesting
      • Common_ADCS_Vulnerability_lab_setup
      • ESC1 Attack Low Privilege to Domain Admin Without Password
      • ESC2 Exploitation AD CS Certificate Abuse & Domain Compromise
      • ESC 3 Exploitation Guide
      • ESC4 Exploitation Techniques for Domain Compromise
      • ESC5 Exploitation Real World Attack Scenarios

      Module 10. Exploiting Active Directory Trust Relationship

      • Exploiting Trust of Active Directory Forest (Theory)
      • Exploiting Active Directory Trust using Golden Ticket

      Module 11. Active Directory CVE Exploitation

      • Intro to CVE Testing in Active Directory
      • Exploit NoPac Vulnerability in AD

      Module 12. Active Directory Persistence

      • Intro & Why Persistance Matters in a Pentest
      • AD Persistance Through Credentials (DCSync Attack) Part 1
      • AD Persistance Through Credentials Using Mimikatz Part 2
      • AD Persistance Using Golden Tickets
      • AD Persistance (Golden Tickets) Using Mimikatz
      • AD Persistance Using Silver Tickets
      • AD Persistance Using ADCS Certificates
      • AD Persistance via SID History Abuse
      • AD Persistance Through Group Membership

      Module 13. Active Directory Hardening

      Module 14. AD Assessment Report

      Tags

      • active directory

      A course by

      M
      mdhimelatikh

      Course Includes:

      • Price:
        ৳ 25,000.00 Original price was: ৳ 25,000.00.৳ 6,999.00Current price is: ৳ 6,999.00.
      • Instructor:mdhimelatikh
      • Lessons:93
      • Level:Intermediate
      ৳ 6,999.00 ৳ 25,000.00
      Wishlist
      Hi, Welcome back!
      Continue with Google
      Forgot Password?
      Don't have an account?  Register Now

      Share On:

      Courses You May Like

      pentesting for professional
      ৳ 40,000.00 Original price was: ৳ 40,000.00.৳ 15,000.00Current price is: ৳ 15,000.00.
      • 754 Lessons
      • 6 Students
      Pentesting
      Penetration Testing For Professionals
      cropped-hacked-by-himel-logo.png

      Hacked by Himel is a cybersecurity learning platform sharing ethical hacking, write-ups, and courses to help you master offensive and defensive security in Bangladesh.

      Add: Jashore, Bangladesh
      Call: +8801951045900
      Email: services@hbhsec.com

      Online Platform

      • Home
      • Blog
      • About US
      • Contact Us
      • Privacy Policy

      Links

      • Home
      • Courses
      • Blog
      • Contact Us

      Contacts

      Enter your email address to register to our newsletter subscription

      Icon-facebook Icon-youtube Icon-linkedin2 Icon-instagram Icon-twitter
      Copyright 2026 | All Rights Reserved
      Hacked By HimelHacked By Himel
      Sign inSign up

      Sign in

      Don’t have an account? Sign up
      Lost your password?

      Sign up

      Already have an account? Sign in
      Continue with Google

      Have Questions? WhatsApp Us