WIKI / introductory

Active Directory attack map

An orientation guide to the surfaces connecting identity, privileges and lateral movement.

Active Directory is not a list of isolated techniques. It is a system of relationships between identities, computers, permissions and trust mechanisms. Before running tools, build a map that explains which principal can influence which resource.

Main surfaces

A useful first classification separates four surfaces:

  • Identities and credentials.
  • Groups, ACLs and delegation.
  • Computers, sessions and local administration.
  • Trust relationships between domains.

Workflow

context → enumeration → hypothesis → validation → evidence

Enumeration should answer concrete questions. Collecting objects without a hypothesis creates noise, not operational knowledge.