YoVDO

Advanced Pen Testing Techniques for Active Directory

Offered By: LinkedIn Learning

Tags

Penetration Testing Courses Active Directory Courses LDAP Courses Kerberos Courses Password Spraying Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore concrete, practical strategies for penetration testing Active Directory to prevent enterprise cybersecurity threats.

Syllabus

Introduction
  • Understand and test the security of identity providers
  • What you should know
  • Disclaimer
1. Introduction to Identities
  • Understand Active Directory's role in security
  • The LDAP protocol
  • Interact with LDAP at the command line
  • The LDAPAdmin tool
  • What is Active Directory?
  • Interact with Active Directory at the command line
  • Access LDAP services with a GUI client
  • Add users and computers to a domain
  • Active Directory security audit
2. Testing Active Directory
  • Set up for testing
  • Extract the AD hashes
  • Password spraying Active Directory
  • Kerberos brute-forcing attacks
  • Use CrackMapExec to access and enumerate AD
  • Investigate the SYSVOL share
  • Take advantage of legacy data
3. Advanced Penetration Testing
  • Specific Active Directory attacks
  • Remote extraction of AD hashes
  • Carry out a Kerberos roasting
  • Run a no-preauthentication attack
  • Forge a golden ticket
  • Running a shadow attack
  • Using rubeus to take over the domain
  • Relaying attacks to get a certificate
  • Using smartcards to gain privileged access
  • Set the BloodHound loose
Conclusion
  • Next steps

Taught by

Malcolm Shore

Related Courses

Windows Server Management and Security
University of Colorado System via Coursera
Cyber Attack Countermeasures
New York University (NYU) via Coursera
CompTIA Network+ (N10-007) Cert Prep: 5 Securing TCP/IP
LinkedIn Learning
Access Control Mechanisms in Linux
Pluralsight
Cloudera Hadoop Administration
YouTube