The Anatomy of an Active Directory Exploitation Attack
In the vast majority of enterprise environments, Microsoft Active Directory (AD) is the central nervous system. It manages user identities, enforces security policies, and dictates which accounts have access to which resources. Consequently, it is the ultimate prize for an attacker. The adage in the red teaming community is simple: If you own Active Directory, you own the network.
Active Directory attacks rarely rely on zero-day vulnerabilities. Instead, they abuse the complex web of legitimate administrative features, legacy protocols, and inevitable misconfigurations that plague large domains. Let's walk through the standard anatomy of an AD exploitation attack, from initial foothold to total domain dominance.
Phase 1: Reconnaissance and BloodHound
Once an attacker lands on a single domain-joined workstation (perhaps via a phishing email or an exploited web app), their first goal is to map the terrain. They are looking for the shortest path from their current, low-privileged user to a Domain Admin account.
The tool of choice for this is BloodHound. By running an ingestor script (like SharpHound) on the compromised machine, the attacker queries the Domain Controller for a massive amount of metadata: user groups, group policies, local admin rights, and active sessions.
BloodHound visualizes this data as a graph. It might reveal that the compromised user jdoe is part of a custom group that has local admin rights on Server-A, and a Domain Admin is currently logged into Server-A. The path is set.
Phase 2: Credential Harvesting and Lateral Movement
To move from the compromised workstation to Server-A, the attacker needs credentials.
If the attacker can escalate to local SYSTEM on the initial workstation, they can use tools like Mimikatz to interact with the Local Security Authority Subsystem Service (LSASS) process. LSASS stores credentials in memory to facilitate single sign-on. The attacker can extract plaintext passwords or NTLM hashes.
Armed with a hash, the attacker doesn't even need to crack it. They can use a technique called Pass-the-Hash (PtH). By injecting the hash directly into their session, they can authenticate to Server-A over SMB or WMI as if they had typed the actual password.
Phase 3: Exploiting Domain Protocols (Kerberoasting)
Sometimes, the path to Domain Admin isn't a straight line of lateral movement. Attackers can exploit AD's primary authentication protocol: Kerberos.
One of the most common and devastating attacks is Kerberoasting. When a user requests access to a service (like an SQL database) running under a specific service account, the Domain Controller provides a Kerberos ticket encrypted with the password hash of that service account.
Any authenticated domain user can request these tickets for any Service Principal Name (SPN) in the domain. The attacker requests the tickets, exports them from memory, and takes them offline. Because service accounts often have weak, non-expiring passwords and high privileges, the attacker can use a massive GPU rig to crack the encrypted ticket offline, recovering the service account's plaintext password.
Phase 4: Domain Privilege Escalation
Beyond protocols, attackers look for misconfigured Access Control Lists (ACLs). Active Directory allows administrators to delegate specific permissions.
For example, a low-privileged helpdesk user might be granted the GenericAll or ForceChangePassword permission over a specific highly privileged group to help with password resets. If the attacker compromises that helpdesk account, they can simply forcefully reset the password of an administrator within that group, taking over the account immediately.
Phase 5: Domain Dominance (The Golden Ticket)
Once an attacker successfully compromises a Domain Admin account or compromises the Domain Controller directly, the domain is officially lost. But attackers know that defenders will eventually notice them. To survive remediation, they establish persistence.
The ultimate persistence mechanism is the Golden Ticket. To create one, the attacker extracts the password hash of the krbtgt account—a special, hidden account on the Domain Controller that encrypts all Kerberos Ticket Granting Tickets (TGTs).
With the krbtgt hash, the attacker can forge their own Kerberos tickets. They can create a ticket that says they are the Enterprise Administrator, and it is valid for 10 years. Even if the defenders realize they are breached, change every user's password, and reboot every server, the attacker can still use their forged Golden Ticket to log back in as a Domain Admin—unless the defenders specifically remember to reset the krbtgt password twice.
Conclusion
Securing Active Directory is an incredibly difficult task that requires constant vigilance. It requires enforcing the principle of least privilege, restricting lateral movement via host-based firewalls, implementing Tiered Administration models, and aggressively monitoring for anomalous Kerberos activity.