>_ learn. hack. secure.
Practical offensive security, explained step by step
Hands-on articles on Active Directory, Hack The Box, Linux, Windows, CVEs and penetration testing, written for people who learn by doing.

Explore by topic
[ AD ]
Active Directory
Kerberos, ACLs, delegation and trusts, and the attack paths that connect them.
Latest articles
-

Active Directory Domain Trusts: Direction, Transitivity, SID Filtering, and Blast Radius
How AD trusts define security boundaries: parent/child, forest and external trusts, direction, transitivity, SID filtering and selective authentication, plus commands to enumerate,…
-

DNS and Active Directory: SRV Records, Dynamic Updates, and Spoofing Risks
How AD-integrated DNS, SRV records and dynamic updates underpin authentication, why insecure updates and record takeover matter, and how to audit AD…
-

Active Directory ACLs and Attack Paths: How Small Permissions Become Domain Admin
SIDs, DACLs, ACEs and the dangerous rights (GenericAll, WriteDACL, WriteOwner, AddMember, ForceChangePassword) that form BloodHound-style attack paths, plus how to audit and…
-

Group Policy Security: SYSVOL, GPO Permissions, and the cpassword Legacy
How Group Policy and SYSVOL work, why GPO edit permissions are a domain-wide code-execution risk, the GPP cpassword exposure, and how to…
-

Active Directory Delegation: Unconstrained, Constrained, and RBCD Risks
Kerberos delegation explained: unconstrained vs constrained vs resource-based delegation, TrustedForDelegation, how each is abused, and PowerShell commands to audit and harden delegation.
-

Active Directory Certificate Services (AD CS): Auditing Templates Before They Become Domain Admin
Why AD CS is a major attack surface: enterprise CAs, certificate templates, enrollment permissions and ESC-style misconfigurations, plus how to inventory, audit,…
>_ new here?
Not sure where to start?
Begin with the Active Directory security guide, then work through the write-ups at your own pace.