>_ the cyber track
Cyber Track Blog
Write-ups, attack paths and defensive notes on Active Directory, Linux, Windows and web security.
Featured articles
-

Active Directory Domain Trusts: Direction, Transitivity, SID Filtering, and Blast Radius
How AD trusts define security boundaries: parent/child, forest and external trusts, direction, transitivity, SID filtering and selective authentication, plus commands to enumerate, audit and monitor trusts.
-
DNS and Active Directory: SRV Records, Dynamic Updates, and Spoofing Risks
How AD-integrated DNS, SRV records and dynamic updates underpin authentication, why insecure updates and record takeover…
-
Active Directory ACLs and Attack Paths: How Small Permissions Become Domain Admin
SIDs, DACLs, ACEs and the dangerous rights (GenericAll, WriteDACL, WriteOwner, AddMember, ForceChangePassword) that form BloodHound-style attack…
-
Group Policy Security: SYSVOL, GPO Permissions, and the cpassword Legacy
How Group Policy and SYSVOL work, why GPO edit permissions are a domain-wide code-execution risk, the…
Browse all articles
-

Active Directory Domain Trusts: Direction, Transitivity, SID Filtering, and Blast Radius
How AD trusts define security boundaries: parent/child, forest and external trusts, direction, transitivity, SID filtering and selective authentication, plus commands to enumerate,…
-

DNS and Active Directory: SRV Records, Dynamic Updates, and Spoofing Risks
How AD-integrated DNS, SRV records and dynamic updates underpin authentication, why insecure updates and record takeover matter, and how to audit AD…
-

Active Directory ACLs and Attack Paths: How Small Permissions Become Domain Admin
SIDs, DACLs, ACEs and the dangerous rights (GenericAll, WriteDACL, WriteOwner, AddMember, ForceChangePassword) that form BloodHound-style attack paths, plus how to audit and…
-

Group Policy Security: SYSVOL, GPO Permissions, and the cpassword Legacy
How Group Policy and SYSVOL work, why GPO edit permissions are a domain-wide code-execution risk, the GPP cpassword exposure, and how to…
-

Active Directory Delegation: Unconstrained, Constrained, and RBCD Risks
Kerberos delegation explained: unconstrained vs constrained vs resource-based delegation, TrustedForDelegation, how each is abused, and PowerShell commands to audit and harden delegation.
-

Active Directory Certificate Services (AD CS): Auditing Templates Before They Become Domain Admin
Why AD CS is a major attack surface: enterprise CAs, certificate templates, enrollment permissions and ESC-style misconfigurations, plus how to inventory, audit,…
-

SMB Signing and NTLM Relay: Closing the Quiet Path to Lateral Movement
How SMB authentication works, why SMB signing stops NTLM relay, and how to audit signing requirements across the fleet with PowerShell, then…
-

LDAP and LDAP Signing in Active Directory: Channel Binding, Relay, and Hardening
How Active Directory uses LDAP and LDAPS, why unsigned binds and missing channel binding enable relay attacks, and how to audit domain…
-

NTLM Authentication: Pass-the-Hash, Relay, and Why Enterprises Are Retiring It
Understand the NTLM challenge-response protocol, NTLMv1 vs NTLMv2, Pass-the-Hash and NTLM relay, where NTLM still lives in the enterprise, and how to…