38. Active Directory Attacks and Defence
38.9 Putting It Together – Purple Team Mindset
Thodkyaat: AD security = identity security. Tools (Impacket, BloodHound, NetExec) shikayche – pan tumcha paisa Blue controls var. Rozcha loop: enum like Red → fix like Blue → re-enum until fail.
Interview model (clean English): "I only test Active Directory in an isolated lab I own. For Kerberoasting I explain SPNs and gMSA remediation. I use BloodHound from a defender perspective to remove AdminTo and GenericAll edges."
| Red team (attacker) does | Blue team (defender) detects / stops |
|---|---|
| Full kill chain in lab: enum → roast → session → ACL → DA | Purple Team: same chain with SIEM alerts proving detection at each hop |
| Documents screenshots of tickets/hashes | Documents Event IDs + GPO evidence that attacks now fail |
Ravindra Bagale's Tip
Tool worship vs control worship – understand the difference. Hashcat's speed impresses; LAPS + signing + gMSA are what save companies. On the job you will go into Blue/SOC/cloud-sec roles – practise the language of defence. Next up: the malware chapter!
Ravindra Bagale's Tip – मराठी
Tool worship vs control worship – फरक समजून घ्या. Hashcat चा speed impress करतो; LAPS + signing + gMSA companies वाचवतात. Job मध्ये Blue/SOC/cloud-sec roles मिळतील – defence ची भाषा practice करा. आता पुढे malware chapter!
Ravindra Bagale's Tip – हिंदी
Tool worship vs control worship – फ़र्क समझो. Hashcat की speed impress करती है; LAPS + signing + gMSA companies को बचाते हैं. Job में Blue/SOC/cloud-sec roles मिलेंगे – defence की भाषा practice करो. अब आगे malware chapter!
Lab
Chapter project (38.8 box) complete kara jar pending asel. Mag 10 flashcards: TGT, TGS, SPN, AS-REP, Kerberoast, PtH, relay, BloodHound edge, LAPS, Tier-0. Pair with Ruhi/Shraddha (study buddy) – ek Red question, ek Blue answer.
Real incident: Kerberoasting in public breach reporting
Multiple public incident reports and red-team case studies (vendor blogs and industry write-ups) have described Kerberoasting as a common step after a domain user foothold when service account passwords were weak. Exact victim names vary by report – pattern is consistent: SPN + weak password + offline cracking. Defence: gMSA / long passwords, AES, 4769 monitoring. Source: public Microsoft detection guidance and major vendor Kerberoasting articles (verify current docs).
Thodkyaat sangaycha tar
- AD = domain identity brain; Domain Admin ≈ keys to the kingdom – lab only for attack practice.
- Safe lab: DC
192.168.56.30+ client + Kali192.168.56.10, fictionalsahyadri.lab/ Raja-Rani Traders. - Enum: nxc ldap, Impacket GetADUsers, BloodHound collectors – then remediate what you find.
- AS-REP (no pre-auth) ani Kerberoast (SPN + weak password) – fix with pre-auth, gMSA, AES, monitoring.
- NTLM relay / PtH – stop with signing, channel binding, LAPS, Credential Guard, Tier model.
- BloodHound edges guide Blue path reduction (AdminTo, MemberOf, HasSession, GenericAll).
- Project: build weak AD → hack in lab → fix → re-verify failure.
- Real incidents remind us: identity + lateral movement decide blast radius.
Samjla ka? Active Directory attacks shiklo – pan pratyek sobat bachav. Pudhchya chapter madhe malware (types, analysis mindset, defence) – CEH modules pudhe. Chala pudhe, mitrano!