Ravindra BagaleCourses & study guides

38. Active Directory Attacks and Defence

38.2 Safe AD Lab Setup

Production AD var "try" = gunha. Aapan VirtualBox/VMware madhe teen VMs (host-only 192.168.56.0/24):

  1. Windows Server (Evaluation OK) → promote to DC for sahyadri.lab (or rajarani.lab). Static IP plan (book lab): Kali 192.168.56.10, DC 192.168.56.30, client 192.168.56.40.
  2. Windows 10/11 member joined to domain – daily driver user zoya / service account later.
  3. Kali – Impacket, BloodHound.py / SharpHound only against this lab.

Install AD DS role, create domain, create OUs (Users, Servers, Workstations), two normal users (shahrukh, amir), one helpdesk group, one SPN service account (later for Kerberoast lab). Snapshot before weakening anything.

Never bridge the DC to your real office Wi-Fi for "easy internet" while running attack tools. Host-only + optional NAT on Kali alone is enough. Aata pudhe jaauya.

Red team (attacker) does Blue team (defender) detects / stops
Builds identical weak lab to practice paths safely Same lab used by Blue to validate detections (Event IDs, Sysmon) before production
Accidentally scans 192.168.1.0/24 home/office Strict host-only adapter; written lab IP list on sticky note; firewall deny other subnets
Uses real org names/passwords in lab Fictional sahyadri.lab only; unique lab passwords never reused at work

Ravindra Bagale's Tip

Students DC la bridged network detaat ani Impacket chalatana neighbour PC scan hoto. He accident pan illegal feel hote. Adapter = Host-Only. Snapshot gheun weak configs try kara – fix nantar restore. Production credentials lab madhe paste nako.

Lab

VirtualBox/VMware madhe DC + Win10 + Kali host-only set kara. DC: AD DS install, domain sahyadri.lab, DNS on DC. Client join domain. Kali: ping 192.168.56.30 ani nxc ldap 192.168.56.30 (auth nantar – pudhe). Screenshot three IPs aaplya notes madhe. Written permission page: "I own this lab."