Ravindra BagaleCourses & study guides

38. Active Directory Attacks and Defence

38.9 Putting It Together – Purple Team Mindset

Thodkyaat: AD security = identity security. Tools (Impacket, BloodHound, NetExec) shikayche – pan tumcha paisa Blue controls var. Rozcha loop: enum like Red → fix like Blue → re-enum until fail.

Interview model (clean English): "I only test Active Directory in an isolated lab I own. For Kerberoasting I explain SPNs and gMSA remediation. I use BloodHound from a defender perspective to remove AdminTo and GenericAll edges."

Red team (attacker) does Blue team (defender) detects / stops
Full kill chain in lab: enum → roast → session → ACL → DA Purple Team: same chain with SIEM alerts proving detection at each hop
Documents screenshots of tickets/hashes Documents Event IDs + GPO evidence that attacks now fail

Ravindra Bagale's Tip

Tool worship vs control worship – fark samja. Hashcat speed impress karto; LAPS + signing + gMSA companies bachavtat. Job madhe Blue/SOC/cloud-sec roles jatil – defence language practice kara. Aata pudhe malware chapter!

Lab

Chapter project (38.8 box) complete kara jar pending asel. Mag 10 flashcards: TGT, TGS, SPN, AS-REP, Kerberoast, PtH, relay, BloodHound edge, LAPS, Tier-0. Pair with Ruhi/Shraddha (study buddy) – ek Red question, ek Blue answer.

Real incident: Kerberoasting in public breach reporting

Multiple public incident reports and red-team case studies (vendor blogs and industry write-ups) have described Kerberoasting as a common step after a domain user foothold when service account passwords were weak. Exact victim names vary by report – pattern is consistent: SPN + weak password + offline cracking. Defence: gMSA / long passwords, AES, 4769 monitoring. Source: public Microsoft detection guidance and major vendor Kerberoasting articles (verify current docs).

Thodkyaat sangaycha tar

  • AD = domain identity brain; Domain Admin ≈ keys to the kingdom – lab only for attack practice.
  • Safe lab: DC 192.168.56.30 + client + Kali 192.168.56.10, fictional sahyadri.lab / Raja-Rani Traders.
  • Enum: nxc ldap, Impacket GetADUsers, BloodHound collectors – then remediate what you find.
  • AS-REP (no pre-auth) ani Kerberoast (SPN + weak password) – fix with pre-auth, gMSA, AES, monitoring.
  • NTLM relay / PtH – stop with signing, channel binding, LAPS, Credential Guard, Tier model.
  • BloodHound edges guide Blue path reduction (AdminTo, MemberOf, HasSession, GenericAll).
  • Project: build weak AD → hack in lab → fix → re-verify failure.
  • Real incidents remind us: identity + lateral movement decide blast radius.

Samjla ka? Active Directory attacks shiklo – pan pratyek sobat bachav. Pudhchya chapter madhe malware (types, analysis mindset, defence) – CEH modules pudhe. Chala pudhe, mitrano!