jinpwn.dev
Posts Archive Cheatsheets About

Type to search posts and cheatsheets.

Type to search posts and cheatsheets.

Posts Archive Cheatsheets About
All cheatsheets Active Directory Pentesting
  • AD MOC
  • Enumeration
  • BloodHound
  • Kerberoasting
  • AS-REP Roasting
  • Password Spraying
  • LLMNR & NTLM Relay
  • ACL Abuse
  • Delegation
  • ADCS ESC1-16
  • Lateral Movement
  • Credential Dumping
  • DCSync
  • Trust Attacks
  • Persistence

AD MOC

Sections AD MOC
  • All cheatsheets
  • AD MOC
  • Enumeration
  • BloodHound
  • Kerberoasting
  • AS-REP Roasting
  • Password Spraying
  • LLMNR & NTLM Relay
  • ACL Abuse
  • Delegation
  • ADCS ESC1-16
  • Lateral Movement
  • Credential Dumping
  • DCSync
  • Trust Attacks
  • Persistence

Full attack chain for Active Directory. Local Windows privesc is in Windows MOC .

Recon #

  • Enumeration
  • BloodHound

Credential access #

  • Kerberoasting
  • AS-REP Roasting
  • Password Spraying
  • LLMNR & NTLM Relay

ACL and object abuse #

  • ACL Abuse
  • Delegation
  • ADCS ESC1-16

Movement and dumping #

  • Lateral Movement
  • Credential Dumping
  • DCSync

Trust and persistence #

  • Trust Attacks
  • Persistence

Support #

  • LDAP
  • Password Cracking
  • Pivoting
Flow

Enum to BloodHound, find the shortest path, abuse the edge, dump, repeat until DA or cross trust.

Next Enumeration

© 2026 JinPwn