> For the complete documentation index, see [llms.txt](https://pwc-3.gitbook.io/pwc/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://pwc-3.gitbook.io/pwc/ji-shu/untitled-1/offensive-security-experiments/active-directory-and-kerberos-abuse.md).

# Active Directory & Kerberos Abuse

## Active Directory & Kerberos Abuse

A collection of techniques that exploit and abuse Active Directory, Kerberos authentication, Domain Controllers and similar matters.

Here are the articles in this section:[From Domain Admin to Enterprise AdminExplore Parent-Child Domain Trust Relationships and abuse it for Privilege Escalation](/pwc/ji-shu/untitled-1/offensive-security-experiments/active-directory-kerberos-abuse/from-domain-admin-to-enterprise-admin.md)[KerberoastingCredential Access](/pwc/ji-shu/untitled-1/offensive-security-experiments/active-directory-kerberos-abuse/kerberoasting.md)[Kerberos: Golden TicketsPersistence and Privilege Escalation with Golden Kerberots tickets](/pwc/ji-shu/untitled-1/offensive-security-experiments/active-directory-kerberos-abuse/kerberos-golden-tickets.md)[Kerberos: Silver TicketsCredential Access](/pwc/ji-shu/untitled-1/offensive-security-experiments/active-directory-kerberos-abuse/kerberos-silver-tickets.md)[AS-REP Roasting](/pwc/ji-shu/untitled-1/offensive-security-experiments/active-directory-kerberos-abuse/as-rep-roasting.md)[Kerberoasting: Requesting RC4 Encrypted TGS when AES is Enabled](/pwc/ji-shu/untitled-1/offensive-security-experiments/active-directory-kerberos-abuse/kerberoasting-requesting-rc4-encrypted-tgs-when-aes-is-enabled.md)[Kerberos Unconstrained Delegation](/pwc/ji-shu/untitled-1/offensive-security-experiments/active-directory-kerberos-abuse/kerberos-unconstrained-delegation.md)[Kerberos Constrained Delegation](/pwc/ji-shu/untitled-1/offensive-security-experiments/active-directory-kerberos-abuse/kerberos-constrained-delegation.md)[Kerberos Resource-based Constrained Delegation: Computer Object Take Over](/pwc/ji-shu/untitled-1/offensive-security-experiments/active-directory-kerberos-abuse/kerberos-resource-based-constrained-delegation-computer-object-take-over.md)[Domain Compromise via DC Print Server and Kerberos Delegation](/pwc/ji-shu/untitled-1/offensive-security-experiments/active-directory-kerberos-abuse/domain-compromise-via-dc-print-server-and-kerberos-delegation.md)[DCShadow - Becoming a Rogue Domain Controller](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1207-creating-rogue-domain-controllers-with-dcshadow)[DCSync: Dump Password Hashes from Domain Controller](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/dump-password-hashes-from-domain-controller-with-dcsync)[PowerView: Active Directory Enumeration](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/active-directory-enumeration-with-powerview)[Abusing Active Directory ACLs/ACEs](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/abusing-active-directory-acls-aces)[Privileged Accounts and Token Privileges](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/privileged-accounts-and-token-privileges)[From DnsAdmins to SYSTEM to Domain Compromise](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/from-dnsadmins-to-system-to-domain-compromise)[Pass the Hash with Machine$ Accounts](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/pass-the-hash-with-machine-accounts)[BloodHound with Kali Linux: 101](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/abusing-active-directory-with-bloodhound-on-kali-linux)[Backdooring AdminSDHolder for Persistence](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/how-to-abuse-and-backdoor-adminsdholder-to-obtain-domain-admin-persistence)[Active Directory Enumeration with AD Module without RSAT or Admin Privileges](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/active-directory-enumeration-with-ad-module-without-rsat-or-admin-privileges)[Enumerating AD Object Permissions with dsaclsEnumeration, living off the land](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/using-dsacls-to-check-ad-object-permissions)[Active Directory Password Spraying](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/active-directory-password-spraying)[Active Directory Lab with Hyper-V and PowerShell](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/active-directory-lab-with-hyper-v-and-powershell)
