Skip to content

Breaching Active Directory

Getting the first valid set of Active Directory credentials, the usual prerequisite for everything else in an AD engagement.

Why It Matters

Most AD attacks assume you already have a foothold: one valid domain account. Breaching AD is about getting that first credential, whether from an exposed service, a misconfiguration, intercepted authentication, or OSINT. Once inside, the work moves to Discovery and Privilege Escalation.

Reference

Where Credentials Come From

Source Notes
OSINT and breach data Have I Been Pwned, DeHashed, GitHub leaks, documents
NTLM-authenticated services OWA/Exchange, RDP, AD-integrated VPNs, internet-facing apps that accept domain creds
LDAP bind credentials Services (GitLab, Jenkins, printers, VPNs, custom apps) that store a domain bind account
Authentication relays Intercepting and relaying NetNTLM authentication on the internal network
Deployment systems MDT/SCCM and PXE boot images that contain credentials
Configuration files Web app configs, service configs, registry keys, deployed application files

Password Spraying

Trying one common password across many usernames stays under per-account lockout thresholds. Build the username list from OSINT and the organization's email format, pick passwords that fit the season or policy, and keep the attempt rate low. Tools: kerbrute, NetExec.

Lockouts

Spraying can still lock accounts if the password count per account exceeds the policy. Know the lockout threshold and observation window before starting, and stay well under them.

LDAP Pass-back

If you control a device's LDAP configuration (for example a printer's admin panel), redirecting its LDAP server to a host you control can capture the bind credentials. A rogue LDAP server configured to accept cleartext mechanisms, with tcpdump capturing port 389, recovers the credential when the device tests its connection.

NetNTLM Interception and Relay

SMB and other services use NetNTLM authentication, which can be captured and abused:

  • Responder answers LLMNR, NBT-NS, and WPAD requests to coerce and capture authentication: sudo responder -I <interface>
  • Captured NetNTLM hashes can be cracked offline (slower than raw NTLM) or relayed to another host to gain an authenticated session

How I Use It

I start with the quietest sources: OSINT, breach data, and any exposed service that accepts domain credentials for a careful spray. On an internal network, Responder plus relaying is often the fastest path to a first credential. One valid account is the goal; from there the engagement moves into enumeration with BloodHound and PowerView.

Resources