Opleiding: Masterclass: Advanced Active Directory Attacks and Mitigations: Investigation and Monitoring Suplement [AADA-IM]
OVERVIEW
This is an international Live Virtual Class, which means you will share the learning experience with a group of IT pros from around the world! This is a great workshop that teaches how to implement secure Microsoft Active Directory infrastructure. The course covers all modern attacks against core Windows identity solutions that everybody talks about and during the session, you will learn how to prevent them! Our goal is to show you how to make your AD infrastructure immune to modern hacking techniques.
This is a deep dive workshop on Active Directory services security, a must-go for administrators, security officers and architects.All exercises are based on Windows Server 2022 and 2025, Windows 11, and Kali Linux. This course is based on our practical knowledge from tons of successful projects, many years of real-world experience, and zero mercy for misconfigurations or insecure solutions!
OBJECTIVES
After completing this course you should be able to:
- Assess the health and structure of AD objects, containers, and GPOs
- Analyze and validate permissions and access control configurations
- Understand NTLM authentication workflow (v1 and v2)
- Detect indicators of NTLM-based attacks
- Understand the Kerberos authentication flow and ticketing process
- Identify and execute common Kerberos attacks
AUDIENCE
- Security architects
- Active Directory administrators
- Security administrators
- Security auditors, and other people responsible for implementing secure identity.
CERTIFICATION
- What is wonderful about our certification is that it is lifetime valid with no renewal fees – the technology changes, but fundamentals and attitude remain mostly the same. Our Virtual Certificates, which entitle you to collect CPE Points, are issued via Accredible.
CONTENT
Module 1: Active Directory Services Health Check
- Objects, containers, GPOs
- Permissions
- Delegation of privileges
- Trusts
- Monitoring
Module 2: NTLM authentication
- NTLM v1
- NTLM v2
- Pass-the-Hash
- MITM Attacks
- NetNTLM Response cracking
- NTLM Relay
- Online password attacks
Module 3: Attacks on NTLM: Detection and Mitigations
- NTLM attack detections
- Hardening NTLM authentication
Module 4: Kerberos authentication
- Authentication flow
- Service kerberization
- PKInit
- PAC validation
Module 5: Attacks against Kerberos: Detection and Mitigations
- Pass-the-Ticket
- Pass-the-Key and Overpass-the-Hash
- Silver ticket
- Golden ticket
- Keberoasting and AS_REP Roasting
- Kerberos armoring
Module 6: Advanced AD Attacks and Persistence: Detection and Mitigations
- Domain and forest security boundaries
- DCSync
- DCShadow
- AdminSDHolder
- NGC Keys and Shadow Credentials
- Skeleton Key
- Golden Ticket
- Offline attacks
- Decrypting secrets with DPAPI and DPAPI-NG
- Attacks against smart card-based-authentication
Module 7: System based mitigations against identity attacks
- LAPS
- LSA Protection
- Credential Guard
- Defender Attack Surface Reduction
- RPC Filters
Module 8: Active Directory auditing techniques
- Security Assessment Checklists and Tools
- Attack Path Mapping
- ACL Analysis
Module 9: Entra ID Hybrid Security
- Stealing Entra ID tokens
- Kerberos Trust
- Seamless SSO
- Federated Authentication