
Practical Active Directory Pentesting Masterclass 2026
Keywords
Summary
171 words
Critical Evaluation
Value of the Information & Strength of the Argument
The video provides high practical value by demonstrating real attack techniques in a live lab environment. The argumentation is solid, as the hosts explain the underlying mechanisms of each attack (e.g., why LLMNR poisoning works, how NTLM hashes are captured and cracked) rather than just showing commands. They also discuss the impact of misconfigurations and the importance of understanding AD internals. The session is well-structured, progressing from basics to advanced topics, and includes both offensive and defensive perspectives. The use of the ‘Game of Active Directory’ lab adds credibility and allows viewers to replicate the exercises.
Scientific Rigor, Source Quality, Title Accuracy
The content is technically rigorous, with accurate explanations of AD components and attack vectors. The hosts reference open-source tools (e.g., BloodHound, Hashcat, DSInternals) and the ‘Game of Active Directory’ lab, which are credible resources. However, the session does not cite formal academic sources or provide references for further reading. The title accurately reflects the content, as it is indeed a practical masterclass. The video description includes a detailed list of topics covered, which matches the actual content. No comments were provided for analysis.
194 words
Title / Content Match
The title accurately reflects the content: a practical, hands-on masterclass covering Active Directory penetration testing techniques.
Quality & Reliability
8/10
The session is led by a security architect with relevant certifications (OSCP, CRTP, etc.) and provides hands-on demonstrations of AD attacks, referencing open-source tools and labs. The content is technically accurate and practical, though it lacks formal citations and is presented as a masterclass rather than a peer-reviewed source.
Key Moments
Markers derived by PSI from the transcript: the creator did not define chapters.
- Introduction and importance of Active Directory security
- Explanation of AD components: directory, directory services, domain controller
- Overview of AD structure: forests, domains, OUs
- Demonstration of NTDS.DIT extraction using NTDSUTIL
- LLMNR poisoning and NTLM hash capture
- Hashcat cracking of NTLM hashes
- BloodHound for mapping AD attack paths
- ADCS vulnerabilities and certificate-based attacks
- DCSync, DACL abuse, and persistence techniques
- Kerberos attacks: Golden Ticket, Silver Ticket, Kerberoasting
Cited Sources
- Game of Active Directory — Open-source lab used for demonstrations
- BloodHound — Tool for AD attack path mapping
- Hashcat — Password cracking tool used for NTLM hashes
- DSInternals — Tool for parsing NTDS.DIT and extracting boot key
Concurring Sources
- Active Directory Security Best Practices — Microsoft documentation supporting the importance of AD security and recommended mitigations.
- BloodHound Documentation — Official documentation for BloodHound, a tool used in the video for AD attack path analysis.
Contribution & Novelties
This masterclass provides a comprehensive, hands-on approach to AD penetration testing, combining foundational knowledge with practical demonstrations. It stands out by emphasizing the ‘why’ behind attacks, not just the ‘how’, and by using a realistic, open-source lab environment. The session covers a wide range of techniques, from initial access to persistence, and includes both offensive and defensive perspectives.
Pour aller plus loin :
- Active Directory Security — Microsoft’s official best practices for securing AD.
- MITRE ATT&CK - Active Directory — Framework for understanding AD attack techniques.
- Kerberos (protocol) — Overview of the Kerberos authentication protocol.
95 words
Radar Profile
The radar profile shows high scores across all dimensions, indicating a well-rounded and reliable resource. The video excels in providing substantial information and technical depth, with strong practical value and credibility.