(TL22)(INCYBER)Linux dans Active Directory:décomposition d’un chemin de compromission en Purple Team

(TL22)(INCYBER)Linux dans Active Directory:décomposition d’un chemin de compromission en Purple Team

🎙 Raphaël Lon et Théo Bertrand 👥 7K 📅 April 14, 2026 ⏱ 31 min 👁 54 📄 expert opinion 🧭 2026-08-13
Available in: English (current) Français

Keywords

Active DirectoryPurple TeamLinuxSSHKerberosPrivilege EscalationDetection

Summary

In this conference talk, two purple teamers from Advance present a realistic compromise path in an Active Directory environment, focusing on Linux integration. They begin with an attacker already on the internal network with a low-privileged domain account (stagiaire). Through password spraying, they gain SSH access to a Linux server due to a misconfiguration allowing all domain users to log in. Once on the server, they enumerate sudo privileges and find a script that can be abused via GTFOBins to escalate to root. As root, they discover a keytab file containing credentials for a service account (SVC backup). Using this keytab, they obtain a Kerberos TGT and pivot to a Windows server, where they find PowerShell history containing domain administrator credentials. Finally, they use these credentials to perform a DC Sync, compromising the entire domain. The talk emphasizes the importance of detection, discussing potential monitoring strategies such as auditing SSH authentication events, using auditd on Linux, and monitoring access to sensitive files like SSSD.conf. The speakers highlight that such attack paths are realistic and often found in real engagements.

179 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into a realistic attack path that combines Linux and Active Directory, which is often overlooked. The speakers clearly explain each step, from initial access to domain compromise, and justify their actions with practical experience. They also discuss detection opportunities, which adds practical value for defenders. The argumentation is solid, based on real-world purple team exercises, and they acknowledge the scenario is a composite of real findings. However, they do not provide detailed technical commands or logs, which might limit its immediate applicability for advanced practitioners.

Scientific Rigor, Source Quality, Title Accuracy

The talk is based on the speakers’ professional experience, which lends credibility, but they do not cite external sources or provide references. The title accurately reflects the content, and the presentation is well-structured. The description includes links to the INCYBER forum and social media, but these are not scientific sources. The lack of formal citations reduces the scientific rigor, but the practical nature of the content compensates somewhat. The speakers mention tools like NetExec, GTFOBins, and SSSD, which are well-known in the cybersecurity community.

189 words

Title / Content Match

The title accurately describes the content: a purple team approach to decomposing a compromise path involving Linux in an Active Directory environment.

Quality & Reliability

7/10

The speakers are experienced purple teamers who present a realistic attack path based on real engagements. They explain technical details and detection considerations, but the video is a conference talk without formal citations or peer-reviewed sources.

Key Moments

Cited Sources

Concurring Sources

  • GTFOBins — Referenced in the talk as a resource for finding binary abuse techniques.
  • MITRE ATT&CK — Not explicitly mentioned but aligns with the attack and detection concepts discussed.

Contribution & Novelties

This talk provides a concrete, step-by-step attack path that bridges Linux and Active Directory, a topic often underrepresented in cybersecurity discussions. It emphasizes the purple team perspective, focusing on detection as well as exploitation. The novelty lies in the combination of techniques: using SSH misconfigurations, abusing SSSD, extracting keytabs, and pivoting to Windows. The speakers also share practical detection advice based on real-world experience.

Pour aller plus loin :

  • GTFOBins — A curated list of Unix binaries that can be used to bypass local security restrictions, relevant to the privilege escalation techniques discussed.
  • MITRE ATT&CK — A knowledge base of adversary tactics and techniques, useful for mapping the attack path and detection opportunities.
  • Active Directory Security — A blog by Sean Metcalf with in-depth articles on Active Directory attacks and defenses, relevant to the domain compromise aspects.

137 words

Radar Profile

The radar profile shows high scores in quantity of information, technical level, and reliability, with slightly lower scores in quality of information and global reliability. This indicates a technically dense and informative talk, but with limited formal sourcing and some reliance on anecdotal evidence.

Reliability 7/10

💬 No comments were provided for analysis.