انتقل إلى المحتوى
خط الاستجابة الطارئة 24/7
ar
الخدمات
الحلول
الأبحاث
الشركة
الأدواتمركز الثقة

24 سبتمبر 2026مقالات تقنية

أكثر 10 مسارات هجوم على Active Directory نصادفها

The road to domain admin rarely runs through one critical flaw. It usually runs through small misconfigurations chained together.

2 دقائق قراءة

هذا المحتوى متاح حاليًا باللغة الإنجليزية فقط.

Why Active Directory, still?

Active Directory remains the identity and privilege backbone of most organizations. Accounts, exceptions and legacy settings accumulated over the years give attackers paths from a single user account to the entire domain.

The list below summarizes the paths we meet in internal network tests and red team engagements, together with fixes.

Ten attack paths

Attack pathWhy it worksFix
KerberoastingPasswords of service accounts with SPNs can be cracked offline.Use gMSA; 25+ character passwords and AES for service accounts
AS-REP roastingHashes can be requested for accounts without pre-authentication.Remove the DONT_REQ_PREAUTH flag
Unconstrained delegationTGTs of admins connecting to the server can be captured.Move to constrained delegation; mark sensitive accounts as non-delegable
RBCD abuseWrite access to a computer object leads to admin on that machine.Set MachineAccountQuota to 0; audit object ACLs
AD CS ESC1Templates where the enrollee supplies the subject issue certificates for anyone.Disable “Supply in request”; require manager approval
AD CS ESC8 / NTLM relayRelaying NTLM to web enrollment yields a DC certificate.Enforce EPA and HTTPS on Web Enrollment; restrict NTLM
LLMNR / NBT-NS poisoningName resolution fallbacks leak credentials.Disable LLMNR and NBT-NS via GPO; require SMB signing
DCSync rightsReplication rights on non-DC accounts expose every hash.Audit Replicating Directory Changes rights regularly
Local admin password reuseThe same password everywhere enables lateral movement.Enable Windows LAPS on all endpoints
Exposed admin sessionsTier 0 accounts logging on to workstations leave credentials behind.Tiering model, PAWs and the Protected Users group

Where to start

  1. 01

    Visibility

    Map privilege relationships with an attack path analysis tool and identify your Tier 0 assets.

  2. 02

    Quick wins

    Disabling LLMNR/NBT-NS, requiring SMB signing and deploying LAPS break the first link of most chains.

  3. 03

    Certificate services

    Review AD CS templates — the most critical paths increasingly run through them.

  4. 04

    Monitoring

    Write detections for Kerberoasting, DCSync and certificate requests.

To have your environment analyzed from an attacker’s perspective, see our Active Directory Security service.

لنحدد النطاق معًا.

أخبرنا باحتياجك وسيعد خبراؤنا عرضًا مخصصًا لك.

جميع الأبحاث