هذا المحتوى متاح حاليًا باللغة الإنجليزية فقط.
Why Active Directory, still?
Active Directory remains the identity and privilege backbone of most organizations. Accounts, exceptions and legacy settings accumulated over the years give attackers paths from a single user account to the entire domain.
The list below summarizes the paths we meet in internal network tests and red team engagements, together with fixes.
Ten attack paths
| Attack path | Why it works | Fix |
|---|---|---|
| Kerberoasting | Passwords of service accounts with SPNs can be cracked offline. | Use gMSA; 25+ character passwords and AES for service accounts |
| AS-REP roasting | Hashes can be requested for accounts without pre-authentication. | Remove the DONT_REQ_PREAUTH flag |
| Unconstrained delegation | TGTs of admins connecting to the server can be captured. | Move to constrained delegation; mark sensitive accounts as non-delegable |
| RBCD abuse | Write access to a computer object leads to admin on that machine. | Set MachineAccountQuota to 0; audit object ACLs |
| AD CS ESC1 | Templates where the enrollee supplies the subject issue certificates for anyone. | Disable “Supply in request”; require manager approval |
| AD CS ESC8 / NTLM relay | Relaying NTLM to web enrollment yields a DC certificate. | Enforce EPA and HTTPS on Web Enrollment; restrict NTLM |
| LLMNR / NBT-NS poisoning | Name resolution fallbacks leak credentials. | Disable LLMNR and NBT-NS via GPO; require SMB signing |
| DCSync rights | Replication rights on non-DC accounts expose every hash. | Audit Replicating Directory Changes rights regularly |
| Local admin password reuse | The same password everywhere enables lateral movement. | Enable Windows LAPS on all endpoints |
| Exposed admin sessions | Tier 0 accounts logging on to workstations leave credentials behind. | Tiering model, PAWs and the Protected Users group |
Where to start
- 01
Visibility
Map privilege relationships with an attack path analysis tool and identify your Tier 0 assets.
- 02
Quick wins
Disabling LLMNR/NBT-NS, requiring SMB signing and deploying LAPS break the first link of most chains.
- 03
Certificate services
Review AD CS templates — the most critical paths increasingly run through them.
- 04
Monitoring
Write detections for Kerberoasting, DCSync and certificate requests.
To have your environment analyzed from an attacker’s perspective, see our Active Directory Security service.


