All Modules WINDOWS

Windows · Complete Guide

Eleven chapters covering the OS-level knowledge behind most enterprise attacks: process and session architecture, Active Directory fundamentals, Kerberos and NTLM authentication, tokens and privilege escalation, the registry, Windows event logging and Sysmon, common attack techniques, Active Directory attack detection, PowerShell logging, AD Certificate Services attacks, and delegation abuse with modern AD hardening. Built for analysts who see Windows Event IDs and process trees daily but have never had to explain the internals behind them.

11 CHAPTERS
~16 HRS CONTENT
BEGINNER to ADVANCED SKILL RANGE
SEP 2026 LAST UPDATED
MODULE PROGRESS 0 / 11 chapters complete
Active Directory Kerberos NTLM tokens registry Sysmon Kerberoasting DCSync

ALL CHAPTERS

/
01
BEGINNER 30 min

Windows Architecture & the Process Model

Processes, threads, and handles, how sessions and integrity levels work, and the process tree relationships that show up in every EDR alert and every Sysmon log.

processes integrity levels sessions
02
BEGINNER 35 min

Active Directory Fundamentals

Domains, forests, organizational units, group policy, and trusts, the directory structure that almost every enterprise attack eventually has to navigate.

Active Directory GPOs trusts
03
INTERMEDIATE 40 min

Authentication: NTLM, Kerberos & Tickets

The full Kerberos ticket exchange step by step, how NTLM differs and why it is weaker, and why understanding both is the prerequisite for every credential attack in this module.

Kerberos NTLM TGT/TGS
04
INTERMEDIATE 35 min

Tokens, Privileges & Access Control

Access tokens and SIDs, how ACLs actually grant or deny access, privilege escalation fundamentals, and what UAC is really checking when it prompts.

access tokens SIDs UAC
05
INTERMEDIATE 30 min

The Registry

Registry structure and hives, how the registry stores configuration and identity data, and the specific keys attackers abuse for persistence, from Run keys to services.

registry hives persistence Run keys
06
INTERMEDIATE 35 min

Windows Event Logging & Sysmon

The Security log Event IDs that actually matter for detection, why default logging is not enough, and how to configure and read Sysmon for the visibility Windows does not give you by default.

Event IDs Sysmon Security log
07
INTERMEDIATE 40 min

Common Windows Attack Techniques

Credential dumping from LSASS, lateral movement over PsExec/WMI/WinRM, and the persistence mechanisms that follow directly from the process and registry chapters.

credential dumping lateral movement persistence
08
ADVANCED 45 min

Active Directory Attacks & Detection

Kerberoasting, DCSync, and Golden/Silver ticket attacks explained mechanically, plus the detection strategy for each.

Kerberoasting DCSync golden ticket
09
INTERMEDIATE 40 min

PowerShell Security & Logging

Why PowerShell dominates post-exploitation, its logging types, AMSI, Constrained Language Mode, and the Event IDs a SOC analyst actually monitors.

PowerShell AMSI script block logging
10
ADVANCED 45 min

Active Directory Certificate Services Attacks

AD CS misconfigurations from the ESC attack family, certificate template abuse, and NTLM relay to certificate enrollment.

AD CS ESC1-8 certificate abuse
11
ADVANCED 40 min

Delegation Abuse & Modern AD Hardening

Unconstrained, constrained, and resource-based delegation abuse, plus LAPS, gMSA, and the tiered administration model that closes the module.

delegation LAPS tiered admin

PREREQUISITES & OUTCOMES

WHAT YOU SHOULD KNOW

  • The Fundamentals module, or equivalent comfort with core security vocabulary (threat, vulnerability, attack surface)
  • The Networking module, or comfort with client-server communication, since Kerberos and NTLM are network authentication protocols
  • General comfort using Windows as an end user; no prior systems administration or Active Directory experience required

WHAT YOU WILL KNOW AFTER

  • How Windows processes, sessions, and integrity levels actually work, and what a process tree in an EDR alert is really showing you
  • How Active Directory is structured, and why domain admin is the single most valuable target in most enterprise networks
  • The full Kerberos ticket exchange and how NTLM differs, well enough to understand why Kerberoasting and pass-the-hash work
  • How tokens, SIDs, and ACLs govern access, and the mechanics behind common privilege escalation
  • Which registry keys and Event IDs actually matter for persistence detection, and how to configure Sysmon for real visibility
  • How Kerberoasting, DCSync, and Golden/Silver ticket attacks work mechanically, and what each looks like in logs

RECOMMENDED TOOLS

H3AD-SEC tools that pair directly with this module's content.