Eleven chapters covering the OS-level knowledge behind most enterprise attacks: process and session architecture, Active Directory fundamentals, Kerberos and NTLM authentication, tokens and privilege escalation, the registry, Windows event logging and Sysmon, common attack techniques, Active Directory attack detection, PowerShell logging, AD Certificate Services attacks, and delegation abuse with modern AD hardening. Built for analysts who see Windows Event IDs and process trees daily but have never had to explain the internals behind them.
No chapters match “”.
Processes, threads, and handles, how sessions and integrity levels work, and the process tree relationships that show up in every EDR alert and every Sysmon log.
Domains, forests, organizational units, group policy, and trusts, the directory structure that almost every enterprise attack eventually has to navigate.
The full Kerberos ticket exchange step by step, how NTLM differs and why it is weaker, and why understanding both is the prerequisite for every credential attack in this module.
Access tokens and SIDs, how ACLs actually grant or deny access, privilege escalation fundamentals, and what UAC is really checking when it prompts.
Registry structure and hives, how the registry stores configuration and identity data, and the specific keys attackers abuse for persistence, from Run keys to services.
The Security log Event IDs that actually matter for detection, why default logging is not enough, and how to configure and read Sysmon for the visibility Windows does not give you by default.
Credential dumping from LSASS, lateral movement over PsExec/WMI/WinRM, and the persistence mechanisms that follow directly from the process and registry chapters.
Kerberoasting, DCSync, and Golden/Silver ticket attacks explained mechanically, plus the detection strategy for each.
Why PowerShell dominates post-exploitation, its logging types, AMSI, Constrained Language Mode, and the Event IDs a SOC analyst actually monitors.
AD CS misconfigurations from the ESC attack family, certificate template abuse, and NTLM relay to certificate enrollment.
Unconstrained, constrained, and resource-based delegation abuse, plus LAPS, gMSA, and the tiered administration model that closes the module.
WHAT YOU SHOULD KNOW
WHAT YOU WILL KNOW AFTER
H3AD-SEC tools that pair directly with this module's content.
The SOC analyst console. See how process trees, Event IDs, and token/privilege fields from this module show up in a real investigation workflow.
Real detection rules for Kerberoasting, DCSync, and credential dumping. See how Chapters 7 and 8's attack mechanics become production queries.
Visual pivot graph for investigations. Map lateral movement and privilege escalation paths once you understand the tokens and trusts that make them possible.
ATT&CK-driven hypothesis platform. Turn this module's AD attack techniques directly into structured hunt hypotheses.