
The red-team playbook, searchable.
Verified command references, Active Directory & AD CS attack chains, CTF write-ups and notes — all in one fast place. Hit Ctrl K to search anything.
Recent Posts
View allKerberoasting: From a Standard Domain User to Cracked Service Accounts
A hands-on, end-to-end guide to Kerberoasting — how it works, every command (enumerate, request, extract, crack), targeted Kerberoasting against users with no SPN, plus the encryption-downgrade trick, detection, and hardening.
BloodHound Cheat Sheet — Collection & Cypher Queries
End-to-end BloodHound reference — spin up BloodHound CE, collect with SharpHound / bloodhound-python / NetExec, mark owned nodes, and run the Cypher queries that actually find paths to Domain Admin.
Active Directory Attack Paths: Foothold to Domain Admin
The reliable AD kill chain — foothold to Domain Admin — with verified impacket / NetExec / Certipy / bloodyAD commands, Windows (Rubeus) equivalents, BloodHound path-finding, ACL abuse, DCSync, and golden-ticket persistence.