Glossary
Plain-language definitions of the Active Directory attack techniques and defenses used across the guides.
A
- AD CS ESC1
- ESC1 is an Active Directory Certificate Services misconfiguration letting low-privileged users request certificates that impersonate any account.
- AD CS ESC8
- ESC8 is an AD CS weakness where NTLM authentication is relayed to certificate web enrollment endpoints to obtain a certificate for the victim.
- AdminSDHolder
- AdminSDHolder is a protected AD object whose ACL is periodically reapplied to privileged accounts, and a common target for persistence.
- AS-REP roasting
- AS-REP Roasting abuses accounts without Kerberos pre-authentication to obtain crackable authentication data without valid credentials.
- Authentication policy silo
- An authentication policy silo groups privileged accounts and hosts so those accounts can only obtain Kerberos tickets from approved devices.
B
- BloodHound
- BloodHound is a graph-based tool that maps Active Directory relationships to reveal attack paths from ordinary users to privileged control.
D
- DCSync
- DCSync is a technique that abuses AD replication rights to pull password hashes directly from a domain controller without local access.
F
- Fine-grained password policy
- A fine-grained password policy (PSO) applies different password and lockout rules to specific AD users or groups than the domain default policy.
G
- Golden ticket
- A Golden Ticket is a forged Kerberos ticket-granting ticket built with a stolen krbtgt hash, granting unlimited domain access.
- Group managed service account (gMSA)
- A gMSA is an Active Directory account type with an automatically rotated, randomly generated password managed by the domain itself.
H
- Honeytoken
- A honeytoken is a decoy account, credential or object planted in AD that has no legitimate use, so any interaction with it signals an intruder.
K
- Kerberoasting
- Kerberoasting is an attack that extracts service account password hashes from Kerberos service tickets for offline cracking.
- krbtgt
- krbtgt is the built-in AD account whose key signs and encrypts every Kerberos ticket-granting ticket issued by the domain's domain controllers.
L
- LAPS
- LAPS (Local Administrator Password Solution) gives every Windows machine a unique, rotated local admin password stored securely in AD or Entra ID.
- LDAP channel binding
- LDAP channel binding cryptographically ties an LDAP session to its TLS channel, preventing relay attacks against LDAP authentication.
- LLMNR poisoning
- LLMNR poisoning answers broadcast name lookups on the local network to trick Windows hosts into sending NTLM authentication to an attacker.
M
- Machine account quota
- ms-DS-MachineAccountQuota is the domain setting that lets any authenticated user create up to ten computer accounts in Active Directory by default.
N
- NTLM relay
- NTLM relay forwards a captured NTLM authentication attempt to another server in real time, authenticating as the victim without their password.
P
- Pass-the-hash
- Pass-the-Hash is a technique that authenticates using a stolen NTLM password hash directly, without ever knowing the plaintext password.
- PetitPotam
- PetitPotam is an authentication coercion technique that abuses the MS-EFSR protocol to force a Windows host, often a DC, to authenticate elsewhere.
- Privileged access workstation (PAW)
- A privileged access workstation is a hardened, dedicated device used only for administrative tasks, isolated from email, browsing and daily work.
- Protected Users
- Protected Users is a built-in AD security group that forces stronger, non-cacheable authentication for its members to limit credential theft.
R
- Resource-based constrained delegation
- Resource-based constrained delegation (RBCD) lets a resource define which accounts may impersonate users to it, which attackers can abuse if misconfigured.
S
- SID filtering
- SID filtering is a trust protection that strips foreign or privileged SIDs from authentication data crossing an Active Directory trust.
- SID history
- SIDHistory is an AD attribute that keeps an account's old security identifiers after migration so it retains access to legacy resources.
- Silver ticket
- A Silver Ticket is a forged Kerberos service ticket built with a service account's hash, granting access to that single service.
- SMB signing
- SMB signing adds a cryptographic signature to every SMB message so tampering and NTLM relay against file and admin shares are detected and rejected.
T
- Tier model
- The AD tier model separates administration into Tier 0, 1 and 2 by blast radius so privileged credentials never touch less-trusted systems.
U
- Unconstrained delegation
- Unconstrained delegation lets a server cache and reuse any user's full Kerberos TGT, creating a high-value target for attackers.
Z
- Zerologon
- Zerologon (CVE-2020-1472) is a critical flaw in the Netlogon protocol that let attackers reset a domain controller's machine password.