Skip to content

Glossary

Plain-language definitions of the Active Directory attack techniques and defenses used across the guides.

A

AD CS ESC1
ESC1 is an Active Directory Certificate Services misconfiguration letting low-privileged users request certificates that impersonate any account.
AD CS ESC8
ESC8 is an AD CS weakness where NTLM authentication is relayed to certificate web enrollment endpoints to obtain a certificate for the victim.
AdminSDHolder
AdminSDHolder is a protected AD object whose ACL is periodically reapplied to privileged accounts, and a common target for persistence.
AS-REP roasting
AS-REP Roasting abuses accounts without Kerberos pre-authentication to obtain crackable authentication data without valid credentials.
Authentication policy silo
An authentication policy silo groups privileged accounts and hosts so those accounts can only obtain Kerberos tickets from approved devices.

B

BloodHound
BloodHound is a graph-based tool that maps Active Directory relationships to reveal attack paths from ordinary users to privileged control.

D

DCSync
DCSync is a technique that abuses AD replication rights to pull password hashes directly from a domain controller without local access.

F

Fine-grained password policy
A fine-grained password policy (PSO) applies different password and lockout rules to specific AD users or groups than the domain default policy.

G

Golden ticket
A Golden Ticket is a forged Kerberos ticket-granting ticket built with a stolen krbtgt hash, granting unlimited domain access.
Group managed service account (gMSA)
A gMSA is an Active Directory account type with an automatically rotated, randomly generated password managed by the domain itself.

H

Honeytoken
A honeytoken is a decoy account, credential or object planted in AD that has no legitimate use, so any interaction with it signals an intruder.

K

Kerberoasting
Kerberoasting is an attack that extracts service account password hashes from Kerberos service tickets for offline cracking.
krbtgt
krbtgt is the built-in AD account whose key signs and encrypts every Kerberos ticket-granting ticket issued by the domain's domain controllers.

L

LAPS
LAPS (Local Administrator Password Solution) gives every Windows machine a unique, rotated local admin password stored securely in AD or Entra ID.
LDAP channel binding
LDAP channel binding cryptographically ties an LDAP session to its TLS channel, preventing relay attacks against LDAP authentication.
LLMNR poisoning
LLMNR poisoning answers broadcast name lookups on the local network to trick Windows hosts into sending NTLM authentication to an attacker.

M

Machine account quota
ms-DS-MachineAccountQuota is the domain setting that lets any authenticated user create up to ten computer accounts in Active Directory by default.

N

NTLM relay
NTLM relay forwards a captured NTLM authentication attempt to another server in real time, authenticating as the victim without their password.

P

Pass-the-hash
Pass-the-Hash is a technique that authenticates using a stolen NTLM password hash directly, without ever knowing the plaintext password.
PetitPotam
PetitPotam is an authentication coercion technique that abuses the MS-EFSR protocol to force a Windows host, often a DC, to authenticate elsewhere.
Privileged access workstation (PAW)
A privileged access workstation is a hardened, dedicated device used only for administrative tasks, isolated from email, browsing and daily work.
Protected Users
Protected Users is a built-in AD security group that forces stronger, non-cacheable authentication for its members to limit credential theft.

R

Resource-based constrained delegation
Resource-based constrained delegation (RBCD) lets a resource define which accounts may impersonate users to it, which attackers can abuse if misconfigured.

S

SID filtering
SID filtering is a trust protection that strips foreign or privileged SIDs from authentication data crossing an Active Directory trust.
SID history
SIDHistory is an AD attribute that keeps an account's old security identifiers after migration so it retains access to legacy resources.
Silver ticket
A Silver Ticket is a forged Kerberos service ticket built with a service account's hash, granting access to that single service.
SMB signing
SMB signing adds a cryptographic signature to every SMB message so tampering and NTLM relay against file and admin shares are detected and rejected.

T

Tier model
The AD tier model separates administration into Tier 0, 1 and 2 by blast radius so privileged credentials never touch less-trusted systems.

U

Unconstrained delegation
Unconstrained delegation lets a server cache and reuse any user's full Kerberos TGT, creating a high-value target for attackers.

Z

Zerologon
Zerologon (CVE-2020-1472) is a critical flaw in the Netlogon protocol that let attackers reset a domain controller's machine password.