Introduction to Active Directory Fundamental
Active Directory (AD) is present in the majority of corporate environments. Due to its many features and complexity, it presents a vast attack surface. To be successful as penetration testers and information security professionals, we must have a firm understanding of Active Directory fundamentals, AD structures, functionality, common AD flaws, misconfigurations, and defensive measures.
Understanding Active Directory (AD) functionality, schema, and protocols used to ensure authentication, authorization, and accounting within a domain is key to ensuring the proper operation and security of our domains. This module will cover many different terms, objects, protocols, and security implementations about Active Directory, focusing on the core concepts needed to move into later modules focused on enumerating and attacking AD environments.
In this module, we will:
- Examine the history of Active Directory
- Define commonly used terms
- Examine AD objects and structures
- Discuss the authentication protocols used
- Gain an understanding of the difference between rights and privileges
- Practice executing common AD management tasks
This module is broken into sections with accompanying hands-on exercises to practice each of the tactics and techniques we cover. The module ends with a practical hands-on guided lab to reinforce your understanding of the various topic areas.
As you work through the module, you will see example commands and command output for the various topics introduced. It is worth reproducing as many of these examples as possible to reinforce further the concepts presented in each section. You can do this in the target host provided in the interactive sections or your virtual machine.
You can start and stop the module at any time and pick up where you left off. There is no time limit or "grading," but you must complete all of the exercises and the skills assessment to receive the maximum number of cubes and have this module marked as complete in any paths you have chosen.
The module is classified as "Fundamental" in skill level. It assumes a basic knowledge of the Windows command line and operating system fundamentals and a fundamental understanding of information security principles.
A firm grasp of the following modules can be considered prerequisites for successful completion of this module:
- Introduction to Academy
- Getting Started
- Introduction to Networking
- Windows Fundamentals
- Why Active Directory?
- Active Directory Research Over the Years
- Active Directory Structure
- Active Directory Terminology
- Active Directory Objects
- Active Directory Functionality
- Kerberos, DNS, LDAP, MSRPC
- NTLM Authentication
- User and Machine Accounts
- Active Directory Groups
- Active Directory Rights and Privileges
- Security in Active Directory
- Examining Group Policy
- AD Administration: Guided Lab Part I
- AD Administration: Guided Lab Part II
- Wrapping It Up
This module progresses you towards the following Paths
Easy 147 Sections
Cubes Required: 150
Information Security is a field with many specialized and highly technical disciplines. Job roles like Penetration Tester & Information Security Analyst require a solid technical foundational understanding of core IT & Information Security topics. This skill path is made up of modules that will assist learners in developing &/or strengthening a foundational understanding before proceeding with learning the more complex security topics. Every long-standing building first needs a solid foundation. Welcome to Information Security Foundations.
Fundamental 8 Sections
This module is recommended for new users. It allows users to become acquainted with the platform and the learning process.Learning Process
Fundamental 20 Sections
The learning process is one of the essential and most important components that is often overlooked. This module does not teach you techniques to learn but describes the process of learning adapted to the field of information security. You will learn to understand how and when we learn best and increase and improve your learning efficiency greatly.Setting Up
Fundamental 9 Sections
This module covers topics that will help us be better prepared before conducting penetration tests. Preparations before a penetration test can often take a lot of time and effort, and this module shows how to prepare efficiently.Linux Fundamentals
Fundamental 18 Sections
This module covers the fundamentals required to work comfortably with the Linux operating system and shell.Windows Fundamentals
Fundamental 14 Sections
This module covers the fundamentals required to work comfortably with the Windows operating system.Introduction to Bash Scripting
Easy 10 Sections
This module covers the basics needed for working with Bash scripts to automate tasks on Linux systems. A strong grasp of Bash is a fundamental skill for anyone working in a technical information security role. Through the power of automation, we can unlock the Linux operating system's full potential and efficiently perform habitual tasks.Introduction to Networking
Fundamental 12 Sections
As an information security professional, a firm grasp of networking fundamentals and the required components is necessary. Without a strong foundation in networking, it will be tough to progress in any area of information security. Understanding how a network is structured and how the communication between the individual hosts and servers takes place using the various protocols allows us to understand the entire network structure and its network traffic in detail and how different communication standards are handled. This knowledge is essential to create our tools and to interact with the protocols.Intro to Network Traffic Analysis
Medium 15 Sections
Network traffic analysis is used by security teams to monitor network activity and look for anomalies that could indicate security and operational issues. Offensive security practitioners can use network traffic analysis to search for sensitive data such as credentials, hidden applications, reachable network segments, or other potentially sensitive information "on the wire." Network traffic analysis has many uses for attackers and defenders alike.Introduction to Active Directory
Fundamental 16 Sections
Active Directory (AD) is present in the majority of corporate environments. Due to its many features and complexity, it presents a vast attack surface. To be successful as penetration testers and information security professionals, we must have a firm understanding of Active Directory fundamentals, AD structures, functionality, common AD flaws, misconfigurations, and defensive measures.Introduction to Web Applications
Fundamental 17 Sections
In the Introduction to Web Applications module, you will learn all of the basics of how web applications work and begin to look at them from an information security perspective.Web Requests
Fundamental 8 Sections
This module introduces the topic of HTTP web requests and how different web applications utilize them to communicate with their backends.