Labs / Windows
Public MissionAdvancedLv.490 min

Active Directory Attack Paths

Move through a Windows domain like an operator, not a tourist.

Profile the domain, identify a realistic attack chain, and reach the crown jewels without losing operational context.

Reward

+400 XP

Boss Objective

Capture the domain-admin proof

Proof Artifact

Domain compromise proof, path graph, and priority remediation list.

Mission Launch

Launch Mission

Public testers can step into the live browser sandbox immediately. The launch path now runs as a checkpoint mission loop with verification, reward drops, and sealed future stages.

Reward Preview89%

Boss Fight

Capture the domain-admin proof

Member Route

/app/labs/ad-attack-paths

Objective Chain
Navigate a real Active Directory environment. Enumerate users, exploit Kerberoasting, perform lateral movement, and achieve domain compromise.
Mission Completion Preview0 / 5
1

Confirm the domain foothold

Before touching the directory, verify which principal the workstation actually gave you.

Domain foothold logged
2

Enumerate service accounts

The mission reward here is the roastable account name, not the raw command output itself.

Roast target found
3

Use the recovered material

A successful pivot should land you on a higher-value account, not just another shell window.

Pivot landed
4

Confirm the elevated path

Read the group evidence like an attacker path graph. The key clue is the privileged group, not the full wall of output.

DA path exposed
5

Capture the domain-admin proof

End the chain with a concrete artifact from the highest-value context you reached.

DA proof secured
Proof of Skill

Completion Unlock

Domain compromise proof, path graph, and priority remediation list.

Use BloodHound data to prioritize lateral movement.

Practice credential abuse in a controlled enterprise lab.

Turn AD findings into an interview-ready attack narrative.

KerberoastingBloodHoundPass-the-HashDCSync
Mission Intel
Segmented AD forest with workstation foothold and common enterprise controls.

Why This Mission Matters

Use BloodHound data to prioritize lateral movement.

Continuity

Sign in after launch to preserve notes, checkpoints, streaks, and your recruiter-facing proof history.

    Active Directory Attack Paths | Kyvera Labs