Active Directory Attack Paths
Move through a Windows domain like an operator, not a tourist.
Profile the domain, identify a realistic attack chain, and reach the crown jewels without losing operational context.
+400 XP
Capture the domain-admin proof
Domain compromise proof, path graph, and priority remediation list.
Launch Mission
Public testers can step into the live browser sandbox immediately. The launch path now runs as a checkpoint mission loop with verification, reward drops, and sealed future stages.
Boss Fight
Capture the domain-admin proof
Member Route
/app/labs/ad-attack-paths
Confirm the domain foothold
Before touching the directory, verify which principal the workstation actually gave you.
Enumerate service accounts
The mission reward here is the roastable account name, not the raw command output itself.
Use the recovered material
A successful pivot should land you on a higher-value account, not just another shell window.
Confirm the elevated path
Read the group evidence like an attacker path graph. The key clue is the privileged group, not the full wall of output.
Capture the domain-admin proof
End the chain with a concrete artifact from the highest-value context you reached.
Completion Unlock
Domain compromise proof, path graph, and priority remediation list.
Use BloodHound data to prioritize lateral movement.
Practice credential abuse in a controlled enterprise lab.
Turn AD findings into an interview-ready attack narrative.
Why This Mission Matters
Use BloodHound data to prioritize lateral movement.
Continuity
Sign in after launch to preserve notes, checkpoints, streaks, and your recruiter-facing proof history.