Movement

This is a work-in-progress

Below is a checklist to go through when conducting a pentest. Order is irrelevant and many tests require authenticated or admin access. This checklist answers "what to audit on AD?" rather than "how to pwn AD?". A mindmap is in the works for that matter 😉 .

NTLM configuration

Kerberos configuration

Patch management

Access Management (IAM/PAM)

Credentials Management

Domain-level configuration and best-practices

Networking, protocols and services

Active Directory Certificate Services

Last updated