Movement
This is a work-in-progress
Below is a checklist to go through when conducting a pentest. Order is irrelevant and many tests require authenticated or admin access. This checklist answers "what to audit on AD?" rather than "how to pwn AD?". A mindmap is in the works for that matter 😉 .
NTLM configuration
Kerberos configuration
Patch management
Access Management (IAM/PAM)
Credentials Management
Domain-level configuration and best-practices
Networking, protocols and services
Active Directory Certificate Services
Last updated