Skip to content

aleemladha/SANS-Workshop-LateralMovement

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

15 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

SANS Workshop: Shadow Steps: Understanding and Detecting User Impersonation and Lateral Movement in Active Directory

This hands-on, scenario-driven workshop delves into how attackers move stealthily through Active Directory environments using user impersonation and lateral movement techniques. Participants will explore how attackers exploit credentials and trust relationships to expand their access, and how defenders can detect, prevent, and respond to such threats.

Through simulated exercises and guided labs, participants will walk through real-world attack paths such as (over)Pass-the-Hash, Kerberoasting, and token impersonation.

Learning Objectives:

  • Understand the key mechanisms behind user impersonation in Active Directory.
  • Demonstrate how attackers perform lateral movement via tools and techniques such as:
  • Pass-the-Hash
  • Pass-the-Ticket/Overpass-the-Hash
  • Remote Services Abuse (SMB, WMI, RDP, WinRM)\
  • SOCKS PTH
  • Kerberoasting
  • Token Impersonation
  • Token Creation
  • This hands-on workshop is ideal for Penetration Testers with limited knowledge about AD internals.

Access the workbook here:

Submit a PR to add your writeup to this list :)

Install dependencies

No automatic install is provided as it depend of your package manager and distribution. Here are some install command lines are given for ubuntu.

Installation

Special Thanks to

About

No description, website, or topics provided.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors