InfoSec Write-ups

A collection of write-ups from the best hackers in the world on topics ranging from bug bounties…

Follow publication

Member-only story

TryHackMe writeup: Attacktive Directory

Aleksey
InfoSec Write-ups
Published in
16 min readMar 14, 2023

Active Directory is a Microsoft service that allows system administrators in medium-sized to large-sized organisations to store information about computer systems as object in a “directory.” This has made way for great convenience, but at the same time has also made way for another vulnerability vector by which to attack an organisation if not secured properly.

“tryhackme” (2020) published a room where they aim to teach their users a very short introduction to hacking Active Directory systems which can hopefully be useful for systems administrators and members of the blue team to secure the overall organisation. In this article, I will discuss my experiences doing this room.

Some image components from Wikimedia Commons (n.d.) and “Zeitgeist” (2023).

Contents at a glance

  1. Background
  2. Procedure
  3. Discussion
  4. End matter
  5. References

Background

Active Directory is a product by Microsoft that “provides the methods for storing directory data and making this data available to network users and administrators” (Foulds et al 2022). One can imagine Active Directory as a central service that is used by system administrators organise networks of Windows PCs for large organisations. This is not just at a local network level — Active Directory can…

Create an account to read the full story.

The author made this story available to Medium members only.
If you’re new to Medium, create a new account to read this story on us.

Or, continue in mobile web

Already have an account? Sign in

Published in InfoSec Write-ups

A collection of write-ups from the best hackers in the world on topics ranging from bug bounties and CTFs to vulnhub machines, hardware challenges and real life encounters. Subscribe to our weekly newsletter for the coolest infosec updates: https://weekly.infosecwriteups.com/

No responses yet

Write a response