Skip to content

Services, Wiki-Artikel und Blog-Beiträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen

Active Directory Attacks: Kerberoasting, Golden Ticket

Learn the most common Active Directory attack techniques - Kerberoasting, Pass-the-Hash, Golden Ticket - and how to defend your Windows infrastructure.

Summary: A method for cracking passwords or encryption keys by systematically trying every possible combination. Online brute-force attacks target login forms, while offline brute-force attacks crack stolen hashes. Mitigation: MFA, account lockout, rate limiting, and strong passwords.

Sources & References

  1. [1] Microsoft - Active Directory Security Best Practices - Microsoft
  2. [2] MITRE ATT&CK - Enterprise Techniques - MITRE Corporation
  3. [3] BloodHound - Attack Path Analysis - SpecterOps
  4. [4] BSI - Absicherung von Active Directory - Bundesamt für Sicherheit in der Informationstechnik

Questions about this topic?

Our experts advise you free of charge and without obligation.

Free Consultation

About the Author

Vincent Heinen
Vincent Heinen

Head of Offensive Services

E-Mail

M.Sc. in IT Security with more than 5 years of experience in offensive security analysis. Leads the delivery of penetration tests, specializing in web applications, network infrastructure, reverse engineering and hardware security. Responsible for several responsible disclosures.

OSCP+ OSCP OSWP OSWA
This article was last edited on 03/29/2026. Responsible: Vincent Heinen, Head of Offensive Services at AWARE7 GmbH. License: CC BY 4.0 - free use with attribution: "AWARE7 GmbH, https://a7.de"

Rufen Sie uns an

Mo-Fr, 8:00-17:00 Uhr - persönlich und unverbindlich.

0209 8830 6764
Jetzt anrufen