Difficulty:
Focus:
Status:

3 labs available

AdvancedRed Team

Corporate AD Compromise

End-to-end Active Directory attack simulation in a realistic enterprise environment

A fully automated four-machine Active Directory environment modelling a mid-size corporate network. Designed for red teamers who want to practice the complete attack chain — from initial foothold to domain dominance — without spending hours on manual infrastructure setup.

Scope & Goals

  • Gain initial foothold through credential abuse and misconfiguration exploitation
  • Enumerate the domain using BloodHound and manual LDAP techniques
  • Abuse Kerberos delegation, ACL misconfigurations, and LAPS weaknesses
  • Achieve domain compromise via DCSync and Golden Ticket attacks
Duration:~6 hMachines:4 VMsOS:Windows Server 2025Provider:VMware / VirtualBox

What You'll Learn

AS-REP RoastingKerberoastingPass-the-HashPass-the-TicketDCSyncGolden TicketBloodHoundLAPS BypassACL Abuse

For Who

Red TeamersOSCP / CRTO CandidatesPentestersSecurity Researchers

Contains

Automated Deployment
Red Team Scenarios
Blue Team / SOC
Report Sample

Attacks

AS-REP RoastingKerberoastingPass-the-HashDCSyncGolden Ticket

Phases

ReconnaissanceInitial AccessPrivilege EscalationLateral MovementDomain Dominance
ExpertPurple Team

Purple Team AD Exercise

Detection engineering meets adversary simulation — every attack generates a detection rule

A six-machine environment pairing a full Sysmon + Splunk stack on the blue side with a structured kill chain on the red side. Every TTP executed produces log artifacts; every artifact maps to a MITRE ATT&CK technique and a Sigma detection rule. Built for teams that want to close the gap between attack and detection.

Scope & Goals

  • Execute a structured adversary emulation plan across the full kill chain
  • Capture and triage Sysmon, Security, and PowerShell logs in Splunk
  • Write, tune, and validate Sigma detection rules against captured telemetry
  • Produce a detection gap analysis and adversary emulation report
Duration:~12 hMachines:6 VMsOS:WS 2025 + Kali LinuxProvider:VMware / VirtualBox

What You'll Learn

Threat HuntingSigma RulesSIEM TuningMITRE ATT&CK MappingSysmon ConfigDetection Gap AnalysisLog AnalysisWMI Lateral Movement

For Who

Blue TeamersSOC AnalystsDetection EngineersThreat HuntersSecurity Researchers

Contains

Automated Deployment
Red Team Scenarios
Blue Team / SOC
Report Sample

Attacks

Credential DumpingLDAP EnumerationWMI Lateral MovementPass-the-TicketKerberoasting

Phases

Emulation PlanningAttack ExecutionLog CollectionDetection WritingGap AnalysisReporting
IntermediateBlue Team
Coming Soon

AD Hardening & Audit

Harden a freshly deployed domain against the most common Active Directory attacks

A three-machine domain pre-loaded with the most commonly exploited AD misconfigurations — unconstrained delegation, weak ACLs, default password policies, and missing tiering. Your job is to find, fix, and verify each gap before a simulated red team validation suite scores.

Scope & Goals

  • Identify misconfigurations using native tools and open-source auditors
  • Apply hardening controls and Group Policy changes
  • Verify fixes hold against a scripted red team validation suite
  • Document changes in a structured remediation report
Duration:~4 hMachines:3 VMsOS:Windows Server 2025Provider:VMware / VirtualBox

What You'll Learn

AD AuditingGroup PolicyTiered Admin ModelDelegation HardeningACL ReviewPassword PolicyLAPS DeploymentAudit Logging

For Who

SysadminsBlue TeamersIT Security EngineersCompliance Teams

Contains

Automated Deployment
Red Team Scenarios
Blue Team / SOC
Report Sample

Phases

AuditIdentificationRemediationValidationReporting