> For the complete documentation index, see [llms.txt](https://blog.securescape.cc/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://blog.securescape.cc/offensive-security/red-team/active-directory-wip/ad-lab.md).

# AD Lab

* 2 Forest
  * tradebank.grow (Forest 1)
    * us.tradebank.grow (Inbound)
  * bizpartner.com (Forest 2 - Two way trust)
* 2 Child Domains
* Linux
* Attack Vectors
  * Password in user description
  * ACLs
  * Delegations
  * ADCS
  * MSSQL
  * SID Hopping
  * Cross Forest
  * Service Abuse (Unquoted Service Path)
* FIX THE GRAPH NERD

<img src="/files/31AQnUvxudMOkmtymOp5" alt="" class="gitbook-drawing">
