About The Domain Diaries
Welcome to The Domain Diaries β a collection of real penetration testing stories, focused primarily on Active Directory environments.
What Youβll Find Here
- π Real engagement stories (anonymized, of course)
- π« Kerberos attacks β Golden tickets, silver tickets, Kerberoasting
- π Credential harvesting β Pass-the-hash, NTLM relay, DCSync
- π€οΈ Lateral movement β How attackers pivot through networks
- π‘οΈ Defense insights β What blue teams can learn from red team ops
Who Am I?
A pentester whoβs seen things. Domain Admin things. I write about my experiences to help others learn β both attackers looking to improve their craft and defenders trying to understand the threats they face.
Disclaimer
All stories are from authorized penetration testing engagements. Names, companies, and identifying details have been changed. Donβt do illegal stuff. Get permission. Be ethical.
C:\> net user attacker /domain
The request will be processed at a domain controller...
Stay curious. Stay ethical.