01 AD Active-Directory_cheat_sheet 2026-08-10 02 ENUM Anonymous Null Testing 2026-08-10 03 AD Attack #1 — Password Spraying 2026-08-10 04 AD Attack #11 — Golden Ticket Attack 2026-08-10 05 AD Attack #13 — Diamond Ticket Attack 2026-08-10 06 AD Attack #14 — Sapphire Ticket Attack 2026-08-10 07 AD Attack #19 — GenericAll Abuse 2026-08-10 08 AD Attack #2 — Kerberoasting 2026-08-10 09 AD Attack #21 — WriteDACL Abuse 2026-08-10 10 AD Attack #23 — ForceChangePassword Abuse 2026-08-10 11 AD Attack #27 — ESC1 SAN Specification in Template 2026-08-10 12 AD Attack #28 — ESC2 Any Purpose EKU No EKU 2026-08-10 13 AD Attack #29 — ESC3 Certificate Request Agent 2026-08-10 14 AD Attack #30 — ESC4 Template Write Permissions 2026-08-10 15 AD Attack #32 — ESC7 Vulnerable CA Officer Permissions 2026-08-10 16 AD Attack #43 — PrintNightmare (CVE-2021-34527) 2026-08-10 17 AD Attack #44 — noPAC Sam-the-Admin (CVE-2021-42278 42287) 2026-08-10 18 AD Attack #45 — Token Impersonation (SeImpersonatePrivilege) 2026-08-10 19 AD Attack #49 — Abusing Backup Operators Group 2026-08-10 20 AD Attack #52 — Abusing Print Operators Group 2026-08-10 21 AD Attack #54 — PsExec Remote Execution via SMB 2026-08-10 22 AD Attack #60 — Token Stealing and Impersonation 2026-08-10 23 AD Attack #61 — Skeleton Key Attack 2026-08-10 24 AD Attack #62 — DSRM Backdoor Abuse 2026-08-10 25 AD Attack #63 — SID History Injection 2026-08-10 26 AD Attack #68 — Cross-Domain Trust Abuse (SID History) 2026-08-10 27 AD Attack #71 — PAM Trust Abuse (Bastion Forest) 2026-08-10 28 AD Attack #73 — gMSA Password Extraction 2026-08-10 29 AD Attack #74 — Azure AD Connect Credential Extraction 2026-08-10 30 AD Attack #76 — MSSQL Server and Linked Server Abuse 2026-08-10 31 AD Attack #78 — AD Recycle Bin Object Abuse 2026-08-10 32 AD Certificate Persistence — Certifried (CVE-2022-26923) 2026-08-10 33 AD DPERSIST3 — Malicious Misconfiguration (ACL Backdoor) 2026-08-10 34 AD ESC1 — SAN Specification in Template 2026-08-10 35 AD ESC13 — Issuance Policy OID Group Link 2026-08-10 36 AD ESC14 — Weak Explicit Certificate Mapping 2026-08-10 37 AD ESC17 — ADCS Certificate Spoofing to Attack HTTPS-Enabled WSUS Clients 2026-08-10 38 AD ESC3 — Misconfigured Enrollment Agent Templates 2026-08-10 39 AD ESC4 — Vulnerable Certificate Template Access Control 2026-08-10 40 NIX Find Command 2026-08-10 41 AD Golden Certificate Attack — DPERSIST1 2026-08-10 42 FLOW HTB Attack Flow Playbook 2026-08-27 43 PRIV Linux Privilege Escalation 2026-08-09 44 FLOW Most Used Commands 2026-07-18 45 FLOW Potato Attacks — SeImpersonate to SYSTEM 2026-09-17 46 AD PowerView and PowerUp Deep-Dive 2026-08-29 47 AD SharpHound_ 2026-08-10 48 AD THEFT3 — Machine Certificate Theft via DPAPI 2026-08-10 49 ENUM Windows Enumeration 2026-08-10 50 PRIV Windows Privilege Escalation 2026-09-17