Shadow Steps Understanding and Detecting User Impersonation and Lateral Movement in Active Directory
This hands-on, scenario-driven workshop delves into how attackers move stealthily through Active Directory environments using user impersonation and lateral movement techniques. Participants will explore how attackers exploit credentials and trust relationships to expand their access, and how defenders can detect, prevent, and respond to such threats. Through simulated exercises and guided labs, participants will walk through real-world attack paths such as (over)Pass-the-Hash, Kerberoasting, and token impersonation. This hands-on workshop is ideal for Penetration Testers with limited knowledge about AD internals. LEARNING OBJECTIVES: Understand the key mechanisms behind user impersonation in Active Directory. Demonstrate how attackers perform lateral movement via tools and techniques such as: Pass-the-Hash Pass-the-Ticket/Overpass-the-Hash Remote Services Abuse (SMB, WMI, RDP, WinRM)\ SOCKS PTH Kerberoasting Token Impersonation Token Creation PREREQUISITES: Basic understanding of Windows networks and Active Directory Familiarity with common cybersecurity concepts Participants should have an AWS account with appropriate payment methods associated. Participants will need an Ubuntu VM with Terraform and Empire Installed. This workshop supports content and knowledge from SEC565: Red Team Operations and Adversary Emulation. To learn more about this course, explore upcoming sessions, and access your FREE preview, visit https://www.sans.org/sec565 Watch this session unedited and access the presentation slides: https://www.sans.org/webcasts/underst... Learn more about Jean-François Maes: https://www.sans.org/profiles/jeanfra... To check out more from the Offensive Operations curriculum and discover additional free resources, please visit: https://www.sans.org/offensive-operat...

Breaking the Lock: How MFA Can Still Be Defeated

Intro to Kerberos and Common AD Privesc Attacks with Empire

Major Course Update | SEC598 Automate Security with Generative AI

Mastering PE Parsing with WinDbg

Continuous Penetration Testing: Rethinking Offensive Security in an Ever-Changing Threat Landscape

Detecting & Hunting Ransomware Operator Tools: It Is Easier Than You Think!

Pwning Bossware for Fun and Ethics

Social Engineering The Windows Kernel: Finding And Exploiting Token Handling Vulnerabilities

To Phish or Not to Phish: Understanding Modern Attacks and Defenses

How to Detect a Fake Cell Tower Spying on Your Phone (Stingray)

DEF CON 33 - Cash, Drugs, and Guns - Why Your Safes Aren't Safe - Mark Omo, James Rowley

Modern Recon for Red Teams and Pentesters | Jason Haddix

Building Agents with Claude Opus 4 8 Live Demos with Letta

The Biggest Hacking Mystery of Our Time: Shadow Brokers

Purple Teaming Reloaded: AI, Adversaries & the New SEC599

Weaponizing the Algorithm with SEC535

Offensive Security Operations with Attack Surface Management and Continuous Pen Testing

Hackventures with Josh: Better Password Attacks with AI

AirSnitch – How Worried Should You Be?

