Last updated: April 29, 2026
The complete red-team AD chain. Modules 8-17 in AD track covered individual techniques; this is operator playbook.
Path planning
- Initial access (phish, web exploit, valid creds)
- Local recon (BloodHound from compromised host)
- Identify shortest path to DA
- Choose technique per step (Kerberoast → DCSync, or RBCD → ticket forge)
- Execute with OPSEC (silent EDR-evasive techniques)
- Persistence at multiple tiers
- Exfiltrate target objectives
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.