← All walkthroughs

Phishing to Domain Admin

The canonical Active Directory attack path: a phishing foothold on a workstation, escalated through credential theft and Kerberos abuse to full domain dominance.

On-prem Active Directory Intermediate Active DirectoryWindowsPhishingKerberos
Authorized testing only. This is a conceptual, defensive-aware walkthrough that maps an attack path to MITRE ATT&CK, detection and mitigation, and links to references for the detail. It is not a copy-paste playbook. Use it only against systems you own or are explicitly permitted to test.

Scenario

An authorized red-team engagement with permission to phish a defined list of employees. The objective is to show how a single click can lead to Domain Admin, and where the blue team could have cut the chain.

  1. 1

    Reconnaissance

    Build a target list and pretext

    Collect in-scope employee email addresses and public details to craft a believable, authorized phishing pretext and identify likely-vulnerable roles.

    Detection

    OSINT is largely invisible, but lookalike-domain registration and inbound reconnaissance to the mail gateway can be monitored.

    Mitigation

    Security-awareness training, DMARC/DKIM/SPF enforcement, and monitoring for newly registered lookalike domains.

  2. 2

    Initial Access

    Land code execution via phishing

    Deliver the agreed phishing lure (attachment or link) to obtain execution on a user workstation, staying strictly within the approved target list and payload rules of engagement.

    Detection

    Mail-gateway detonation, EDR on attachment/macro execution, and proxy logs for the delivery domain.

    Mitigation

    Block risky attachment types, disable Office macros from the internet, use MFA, and sandbox links at the gateway.

  3. 3

    Execution

    Establish a stable agent

    Convert the initial execution into a resilient command-and-control channel using the host's own scripting interpreter, with care to keep the agent in scope and recoverable.

    Detection

    Script-block logging, suspicious parent/child process trees, and beaconing patterns in network telemetry.

    Mitigation

    Constrained-language mode, application control (WDAC/AppLocker), and egress filtering with TLS inspection.

  4. 4

    Credential Access

    Harvest credentials from the first host

    Recover cached credentials and tokens from the workstation to obtain a domain user context to work from.

    Detection

    LSASS access by non-system processes is a high-fidelity EDR alert; Credential Guard blocks the classic technique entirely.

    Mitigation

    Enable Credential Guard, run EDR with LSASS protection, and restrict local admin rights.

    References mimikatz · lsassy
  5. 5

    Discovery

    Map the domain and find a path to privilege

    Enumerate users, groups, computers and trust relationships, then analyse the data to find the shortest path from the current principal to a high-value target.

    Detection

    Large LDAP queries and SAMR enumeration from a workstation are detectable; honeypot objects catch indiscriminate collection.

    Mitigation

    Tier the AD administration model, restrict LDAP reconnaissance, and deploy deceptive/honeytoken objects.

  6. 6

    Credential Access

    Crack a service account via Kerberoasting

    Request service tickets for accounts with SPNs and crack them offline to recover a service-account password — often a route to higher privilege.

    Detection

    Spikes of Kerberos TGS requests (especially RC4) for many SPNs are a well-known hunting signal.

    Mitigation

    Use group-managed service accounts with long random passwords, enforce AES, and alert on bulk TGS requests.

  7. 7

    Lateral Movement

    Move to a privileged host

    Reuse recovered hashes or tickets to authenticate to systems where the compromised account has rights, hopping toward a host where a Domain Admin is logged on.

    Detection

    Anomalous logon types, pass-the-hash patterns, and lateral authentication from a workstation to many hosts.

    Mitigation

    Enforce the AD tiering model, deny local-admin reuse (LAPS), and block workstation-to-workstation traffic.

  8. 8

    Domain Dominance

    Compromise the domain and establish persistence

    With Domain Admin-equivalent rights, demonstrate replication of directory secrets and (where authorized) a forged ticket to prove durable control — then document everything for clean-up.

    Detection

    Non-DC hosts performing directory replication (DCSync) is a critical alert; golden-ticket anomalies show up with careful Kerberos logging.

    Mitigation

    Restrict replication rights, monitor for DCSync from non-DCs, and rotate the krbtgt account twice after any suspected compromise.

Key takeaways

  • The path from a single phished user to Domain Admin is short on a flat, untiered AD.
  • Credential Guard, AD tiering and LAPS individually break several links in this chain.
  • Kerberoasting and DCSync are noisy if you are logging Kerberos and directory replication — instrument for them.