Table of contents Darth Sidious GETTING STARTED Getting started External network access to Domain Admin Intro to Windows hashes Building a lab Building a lab Preparing Kali Building a small lab Building a lab with ESXI and Vagrant Cuckoo malware analysis lab Initial access Password spraying Initial access through exchange ENUMERATION Powershell BloodHound PowerView Azure enumeration Execution Pass the hash Responder with NTLM relay and Empire DeathStar CrackMapExec Privilege escalation Mimikatz Token Impersonation Juicy Potato ALPC bug 0day Defense evasion Bypassing Applocker and Powershell contstrained language mode From RDS app to Empire shell Stealth OTHER Link encyclopedia Writeups lkylabs v1 War stories Domain admin in 30 minutes Credential access Password cracking and auditing Command & Control SILENTTRINITY