Attack path
From weak password policy to full domain compromise — the most common real-world AD attack chain.
Complete all lessons, quizzes, and flashcards in this attack path to earn the Password Spray Campaign badge.
You have a low-privilege domain account and suspect the organization has a weak password policy. Walk through the full chain: policy recon, credential spraying, memory harvesting, lateral movement, and domain compromise.
Pass the Hash is a lateral movement technique that uses a stolen NTLM password hash to authenticate as a user without knowing the plaintext password. This lesson explains why the attack works, what material is needed, where it fits in post-compromise movement, and how to explain the significance of NTLM hash reuse clearly in interviews, reports, and stakeholder conversations.
Study this technique →0 of 6 decks reviewed
0 of 6 quizzes taken
You completed a full end-to-end compromise walkthrough — from reconnaissance through domain takeover. Upgrade to unlock the remaining premium attack paths and continue building interview-ready attack chains.