← All Lessons
Premium
TechniqueActive Directory
ACE-Based Domain Persistence
Once an attacker reaches high privilege in Active Directory, they can plant durable backdoors by editing the access control entries (ACEs) on key objects rather than holding a password. This lesson explains why ACE-based persistence survives credential resets, what objects are targeted, and how to communicate the risk clearly in interviews, reports, and stakeholder conversations.
Sign in or upgrade to unlock the full premium library.
What you'll learn
- Access Control Entry (ACE)
- AdminSDHolder / SDProp
- DCSync rights
- Security descriptor backdoor
- msDS-AllowedToDelegateTo
- Persistence vs. access
What premium includes
- All 68 lessons: AD techniques, professional skills, each with interview answers and study kits
- Complete study kit for every lesson: quizzes, flashcards, and briefs
- Every learning track with full structured progression
- All 12 attack paths: full compromise walkthroughs for interviews and reports
- New lessons and attack paths added regularly