← All Lessons
Premium

TechniqueActive Directory

Shadow Credentials

Shadow Credentials exploits write access to an AD object's msDS-KeyCredentialLink attribute to register an attacker-controlled public key, enabling the attacker to authenticate as that object using Kerberos PKINIT without knowing the account's password. This lesson explains why the technique works, what preconditions matter, what the attacker gains, and how to communicate the risk clearly in interviews, reports, and stakeholder conversations.

Sign in or upgrade to unlock the full premium library.

What you'll learn

  • msDS-KeyCredentialLink
  • PKINIT
  • No password change
  • Persistence
  • Computer accounts as targets
  • Stealthier than password reset

What premium includes

  • All 68 lessons: AD techniques, professional skills, each with interview answers and study kits
  • Complete study kit for every lesson: quizzes, flashcards, and briefs
  • Every learning track with full structured progression
  • All 12 attack paths: full compromise walkthroughs for interviews and reports
  • New lessons and attack paths added regularly

Continue with free content