Active Directory security is not black magic.
Learn how attackers see your network.
Two days. Zero theory ballast. 100% hands-on. The GOAD workshop for juniors, admins and everyone who finally wants to understand how Windows domains really get owned.
$ nxc smb 10.10.10.0/24 -u users.txt -p 'Winter2026!' --continue-on-success SMB 10.10.10.11 DC01 [+] sevenkingdoms.local\jsnow:Winter2026! (Pwn3d!) $ certipy find -u jsnow -p 'Winter2026!' -dc-ip 10.10.10.11 -vulnerable [!] ESC1 vulnerable template: "User" → Domain Admin path found. $ impacket-secretsdump -just-dc sevenkingdoms/administrator@10.10.10.11 [*] Dumping NTDS.dit ... krbtgt:502:aad3b435...:e2b475c... ← game over.
Enough with the PDF collecting.
Most IT-security trainings are stuffed with theoretical filler that gets you nowhere in practice. At Exploit Labs we have no interest in artificial gatekeeping. We want you to understand how networks actually get attacked - so you spot the weaknesses before a real adversary does. This is not a dusty certificate track where you memorise slides. This is the unvarnished “Attackers' Truth” entry into the world of Active Directory pentesting.
Your toolkit for the real thing.
Initial Access & Recon
How to land your first foothold without loud, obvious port scanners - manipulating LLMNR/NBT-NS name resolution and running targeted password spraying against Active Directory.
Credential Harvesting & NTLM Relaying
How to exploit missing SMB signing to intercept authentication traffic and relay it straight to critical endpoints such as LDAP or ADCS.
MachineAccountQuota (MAQ) Abuse
Why the Windows default that lets any regular domain user create up to 10 machine accounts is a massive risk for the entire directory tree.
Lateral Movement & LSASS Dumping
How attackers move quietly from host to host, dump the LSASS process on compromised clients and pull plaintext passwords or NTLM hashes straight out of memory.
Kerberos & Delegation Abuse
We demystify Kerberos. After two days you will understand Kerberoasting and AS-REP Roasting better than most senior administrators.
ADCS (Active Directory Certificate Services)
The royal road to domain takeover. You learn the certificate-service misconfigurations (ESC1 through ESC8) that flatten an entire infrastructure in seconds.
GPO Abuse & Domain Dominance
How attackers weaponise existing group policies, inject malicious scheduled tasks and use DCSync to replicate password hashes straight out of the NTDS.dit database.
Who is this for?
This training is for you if…
- …you are a junior or career-changer who finally wants to break through the offensive-security barrier.
- …you are a sysadmin who no longer just wants to run infrastructure, but harden it against real attacks.
- …you are done with 5-day PowerPoint marathons and want to work straight from the terminal with Kali Linux.
- …you want to learn in an environment where a first-name basis is the norm and no question is treated as dumb.
Everything you need to know.
Common questions about the GOAD workshop.
Lab access, prerequisites, schedule and what's included - short and honest.
Ready for your first lab domain takeover?
Exploit Online (DE)
- Online · German
- 1-2 Dec 2026 · Remote
Instant payment by card. Credentials and calendar invite arrive automatically once payment is confirmed.
Exploit Iceland
- Reykjavík
- 15-16 Oct 2026 · Venue: TBA
On-site seat includes 2 days of live training on venue, VPN lab access and daytime catering. Travel & accommodation not included.
Exploit Dubai
- Dubai
- 5-6 Nov 2026 · Venue: TBA
On-site seat includes 2 days of live training on venue, VPN lab access and daytime catering. Travel & accommodation not included.
From 3 attendees, or for billing via your employer (online or on-site). We reply with a formal quote and invoice within one business day.
Questions about booking or invoicing via your employer? Email us directly: frontoffice@xplt.com