Skip to content
Exploit Labs
Exploit Labs · Hands-on Workshop

Active Directory security is not black magic.
Learn how attackers see your network.

Two days. Zero theory ballast. 100% hands-on. The GOAD workshop for juniors, admins and everyone who finally wants to understand how Windows domains really get owned.

On-site Iceland / Dubai - €999
root@kali · goad.lab
$ nxc smb 10.10.10.0/24 -u users.txt -p 'Winter2026!' --continue-on-success
SMB   10.10.10.11   DC01   [+] sevenkingdoms.local\jsnow:Winter2026! (Pwn3d!)
$ certipy find -u jsnow -p 'Winter2026!' -dc-ip 10.10.10.11 -vulnerable
[!] ESC1 vulnerable template: "User"  →  Domain Admin path found.
$ impacket-secretsdump -just-dc sevenkingdoms/administrator@10.10.10.11
[*] Dumping NTDS.dit ...  krbtgt:502:aad3b435...:e2b475c... ← game over.
Attackers' Truth

Enough with the PDF collecting.

Most IT-security trainings are stuffed with theoretical filler that gets you nowhere in practice. At Exploit Labs we have no interest in artificial gatekeeping. We want you to understand how networks actually get attacked - so you spot the weaknesses before a real adversary does. This is not a dusty certificate track where you memorise slides. This is the unvarnished “Attackers' Truth” entry into the world of Active Directory pentesting.

Curriculum · 7 attack paths

Your toolkit for the real thing.

01 / 07

Initial Access & Recon

How to land your first foothold without loud, obvious port scanners - manipulating LLMNR/NBT-NS name resolution and running targeted password spraying against Active Directory.

02 / 07

Credential Harvesting & NTLM Relaying

How to exploit missing SMB signing to intercept authentication traffic and relay it straight to critical endpoints such as LDAP or ADCS.

03 / 07

MachineAccountQuota (MAQ) Abuse

Why the Windows default that lets any regular domain user create up to 10 machine accounts is a massive risk for the entire directory tree.

04 / 07

Lateral Movement & LSASS Dumping

How attackers move quietly from host to host, dump the LSASS process on compromised clients and pull plaintext passwords or NTLM hashes straight out of memory.

05 / 07

Kerberos & Delegation Abuse

We demystify Kerberos. After two days you will understand Kerberoasting and AS-REP Roasting better than most senior administrators.

06 / 07

ADCS (Active Directory Certificate Services)

The royal road to domain takeover. You learn the certificate-service misconfigurations (ESC1 through ESC8) that flatten an entire infrastructure in seconds.

07 / 07

GPO Abuse & Domain Dominance

How attackers weaponise existing group policies, inject malicious scheduled tasks and use DCSync to replicate password hashes straight out of the NTDS.dit database.

Audience

Who is this for?

This training is for you if…

  • …you are a junior or career-changer who finally wants to break through the offensive-security barrier.
  • …you are a sysadmin who no longer just wants to run infrastructure, but harden it against real attacks.
  • …you are done with 5-day PowerPoint marathons and want to work straight from the terminal with Kali Linux.
  • …you want to learn in an environment where a first-name basis is the norm and no question is treated as dumb.
Hard facts

Everything you need to know.

Format
Online (Zoom + VPN lab) or on-site in Reykjavík & Dubai
Dates
Iceland: 15-16 Oct 2026 · Dubai: 5-6 Nov 2026 · Online (DE): 1-2 Dec 2026 · 09:00-17:00 each day
Language
German for the online cohort. On-site editions are mixed DE/EN.
Investment
Online €129 · On-site (Iceland / Dubai) €999 - each excl. VAT
Included
2 days of live instruction, personal VPN access to the isolated GOAD lab, live expert support and all accompanying cheat-sheets. On-site editions also include daytime catering on venue.
FAQ

Common questions about the GOAD workshop.

Lab access, prerequisites, schedule and what's included - short and honest.

Registration

Ready for your first lab domain takeover?

Remote · German

Exploit Online (DE)

  • Online · German
  • 1-2 Dec 2026 · Remote
€129 excl. VAT

Instant payment by card. Credentials and calendar invite arrive automatically once payment is confirmed.

Exploit Iceland logo
On-site · Reykjavík

Exploit Iceland

  • Reykjavík
  • 15-16 Oct 2026 · Venue: TBA
€999 excl. VAT

On-site seat includes 2 days of live training on venue, VPN lab access and daytime catering. Travel & accommodation not included.

Exploit Dubai logo
On-site · Dubai

Exploit Dubai

  • Dubai
  • 5-6 Nov 2026 · Venue: TBA
€999 excl. VAT

On-site seat includes 2 days of live training on venue, VPN lab access and daytime catering. Travel & accommodation not included.

Corporate invoice
Groups & teams

From 3 attendees, or for billing via your employer (online or on-site). We reply with a formal quote and invoice within one business day.

Questions about booking or invoicing via your employer? Email us directly: frontoffice@xplt.com

Part of our training portfolio - see also OSCP certification.