Break Active Directory before attackers do - live in Dubai.
Two days of practical Active Directory attacks in a hosted multi-domain lab, guided by an XPLT penetration-testing operator from first foothold to full domain compromise.
- 5-6 November 2026
- 09:00-17:00 GST
- English
- Dubai · BOCASU
Secure Stripe checkout · Corporate invoice available · Seat transfer subject to booking terms
- Hosted multi-domain lab
- Prepared Kali environment
- 30 days of additional lab access
- Live operator guidance
- Certificate of attendance
- Lunch and refreshments
What you will be able to do by day two.
- Enumerate an unfamiliar Active Directory environment and identify viable attack paths.
- Use BloodHound and native enumeration to understand domains, trusts, privileges and delegation.
- Execute Kerberoasting, AS-REP Roasting, password spraying and credential attacks.
- Exploit relevant NTLM relay, ACL, delegation, GPO and AD CS weaknesses.
- Chain individual weaknesses into a complete domain-compromise path.
- Explain the corresponding hardening and detection opportunities to a defensive team.
Seven practical modules. One complete attack chain.
Practice-led: short explanations followed immediately by guided lab execution.
Initial foothold and targeted reconnaissance
Quiet enumeration instead of noisy scanning: name-resolution abuse, targeted password spraying and mapping the directory you just landed in.
Credential attacks and NTLM relay
Capture authentication traffic where SMB signing is missing and relay it to services such as LDAP or the certificate authority.
Machine account creation and abuse chains
MachineAccountQuota lets an ordinary domain user create computer accounts. On its own that is not a compromise - it is an enabler you chain with delegation or certificate weaknesses.
Credential dumping and lateral movement
Pull credential material from compromised hosts and move between systems with the access you actually have.
Kerberos and delegation abuse
Kerberoasting, AS-REP Roasting and the delegation configurations that turn a service account into a path to privilege.
Active Directory Certificate Services
The certificate-template and enrolment weaknesses covered in the lab, and why a certificate is a durable credential.
ACL, GPO and domain-compromise paths
Object permissions, group-policy abuse and directory replication - assembled into the final chain to domain compromise.
The attack path, day by day.
Reconnaissance, initial foothold, password attacks, AS-REP Roasting, Kerberoasting, credential access and lateral movement.
ACL and delegation abuse, the confirmed AD CS scenarios, cross-domain movement and the final domain-compromise chain.
Breaks and lunch are included. Questions are handled continuously during the lab.
Taught by operators, not slide readers.
Johannes discovered offensive security early: as a teenager he ran LAN parties with over 200 participants, until a single attack shut the network down and changed his focus. Since 2006 he has specialised in penetration testing, secure software development and security operations. He is a certified OffSec trainer, a member of the FIRST Red Team Special Interest Group, an OWASP contributor and was part of the ENISA Workgroup on Threat Landscapes for several years. Alongside training he researches the automation of penetration tests with AI as part of his PhD studies. The GOAD material is informed by the practical assessments Exploit Labs delivers for clients.
- Certified OffSec trainer
- FIRST Red Team SIG
- ENISA Threat Landscapes Workgroup
Isn't GOAD free? Yes.
GOAD is an open-source Active Directory practice lab. You are not paying for access to open-source files. You are paying for a maintained hosted environment, a curated two-day attack path, prepared tooling, direct operator guidance, troubleshooting support and an in-person cohort experience.
Built on the open-source Game of Active Directory project by Orange Cyberdefense and its contributors. View the project.
Designed for practitioners who know the basics.
- Penetration testers
- SOC and blue-team engineers
- Windows and Active Directory administrators
- Security consultants
- Experienced junior practitioners preparing for deeper offensive work
Prerequisites
- Basic Windows and Active Directory concepts
- Basic networking knowledge including TCP/IP, DNS and SMB
- Ability to work in a Linux terminal
- Prior Kali, TryHackMe, HTB or CTF exposure is helpful but not mandatory
This is not a zero-knowledge introduction to IT or networking.
What is included
- Two full instructor-led days
- Personal access to the hosted multi-domain lab
- Prepared Kali VM image, or verified setup instructions
- Slides and field cheat sheets
- 30 days of post-workshop lab access
- Certificate of attendance
- Lunch and refreshments at the venue
Before you book
- Travel and accommodation are not included.
- Bring your own laptop with at least 8 GB RAM, local admin rights and a virtualisation tool (VMware, VirtualBox or UTM).
- Setup instructions and the lab prerequisites arrive by email at least one week before the workshop.
- After payment you receive an immediate confirmation with the invoice, then the joining details and setup pack.
Book your Dubai seat
- Dubai · BOCASU
- 5-6 November 2026 · 09:00-17:00 GST
- English
Per seat. German VAT applies only to a German billing address; Stripe calculates and shows the final total before payment.
- Two full instructor-led days
- Personal access to the hosted multi-domain lab
- Prepared Kali VM image, or verified setup instructions
- Slides and field cheat sheets
- 30 days of post-workshop lab access
- Certificate of attendance
- Lunch and refreshments at the venue
Request an invoice or quotation
For purchase orders, corporate billing or several seats. We respond within one business day.