Skip to content
Exploit Labs
XPLT · Hands-on Active Directory Workshop

Compromise a Windows domain in two days - live in Reykjavík.

An instructor-led attack workshop in a hosted multi-domain lab: you enumerate, escalate and chain weaknesses until the directory falls, with an XPLT operator beside you.

  • 15-16 October 2026
  • 09:00-17:00 GMT
  • English
  • Reykjavik · Regus - Reykjavik
  • Maximum 10 attendees
Request employer invoice

Secure Stripe checkout · Invoice provided · Seat transfer subject to booking terms

  • Hosted multi-domain lab
  • Prepared Kali environment
  • 30 days of additional lab access
  • Live operator guidance
  • Certificate of attendance
  • Lunch and refreshments

What you will be able to do by day two.

  • Enumerate an unfamiliar Active Directory environment and identify viable attack paths.
  • Use BloodHound and native enumeration to understand domains, trusts, privileges and delegation.
  • Execute Kerberoasting, AS-REP Roasting, password spraying and credential attacks.
  • Exploit relevant NTLM relay, ACL, delegation, GPO and AD CS weaknesses.
  • Chain individual weaknesses into a complete domain-compromise path.
  • Explain the corresponding hardening and detection opportunities to a defensive team.

Seven practical modules. One complete attack chain.

Practice-led: short explanations followed immediately by guided lab execution.

01 / 07

Initial foothold and targeted reconnaissance

Quiet enumeration instead of noisy scanning: name-resolution abuse, targeted password spraying and mapping the directory you just landed in.

02 / 07

Credential attacks and NTLM relay

Capture authentication traffic where SMB signing is missing and relay it to services such as LDAP or the certificate authority.

03 / 07

Machine account creation and abuse chains

MachineAccountQuota lets an ordinary domain user create computer accounts. On its own that is not a compromise - it is an enabler you chain with delegation or certificate weaknesses.

04 / 07

Credential dumping and lateral movement

Pull credential material from compromised hosts and move between systems with the access you actually have.

05 / 07

Kerberos and delegation abuse

Kerberoasting, AS-REP Roasting and the delegation configurations that turn a service account into a path to privilege.

06 / 07

Active Directory Certificate Services

The certificate-template and enrolment weaknesses covered in the lab, and why a certificate is a durable credential.

07 / 07

ACL, GPO and domain-compromise paths

Object permissions, group-policy abuse and directory replication - assembled into the final chain to domain compromise.

The attack path, day by day.

Day 1

Reconnaissance, initial foothold, password attacks, AS-REP Roasting, Kerberoasting, credential access and lateral movement.

Day 2

ACL and delegation abuse, the confirmed AD CS scenarios, cross-domain movement and the final domain-compromise chain.

Breaks and lunch are included. Questions are handled continuously during the lab.

Taught by operators, not slide readers.

Johannes Schönborn, Founder & General Manager, Exploit Labs
Johannes Schönborn
Founder & General Manager, Exploit Labs

Johannes discovered offensive security early: as a teenager he ran LAN parties with over 200 participants, until a single attack shut the network down and changed his focus. Since 2006 he has specialised in penetration testing, secure software development and security operations. He is a certified OffSec trainer, a member of the FIRST Red Team Special Interest Group, an OWASP contributor and was part of the ENISA Workgroup on Threat Landscapes for several years. Alongside training he researches the automation of penetration tests with AI as part of his PhD studies. The GOAD material is informed by the practical assessments Exploit Labs delivers for clients.

  • Certified OffSec trainer
  • FIRST Red Team SIG
  • ENISA Threat Landscapes Workgroup

Isn't GOAD free? Yes.

GOAD is an open-source Active Directory practice lab. You are not paying for access to open-source files. You are paying for a maintained hosted environment, a curated two-day attack path, prepared tooling, direct operator guidance, troubleshooting support and an in-person cohort experience.

Built on the open-source Game of Active Directory project by Orange Cyberdefense and its contributors. View the project.

Designed for practitioners who know the basics.

  • Penetration testers
  • SOC and blue-team engineers
  • Windows and Active Directory administrators
  • Security consultants
  • Experienced junior practitioners preparing for deeper offensive work

Prerequisites

  • Basic Windows and Active Directory concepts
  • Basic networking knowledge including TCP/IP, DNS and SMB
  • Ability to work in a Linux terminal
  • Prior Kali, TryHackMe, HTB or CTF exposure is helpful but not mandatory

This is not a zero-knowledge introduction to IT or networking.

What is included

  • Two full instructor-led days
  • Personal access to the hosted multi-domain lab
  • Prepared Kali VM image, or verified setup instructions
  • Slides and field cheat sheets
  • 30 days of post-workshop lab access
  • Certificate of attendance
  • Lunch and refreshments at the venue

Before you book

  • Travel and accommodation are not included.
  • Bring your own laptop with at least 8 GB RAM, local admin rights and a virtualisation tool (VMware, VirtualBox or UTM).
  • Setup instructions and the lab prerequisites arrive by email at least one week before the workshop.
  • After payment you receive an immediate confirmation with the invoice, then the joining details and setup pack.

What attendees say

It was fun sitting on the other side of the table: attacking a Windows AD network instead of just maintaining it.

Mark · IT administrator · GOAD Iceland attendee

Our team learnt a lot about how things come together and how to defend the network.

Thomas · Workshop participant · GOAD Iceland attendee

Hands-on, good atmosphere, barely any slides: very good!

Christian · Workshop participant · GOAD Iceland attendee

A lot of hacking experience in a short timeframe, it was great!

Tim · Workshop participant · GOAD Iceland attendee

Small team size was good, there was enough time for everybody to ask their questions and get problems solved.

Anja · Workshop participant · GOAD Iceland attendee

Book your Reykjavik seat

Exploit Iceland
  • Reykjavik · Regus - Reykjavik
  • 15-16 October 2026 · 09:00-17:00 GMT
  • English
€999

Per seat. German VAT applies only to a German billing address; Stripe calculates and shows the final total before payment.

  • Two full instructor-led days
  • Personal access to the hosted multi-domain lab
  • Prepared Kali VM image, or verified setup instructions
  • Slides and field cheat sheets
  • 30 days of post-workshop lab access
  • Certificate of attendance
  • Lunch and refreshments at the venue
Request employer invoice

Request an invoice or quotation

For purchase orders, corporate billing or several seats. We respond within one business day.

Reykjavik workshop questions

Cannot travel to Reykjavik? Both onsite editions are listed on the GOAD overview.
15-16 October 2026
€999