An Active Directory (AD) pentest is a simulation of attacks on a company's domain infrastructure to identify vulnerabilities related to account management, access policies, service settings, and trust relationships.
In this article, the author will share his experience using various techniques and tools to identify vulnerabilities that allow for privilege escalation.
We will examine three tools: PowerUp.ps1, WinPEAS, and PrivescCheck.