Shadow Steps: Understanding and Detecting User Impersonation and Lateral Movement in Active Directory



This hands-on, scenario-driven workshop delves into how attackers move stealthily through Active Directory environments using user impersonation and lateral movement techniques. Participants will explore how attackers exploit credentials and trust relationships to expand their access, and how defenders can detect, prevent, and respond to such threats.

 

Through simulated exercises and guided labs, participants will walk through real-world attack paths such as (over)Pass-the-Hash, Kerberoasting, and token impersonation.

 

Learning Objectives:

  • Understand the key mechanisms behind user impersonation in Active Directory.
  • Demonstrate how attackers perform lateral movement via tools and techniques such as:
  • Pass-the-Hash
  • Pass-the-Ticket/Overpass-the-Hash
  • Remote Services Abuse (SMB, WMI, RDP, WinRM)\
  • SOCKS PTH
  • Kerberoasting
  • Token Impersonation
  • Token Creation
  • This hands-on workshop is ideal for Penetration Testers with limited knowledge about AD internals.

Prerequisites:

  • Basic understanding of Windows networks and Active Directory
  • Familiarity with common cybersecurity concepts
  • Participants should have an AWS account with appropriate payment methods associated.
  • Participants will need an Ubuntu VM with Terraform and Empire Installed.

This workshop supports content and knowledge from SEC565: Red Team Operations and Adversary Emulation. To learn more about this course, explore upcoming sessions, and access your FREE demo, click here.

Speaker and Presenter Information

Jean-Fran�ois Maes, Offensive Guardian
Jean-Fran�ois is based in Portugal, where he is the CEO of Offensive Guardian, a boutique red and purple teaming shop providing freelance services to various organizations. He has worked for other noteworthy firms, including, but not limited to: Neuvik, TrustedSec, Fortra's Cobalt-Strike team, and NVISO.

Relevant Government Agencies

Other Federal Agencies, Federal Government, State & Local Government


Register


Register as Attendee


Add to Calendar


Event Type
Webcast


When
Thu, Sep 18, 2025, 10:00am - 12:00pm ET


Cost
Complimentary:    $ 0.00


Website
Click here to visit event website


Organizer
SANS Institute


Contact Event Organizer



Return to search results