

Building and Breaking Active Directory Basic
Instructors:
Stefan Apostol, Content Engineer at TryHackMe
Stefan is a penetration tester with over 10 years of experience in offensive security, spanning pentesting, research, and content creation. He previously worked at Accenture as a Senior Security Analyst. His main areas of focus are infrastructure pentesting, Active Directory pentesting, and red teaming.
Tinus Green, Content Engineer at TryHackMe
Tinus began his career as a penetration tester before transitioning into cyber defence and crisis management. He now leads the consultancy team at MWR CyberSec as Head of Consultancy, alongside his work with TryHackMe. He is passionate about creating teaching content for offensive security.
Who this workshop is for:
Security practitioners who want hands-on time with the backbone of enterprise networks
Pentesters and red teamers who want a structured approach to attacking Active Directory
Sysadmins and engineers who manage AD and want to understand how it gets broken
What's included:
A live, hands-on session where you build the environment yourself
Full recording, sent to everyone who registers
A spot in a focused cohort of 50 practitioners
A Certificate of Participation with CPE credits
What makes this talk different:
It's built around real engagements, not a generic walkthrough of features
You'll see exactly where architecture and infrastructure choices decide whether an op survives
What you'll learn:
Build an Active Directory environment from scratch
Configure users, groups, and GPOs
Enumerate the environment to uncover common misconfigurations
Execute a full attack chain, exploiting those misconfigurations to achieve Domain Administrator privileges
The Series
This is Part 1 of a two-part series. In this session, you'll build a realistic Active Directory environment from scratch, the same one you'll attack in Part 2.
Part 2: Building and Breaking Active Directory Advanced on Thursday, November 19th
Enumeration: mapping the domain like an attacker would
Lateral movement across the environment you just built
Privilege escalation exploiting the exact configs from Part 1
Full domain compromise, start to finish
Register here: https://luma.com/tryhackme-9y3u
Reviews from Past Particioants
This workshop was hands-on and one of the best I've attended. As a Junior Cyber Security Analyst, it gave me solid background knowledge on how to secure Active Directory, as well as how to identify vulnerabilities and weak points that attackers could exploit.
This will help me a lot at work, especially when coordinating with my colleagues in the Network and Infrastructure section. The tools covered will give me a head start in my nighttime CTF sessions after work!
Thank you so much THM team, you played a huge part in helping me land my current position. Looking forward to the second part, the advanced version.
- Abdulaziz Albeloushi, Junior Information Security Analyst
The TryHackMe Building and Breaking Active Directory session was highly engaging and practical. The hands-on exercises provided valuable insight into common Active Directory attack techniques, how they are performed.
The session strengthened my understanding of Active Directory security and gave me practical knowledge that I can apply in my role as a Security Analyst.
- Sayooj Santhosh, Cyber Analyst
As a postgrad student, I found this session especially valuable because Active Directory has not been covered in much practical depth in my university studies.
The build-then-break approach helped fill that gap by showing not only how an Active Directory environment is configured, but also how those configuration decisions can create real attack paths.
Working through scenarios involving enumeration, exposed shares, Kerberoasting, DCSync, and pass-the-hash gave me a much clearer understanding of how Active Directory is actually used, attacked, and defended in real-world environments.
It was a very practical complement to academic study and helped connect theoretical cybersecurity concepts with realistic enterprise scenarios.
— Anonymous, Cybersecurity Student