<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Active Directory on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/active-directory/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sat, 12 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/active-directory/index.xml" rel="self" type="application/rss+xml"/><item><title>bloodyAD</title><link>https://wearethebug.dev/posts/bloodyad/</link><pubDate>Sat, 12 Sep 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/bloodyad/</guid><description>Active Directory privilege escalation swiss-army knife. Quick reference for common bloodyAD operations.</description></item><item><title>NetExec Advanced</title><link>https://wearethebug.dev/posts/netexec-advanced/</link><pubDate>Fri, 28 Aug 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/netexec-advanced/</guid><description>Follow-up to the NetExec cheatsheet: deeper Active Directory abuse techniques, delegation attacks, and operational tooling for experienced operators.</description></item><item><title>NetExec</title><link>https://wearethebug.dev/posts/netexec/</link><pubDate>Sat, 25 Jul 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/netexec/</guid><description>Swiss-army knife for Active Directory and network protocol enumeration/exploitation, successor to CrackMapExec.</description></item><item><title>HTB: Heron</title><link>https://wearethebug.dev/posts/htb-heron/</link><pubDate>Fri, 14 Nov 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-heron/</guid><description>Heron is a small Active Directory scenario that involves typical vulnerabilities found in real word company environments. It's designed for penetration testers and red teamers in search of a quick and challenging lab.</description></item><item><title>VULNLAB: Heron</title><link>https://wearethebug.dev/posts/vl-heron/</link><pubDate>Thu, 13 Jun 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-heron/</guid><description>Heron is a medium-difficulty chain hosted on Vulnlab, featuring an assumed breach from a domain-joined linux jump server access to domain controller. Starting with an enumeration of the internal website for domain users and performing AS-REP roasting, decrypting GPP password from the sysvol share, leading to smb share having write access to web.config, gaining a shell by using AspNetCoreModule for executing powershell commands which lead to finding linux admin’s credentials, reusing the same password that will lead to another user which has WriteAccountRestrictions on dc that leads to resource based delegation</description></item></channel></rss>