
Active Directory Attack Test Cases: MITRE ATT&CK-Mapped Checks for On-Prem AD
Active Directory is the target in most internal compromises. Once an attacker has a domain foothold, the path to Domain Admin runs through a known set of misconfigurations: weak ACLs, roastable service accounts, unconstrained delegation, bad certificate templates. This checklist covers those paths as discrete, repeatable test cases.
Every row is one test case, tagged with its attack phase and MITRE ATT&CK technique ID, carrying the exploit description, execution steps, tools, commands, and the indicators of compromise a defender would see. The same sheet works for the red team running the attack and the blue team validating detection.
Key Takeaways
- Seven attack phases, weighted toward Credential Access (20 of 40 cases)
- Nine privilege escalation checks, including four named CVEs
- Copy-ready commands for the tools that run each case: PowerSploit, Mimikatz, Rubeus, Impacket, NetExec, BloodHound, Certipy, and more.
- An Indicator of Compromise column on every case, so detection teams can check whether their SIEM would catch each technique.
What's Inside
Every row is one test case, grouped by the attack phase an operator moves through in a domain.
- Reconnaissance and Discovery: AD object, ACL, GPO, trust, and network share enumeration.
- Privilege Escalation: group and Machine Account Quota misconfigurations, SID history, ADCS, RODC, plus the four named CVEs.
- Credential Access: roasting, hash and key attacks, delegation, GPP, LAPS, gMSA, NTDS and DSRM dumping, Golden, Silver, Diamond and Skeleton keys.
- Lateral Movement and Persistence: SCCM, WSUS, MSSQL trusted links, trust attacks, and Shadow Credentials.
For each case: MITRE ATT&CK technique ID and name, exploit description, execution steps, tools required, commands, and indicators of compromise.
How to use it









