Resources / Checklists /
Web Application Security
DOCX

Active Directory Attack Test Cases: MITRE ATT&CK-Mapped Checks for On-Prem AD

40 on-prem Active Directory attack test cases, each mapped to its MITRE ATT&CK technique, with the exact tools, commands, and indicators of compromise to run the attack and catch it.
Format:
DOCX
Last updated:
September 15, 2026
Read time:
5
min
Talk to an Expert
White arrow pointing diagonally upward to the right on a black square background.White arrow pointing diagonally upward to the right on a black square background.

Active Directory is the target in most internal compromises. Once an attacker has a domain foothold, the path to Domain Admin runs through a known set of misconfigurations: weak ACLs, roastable service accounts, unconstrained delegation, bad certificate templates. This checklist covers those paths as discrete, repeatable test cases.

Every row is one test case, tagged with its attack phase and MITRE ATT&CK technique ID, carrying the exploit description, execution steps, tools, commands, and the indicators of compromise a defender would see. The same sheet works for the red team running the attack and the blue team validating detection.

Key Takeaways

  • Seven attack phases, weighted toward Credential Access (20 of 40 cases)
  • Nine privilege escalation checks, including four named CVEs
  • Copy-ready commands for the tools that run each case: PowerSploit, Mimikatz, Rubeus, Impacket, NetExec, BloodHound, Certipy, and more.
  • An Indicator of Compromise column on every case, so detection teams can check whether their SIEM would catch each technique.

What's Inside

Every row is one test case, grouped by the attack phase an operator moves through in a domain.

  • Reconnaissance and Discovery: AD object, ACL, GPO, trust, and network share enumeration.
  • Privilege Escalation: group and Machine Account Quota misconfigurations, SID history, ADCS, RODC, plus the four named CVEs.
  • Credential Access: roasting, hash and key attacks, delegation, GPP, LAPS, gMSA, NTDS and DSRM dumping, Golden, Silver, Diamond and Skeleton keys.
  • Lateral Movement and Persistence: SCCM, WSUS, MSSQL trusted links, trust attacks, and Shadow Credentials.

For each case: MITRE ATT&CK technique ID and name, exploit description, execution steps, tools required, commands, and indicators of compromise.

How to use it

01
Pick your phase. Filter to the attack phase you are testing, such as Credential Access, or run all of them for a full internal AD review.
02
Read across the row. The test case first, then the technique it maps to, the tools, the exact commands, and the indicators a defender should see.
03
Run it, then check the IoC column. After executing a test case, confirm whether your monitoring flagged the listed indicators. A test that runs clean with no detection is a gap worth logging.
04
Not comfortable running these against production? Payatu's red team runs the full set in a scoped Active Directory assessment and shows you which paths reach Domain Admin.
Subscribe to our newsletter
Reviewed by
Red circular logo with four overlapping curved segments forming a hollow diamond shape at the center.
Red Team Researchers