
Attacking and Defending Active Directory: Advanced Edition [September 2026]
A deep dive into Red Teaming – Practice attacks with focus on OpSec, Living Off the Land and bypassing security controls like MDI, WDAC and more in a secure multi-forest active directory lab environment. Earn the CRTE® certification
Starts: 5th September 2026 Duration: 4 weeks
Recordings of live sessions included!

What You Will Learn
This advanced bootcamp is designed to help security professionals understand, analyze and practice threats and attacks in a modern, multi-forest Active Directory environment with fully patched Server 2025 machines.
In addition to learning the popular tactics, techniques and procedures (TTPs), you will also see how they change for attacks across forest trusts. You will also learn how to abuse or bypass modern Windows defenses like Credential Guard, Local Administrator Password Solution (LAPS), MDI, Resource-Based Constrained Delegation (RBCD), Windows Defender Application Control (WDAC), Constrained Language Mode (CLM) and more.
In the lab, we evade both Identity detection (MDI) and endpoint detection (Defender and MDE) but the focus remains identity compromise and related OPSEC. If you are more interested in EDR Evasion and endpoint countermeasures, check out our Certified Evasion Techniques Professional (CETP) course.

4 Live Sessions
4 Hrs Per Session
4 Weeks Access
40 Flags To Be Collected
22 Lab Exercises
1 CRTE® Attempt
Recordings Of Live Sessions

Build Your Cybersecurity Credentials
Become a Certified Red Team Expert (CRTE®)
A certificate holder has demonstrated the capability of enumerating and understanding an unknown Windows network and can identify misconfigurations, functionality abuse and trusts abuse. They can use, write and modify open source tools and can abuse other built-in tools to perform enumeration, local privileges escalation, impersonation, pivoting, whitelisting bypasses, and antivirus evasion as well as identify sensitive data with minimal chances of detection.
Bootcamp Completion Certificate
Attendees will also get a course completion certificate after completing Learning Objectives covered during the course.

Live Session Schedule
Weekly 4 hours sessions start at 10:00 am ET and end at 02:00 pm ET.
DATE
LIVE SESSIONS
05 September 2026
Active Directory Enumeration, Offensive .Net Tradecraft and Local Privilege Escalation
12 September 2026
Lateral Movement, Credential Extraction and Domain Privilege Escalation
19 September 2026
Domain Persistence, Hybrid Identity attacks, Cross Domain/Forest attacks
26 September 2026
Defenses, Monitoring and Bypassing Defenses

Prerequisites
1. A good understanding of Active Directory security.
2. The ability to use command line tools.
Bootcamp Syllabus
The course is split in four modules across four weeks:
Module I
Introduction to OPSEC followed in the course and focus on stealth
Introduction to Attack Methodology and Tradecraft
Offensive .Net Tradecraft
Domain Enumeration, Enumerating domain information that can be leveraged during attacks while maintaining a minimal footprint on target endpoints
Learn and practice identifying high-value Active Directory objects, ACL permissions, and relationships to build effective and low-noise attack paths
Enumerate trust relationships within and across forests to map cross trust attack paths
Learn and practice escalating to local administrator privileges in the domain by abusing OU Delegation, Restricted Groups, LAPS, Nested group membership and hunting for privileges using remote access protocols
Credential Replay Attacks
Module II
Abuse COM (Computer Object Monitoring) and PowerShell Remoting for Lateral Movement
Understand various ways to gain remote access on the target machine and OPSEC considerations
Understand Credential Guard and Extract Credentials from a machine that has MDE and WDAC configured
Extract DPAPI protected certificate from MDE onboarded machines
Abuse the BadSuccessor attack for the Domain Privileges Escalation
Understand Microsoft’s EDR – Microsoft Defender for Endpoint (MDE)
Evading application whitelisting (WDAC)
Extract credentials from a machine that has MDE and WDAC configured
Module III
Learn and Practice attacks that allow Escalation from Domain Admins to Enterprise Admins by abusing Active Directory services
Lateral movement from on-prem to Azure AD by attacking Hybrid Identity infrastructure
Abuse Shadow Credentials, WMI filters for Lateral Movement
Advanced Cross Domain attacks. Understand how to leverage KRBTGT account hash or Trust key to move across the domain
Advanced Cross Forest attacks. Execute attacks like abuse of RBCD, Active directory sites, ADCS, SID Filtering misconfigurations etc. across forest trusts forests and understand the nuances of such attacks
Abusing SQL Server for cross forest attacks
More on advanced Cross Forest attacks like abuse of Foreign Security Principals, ACLs etc
Abusing PAM trust and shadow security principals to execute attacks against a managed forest
Learn and execute attacks against trust transitivity
Module IV
Learn about Microsoft Identity Protection (MDI) and its telemetry collection
Understand how MDI relies on anomaly to spot an attack
Bypass various MDI detections throughout the course
Understand about privileges groups, security flags/settings that can be configured on the privilege accounts / groups
Learn and understand the need to leveraging Privilege Administrative Workstation
Learn and understand about Time Bound Administrations (JIT & JEA)
Learn about Tier Model & ESAE environment
Learn about various security features such as Credential Guard, WDAC, MDI, LAPS, Protected Users Group etc

Purchase Options
Bootcamp
30 DAYS LAB ACCESS
+
BOOTCAMP
+
LIFE TIME ACCESS TO COURSE MATERIAL
+
ONE CERTIFICATION EXAM ATTEMPT
$439
Extension
30 DAYS
LAB EXTENSION
+
ONE COMPLEMENTARY EXAM ATTEMPT
$249
Bootcamp
60 DAYS LAB ACCESS
+
BOOTCAMP
+
LIFE TIME ACCESS TO COURSE MATERIAL
+
ONE CERTIFICATION EXAM ATTEMPT
$659
Bootcamp
90 DAYS LAB ACCESS
+
BOOTCAMP
+
LIFE TIME ACCESS TO COURSE MATERIAL
+
ONE CERTIFICATION EXAM ATTEMPT
$879
Exam Reattempt is only for existing or past students of this course who have already purchased this course in the past.
Reattempt
EXAM
REATTEMPT
$99
Add to cart
.
Purchase includes : 30 days lab access + course material + one certification exam attempt
Terms of Purchase and Use:
-
The Course materials and lab portal access are typically shared a few days before the scheduled bootcamp start date.
-
For all users enrolled in a bootcamp, lab access begins on the first day of the scheduled bootcamp.
-
You can use your registered email address to access the lab portal enterprisesecurity.io.
-
One Certification Exam attempt is included in the pricing. Additional exam attempts will be $99 each.
-
Once connected over VPN, consider the lab to be a hostile environment and you are responsible for your computer's security.
-
The above lab is a shared environment and certain pre-specified machines will be off-limits.
-
If you want a dedicated lab just for yourself at extra cost, please use the form in the Contact tab.
Manthan Chhabra
MEET THE INSTRUCTORS

Manthan is a security researcher at Altered Security with a strong passion for enterprise security, red teaming and Active Directory security. He specializes in testing enterprise security defences with a deep understanding of offensive strategies, including EDR evasion and Active Directory attacks.
He continuously researches emerging threats, attack techniques, and mitigation strategies to stay ahead of evolving adversaries. He has conducted Red Team training at BlackHat USA, DEF CON, AltSecCON and more.

