18 Labs · Beginner to Advanced

R7G Labs — Active Directory

Active Directory Security Labs

Realistic domain environments where you practice AD enumeration, Kerberos attack techniques, lateral movement, and defensive hardening—all with structured guidance and completion badges.

Lab environment

A fully provisioned Windows domain for each session

Each lab spins up an isolated Windows Server domain with realistic user accounts, group policies, service accounts, and misconfigurations. Nothing to install. No VMs to configure. Just start the lab.

Windows Server 2022 Domain Controller
10–20 domain user accounts with varied roles
Pre-configured service accounts (with SPNs)
Misconfigured ACLs and GPOs for practice
SIEM integration for detection labs
lab-terminal
$ SharpHound.exe -c All
[+] Collecting domain objects...
[+] Found 3 domain controllers
[+] Found 24 user accounts
[+] Found 6 service accounts
[+] Compressed output: 20240115_BloodHound.zip
$ GetUserSPNs.py lab.local/jdoe
ServicePrincipalName: HTTP/intranet.lab.local
$krb5tgs$23$*svc_web*...

Lab exercises

8 guided lab scenarios

01

AD Enumeration with BloodHound

Beginner

Use BloodHound and SharpHound to map an Active Directory environment and identify attack paths.

30 min
Start
02

Kerberoasting — Attack and Detection

Intermediate

Request TGS tickets for service accounts, crack the hashes offline, then detect the attack in the SIEM.

45 min
Start
03

Pass-the-Hash Lateral Movement

Intermediate

Use PtH to move laterally across a domain, then implement mitigations including Protected Users and Credential Guard.

45 min
Start
04

AS-REP Roasting Attacks

Beginner

Identify accounts with Kerberos pre-auth disabled and extract crackable hashes without authentication.

30 min
Start
05

GPO Hardening for Domain Security

Intermediate

Configure Group Policy Objects to enforce password policy, audit logging, SMB signing, and LSASS protections.

60 min
Start
06

DCSync Attack Detection

Advanced

Simulate a DCSync replication attack to dump password hashes, then build detection rules in a SIEM.

60 min
Start
07

Domain Privilege Escalation via ACL

Advanced

Exploit misconfigured ACLs in Active Directory to escalate privileges to Domain Admin.

75 min
Start
08

Restricting NTLM Authentication

Beginner

Audit and restrict NTLM authentication across a domain to reduce relay attack exposure.

40 min
Start

Tools used in these labs

BloodHoundSharpHoundImpacketCrackMapExecMimikatz (detection)PowerShell AD module

Build AD attack and defense skills now

Create a free account to access beginner labs. Upgrade to unlock all 18 Active Directory labs and earn completion badges.