R7G Labs — Active Directory
Active Directory Security Labs
Realistic domain environments where you practice AD enumeration, Kerberos attack techniques, lateral movement, and defensive hardening—all with structured guidance and completion badges.
Lab environment
A fully provisioned Windows domain for each session
Each lab spins up an isolated Windows Server domain with realistic user accounts, group policies, service accounts, and misconfigurations. Nothing to install. No VMs to configure. Just start the lab.
Lab exercises
8 guided lab scenarios
AD Enumeration with BloodHound
BeginnerUse BloodHound and SharpHound to map an Active Directory environment and identify attack paths.
Kerberoasting — Attack and Detection
IntermediateRequest TGS tickets for service accounts, crack the hashes offline, then detect the attack in the SIEM.
Pass-the-Hash Lateral Movement
IntermediateUse PtH to move laterally across a domain, then implement mitigations including Protected Users and Credential Guard.
AS-REP Roasting Attacks
BeginnerIdentify accounts with Kerberos pre-auth disabled and extract crackable hashes without authentication.
GPO Hardening for Domain Security
IntermediateConfigure Group Policy Objects to enforce password policy, audit logging, SMB signing, and LSASS protections.
DCSync Attack Detection
AdvancedSimulate a DCSync replication attack to dump password hashes, then build detection rules in a SIEM.
Domain Privilege Escalation via ACL
AdvancedExploit misconfigured ACLs in Active Directory to escalate privileges to Domain Admin.
Restricting NTLM Authentication
BeginnerAudit and restrict NTLM authentication across a domain to reduce relay attack exposure.
Tools used in these labs
Build AD attack and defense skills now
Create a free account to access beginner labs. Upgrade to unlock all 18 Active Directory labs and earn completion badges.