# Active Directory Pentesting Lab by Nee

Here's how I created and segmented my AD pentest lab @ home!

I've been wanting to get into AD pentesting for the longest time. I've only had minimal AD pentest experience prior to setting this up. I'd probably have owned 1-2 domains at max😅 over @ [HackTheBox](https://www.hackthebox.com/).&#x20;

I've stayed with team penguin ever since RHCSA and I think its finally time to get myself familiarized with 🪟 , Active Directory and the various attack techniques that come with it!

I'm someone who believes that learning to build something is equally as important as knowing how to break it. I could've easily spun this environment up with [one](https://github.com/browninfosecguy/ADLab) of many scripts available over on github. But I decided to build this up from scratch to educate myself in regards to how a windows environment is setup!

Hope this setup guide helps someone out there! Do check out references and show them some support too :)&#x20;

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FAtS5E4Bm0WR9Uc4dLa8L%2FinfraWIDEa.jpg?alt=media\&token=9bbce266-1304-486d-8548-e29fab99a13f)


# Infrastructure

AD Lab's Infra

## Topology

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FaTJIRfjF0UKqtExd0wGf%2Finfra.jpg?alt=media\&token=0062cc1a-3724-4ded-bc59-a3c6487d42cc)

### Hypervisor

My Active Directory LAB will be virtualized on my Dell PowerEdge R710. My hypervisor of choice is VMware ESXi-6.5.0-20190702001-standard.&#x20;

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2F5HgjRAylMp7hLYWB0YaQ%2Fimage.png?alt=media\&token=3fbd99a3-0807-42e5-b571-71ed272dc5f5)

### Firewall

My firewall of choice is pretty much everyone else's at this point. 😂 pfSense! I've gone ahead and setup a VPN server which allows access into the AD Lan. I'll be using this to place my attacker machine into the network where the AD machines are instead of manually moving my machine into the network. (Basically HTB/THM) I do have plans to let friends and family use this lab in the long run but we'll see 😉!

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FGVz9Q7fnqNkhhwY0CQxq%2Fimage.png?alt=media\&token=f345019e-95a0-4028-87c2-6ff4affc845d)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FLi6v1AKMYL0BPdrsV2QL%2Fimage.png?alt=media\&token=46128da5-6bd9-429b-8db3-e7d251857173)


# Vswitch & Port Group Configuration

## Vswitch

To create a port group on VMware ESXI we first need to create a Virtual Switch as shown below.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FNASE4kZG3SgQCWJ0nXQD%2Fimage.png?alt=media\&token=e1cdba89-327a-4809-873b-335776e58931)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FH8G5GuDgyGch5FooCBkx%2Fimage.png?alt=media\&token=7c8a4297-4259-4d39-84ca-868a25137dd6)

## Port Group

Now that we have a virtual switch setup, we can setup the port group to assign our machines to.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2F8jjeIFtF4G8k04heWYpJ%2Fimage.png?alt=media\&token=d4e53697-f4f5-4bee-91be-4736be9f63b7)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FT5mzfKGNrQJ1L4Njy7WS%2Fimage.png?alt=media\&token=c4ff9b5e-a684-4b0a-be9e-ede82d64a809)

## Pfsense Configuration

Now that we have the new port group created, we can add our Pfsense VM into the network to act as the gateway.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FxfyioNbmdVWt1HEKptfI%2Fimage.png?alt=media\&token=5433d7f0-a243-473a-ad19-958a1d723406)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FNTD20O9KItGAg4Li3Wvx%2Fimage.png?alt=media\&token=f657f058-4800-431a-be36-6dbd18a60ab6)

Now that the machine is connected to the LAN, we will be able to onboard the new LAN onto the FW.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FVq3yUNIw9OYr1HvaQTz6%2Fimage.png?alt=media\&token=5c392ab4-ff67-402d-ad2b-62e51481a242)

Once the Interfaces is added, we have to configure the interface and set the IP range.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FCOeHZiNckqpOJjTnUmTm%2Fimage.png?alt=media\&token=16c543dd-501b-4555-9550-82c654693bc0)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FHzzdDIylRZReuimV5qxH%2Fimage.png?alt=media\&token=d3d24647-f81d-4b90-949d-72ec0355bc6c)

And once all that is done, check back at the terminal to confirm that you're LAN is successfully added as shown below.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FPrOk9OzaQ5L9YZWTPAbj%2Fimage.png?alt=media\&token=d7ca491b-b5df-4571-9ced-b1f50b35fe24)


# pfSense Firewall

Pfsense Firewall Configuration

## Rules

Now that we have the network setup, its time to setup some basic firewall rules to ensure that users are not able to pivot into our main network.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FxnzmP8f8TxF1GD4Yeknz%2Fimage.png?alt=media\&token=03c11258-cc58-41a2-b69a-35b1e8d17f14)

I also have created a VPN server to enable users from external networks to practice pentesting the network together with me. I'll be creating another rule for that network as shown below.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FqhojCD2zaBAs6g3sHGot%2Fimage.png?alt=media\&token=bfc115bb-e78d-4525-96bd-3e1fd9da1605)


# Windows Server 2022 \[Domain Controller]

Windows Server

## VM Creation

Here are the specifications of my Windows Server VM.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FVD5g8Rqm8zHHaX0euwtC%2Fimage.png?alt=media\&token=cac8c8c9-f844-4587-a139-7c16f2e57687)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FCxenplRgH6JPaA15ifpZ%2Fimage.png?alt=media\&token=43ea1ef9-a727-47a2-8c9b-9a8fc79b7569)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2Fur2NlFZZ36RYBZdwi4OR%2Fimage.png?alt=media\&token=a3d51da8-7aa2-4dcc-ab5e-bd7a3c6ffa24)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FVgsBTcnAZuCnpBAnX2BX%2Fimage.png?alt=media\&token=5f0245e1-9d1c-4657-bc61-bd0019151c2b)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FTlkQyGifOFURRJajXxtH%2Fimage.png?alt=media\&token=e23b642c-b230-4a10-91b5-f1043db8749d)


# Windows 11 Pro \[Endpoint]

Endpoint

## VM Creation

Here are the specifications of my Windows 11 pro VM.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2Fyk8E2KNr809y1u9ZHfg5%2Fimage.png?alt=media\&token=02767ca9-264b-4370-8fb8-0e704a1c234e)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2Fn4hGLOHbEOvFt7kuThYu%2Fimage.png?alt=media\&token=17b093dc-849b-4b9d-9914-255319dc0132)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FcSZ33dva4dLHahhpkpfS%2Fimage.png?alt=media\&token=fa2e00a5-3ade-4247-b38a-f71ce8167a6a)

![Hit SHIFT + F10](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FYWBgzCYbxgxxZdLrYqTV%2Fimage.png?alt=media\&token=fc34468d-e108-4260-b847-5ba4e262481c)

![Enter "Regedit"](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2Flnce6mzRNeVHomtqcVKn%2Fimage.png?alt=media\&token=9fa6938a-4200-472b-8a27-bd64acbcdb08)

The following step is to allow the installation of windows 11 without the TPM chip on the VM.

![HKEY\_LOCAL\_MACHINE\SYSTEM\Setup\LabConfig](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2F5wjJZtioYcwClEh5gMBd%2Fimage.png?alt=media\&token=9c6d8bf7-11dd-4cb2-b30d-da742cd39230)

![You should be brought to this page without any error](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FSSAPebAqikaIMt6vV97c%2Fimage.png?alt=media\&token=8ce54535-0431-4679-aeeb-08ec954e4c70)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2Fy5e0lKpPoWe53eOGpwOw%2Fimage.png?alt=media\&token=0b266ff6-9fdb-448a-9e82-5131cb1f6661)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FLOnGro0AvBgGynEJo2B1%2Fimage.png?alt=media\&token=89044a3d-622c-432c-aa1f-fcbb4143497c)

Once you reach this step, very important to hit `Domain join instead` after hitting on the sign in options option.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FaL7ok9IboaaxkX6TW9ri%2Fimage.png?alt=media\&token=36d4de4d-8a93-454e-a166-83c654a21cd8)

Password = `P@ssw0rd`

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FrCIghI4e3dZ3sTbNaDwx%2Fimage.png?alt=media\&token=d83037d8-305f-4ef6-98fd-6d9eb2f1c6fe)


# Domain Controller 1

## Accounts

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FnDXhxMpwgLloTQ8A36kA%2Fimage.png?alt=media\&token=865662ca-c799-4b88-a8ad-57e342d29ea7)

Most Secure Password = `P@ssw0rd`

## PC Name

First I'll be renaming my server as shown below.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FstXcd1i0xvJKbz3snfjR%2Fimage.png?alt=media\&token=ff924240-b098-49da-879d-79c1026bbb97)

## Network Settings

Its important to set a static IP for our Domain Controller.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2F5sYTXnNksqHbg90kRjMG%2Fimage.png?alt=media\&token=8788ef0c-8e17-4e5e-819d-46f1fb24e418)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FOlKye7UoHchAN9iRuZBv%2Fimage.png?alt=media\&token=a2c2cff9-d208-4545-a8c6-9c981c167bd1)

## Active Directory Services

Next, I'll be adding the active directory domain services role on to the server.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FBXpPBfPXt3TFSFlxrjSy%2Fimage.png?alt=media\&token=8c005daf-a2f3-4454-a66c-de1f62c5570e)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FJkxIT80tHDu6uq2jqchq%2Fimage.png?alt=media\&token=ccabc4d8-0f19-4d70-b8d6-8f465b040960)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2F2UvOelgZH5ObvN16BSP5%2Fimage.png?alt=media\&token=7436a1b3-1195-4a09-a43f-858da9a9eb09)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FGkmULRaGtCwpqiLhYEBp%2Fimage.png?alt=media\&token=09676ed1-e841-4dae-8d46-39b5434d2403)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FLynu6diwle7VjtsD6ry6%2Fimage.png?alt=media\&token=f46fd4d0-12d7-4d9b-a791-cc76002c0d7b)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FBMywowDe5SyllP19dN69%2Fimage.png?alt=media\&token=8f2c09e8-897d-4b2f-a700-06b48b1555e7)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2F9MUiNv8fh3hEIXw5n9PC%2Fimage.png?alt=media\&token=345eac5a-b348-4bea-abc2-30759f99f8af)

### Promoting Server to DC

Once the active directory domain services is done installing, there'll be a prompt asking to promote the server to a Domain Controller. Let's go ahead and do that.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FarAJ2OlUcuAunzq74mYS%2Fimage.png?alt=media\&token=584006d9-4d8b-4fc5-bb69-25426c57b21b)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2Fw7pan3wJj6DrRLL4TJQ7%2Fimage.png?alt=media\&token=67cb9039-262e-4a76-b36e-a2b40c3c6c91)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2Fzef753qbsANTqlx7Jkw4%2Fimage.png?alt=media\&token=5349fa3b-982e-4872-85c8-01ff58e1afd0)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FYKlyt05GxbggQ3dVZC34%2Fimage.png?alt=media\&token=3b4a5c84-e804-4e0b-b8db-28b8458be5ec)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FH6SCSNa01lIxA40KfSPE%2Fimage.png?alt=media\&token=790214e2-03ff-4199-8c40-ca7140c1fcb0)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FHLOQHWtJRhDkC1g5lxd7%2Fimage.png?alt=media\&token=f403bb34-6f41-4e47-a409-43fc41cce8a9)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FsXCjKEwl93tTP3oUMeYN%2Fimage.png?alt=media\&token=d049425d-d1a7-4efb-b194-4ba4cb5867e2)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FH1vY2Vj9V0F0auWPrZUU%2Fimage.png?alt=media\&token=6878872d-a62e-40cf-8f22-1f88cda4c85d)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FiXadWwQFW8QPRiaD026f%2Fimage.png?alt=media\&token=4dda1c0e-6f44-4e32-be93-56dc80c95a6e)

After a restart the domain will be populated as shown bellow. If you see something like this, you've done it correctly.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2F3xKaCq6lwZDabZhPBeg0%2Fimage.png?alt=media\&token=adc419f9-d854-4bea-acd3-48f19d034e89)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FmTFGALjPxDLaqlo5idyL%2Fimage.png?alt=media\&token=7c0c0dc1-ba39-4338-9c29-401e79c8bad2)

## DNSClient Server Address

Now that we have the Active Directory service up and running, we can set the correct interface which will be handling our DNS Queries.

```
Set-DnsClientServerAddress -InterfaceIndex 15 -ServerAddress 10.11.12.10
```

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FXQbt3EmlPEuWieIjK84Q%2Fimage.png?alt=media\&token=84815c70-576d-4901-a576-d243b56ffc64)

## Active Directory Certificate Services

Next, AD Certificate Services can be optionally added to the server for LDAP.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FscGKjzlJICx1WadkruPr%2Fimage.png?alt=media\&token=0badaa86-e3a4-4bb4-a843-a91907938342)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FFWWL2IwzPHH2NdzO7EBd%2Fimage.png?alt=media\&token=9392e57a-f9ad-4958-846e-45be6f070b11)

![Hit install](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FsVNAzDSsLk2O1ezhjcin%2Fimage.png?alt=media\&token=9e4e40ec-81d3-4dba-8194-db348eb8c529)

### Configuring Certificate Services

Similar to the case above, a prompt will request to configure the Certificate Services.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2Fy98xRr39GIriZIUG5YWM%2Fimage.png?alt=media\&token=bcb61bd6-2b1a-4de5-ace1-c2dba5490d65)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FsbYKzUl1ZcYKjHZ6hXuj%2Fimage.png?alt=media\&token=fa7fd915-b838-46d0-a950-d9226e14d13c)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FgVsvDgOszENZjjCpw3bD%2Fimage.png?alt=media\&token=773dab9f-326e-46f6-a403-4cd06becd4db)

![Hit configure](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FAcsqKyBi9J1x6PJGHbiR%2Fimage.png?alt=media\&token=6103cdf4-c493-4c44-834a-73b4b9fa3610)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2F7Ow3AKFlgJMxYAHIczaS%2Fimage.png?alt=media\&token=aa456bba-9ca5-4daa-b1c1-84da33f0c425)

Reboot the server for changes to take place!

## Adding Users & Service Accounts

I'll be adding a couple users into the domain for the lab's purpose.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FLy1UL4uozrxaRGfgil8U%2Fimage.png?alt=media\&token=cbac6840-c712-46a8-bdd9-5224fe1705e3)

### User Accounts

#### John Hammond

```
First = John
Last = Hammond
logon = john
password = P@ssw0rd
```

<div align="center"><img src="https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FRXlWhxWDYZQiB7wThdi5%2Fimage.png?alt=media&amp;token=fa11b85b-8b5d-4597-b774-ceddc5445746" alt=""></div>

#### Heath Adams

```
First = Heath
Last = Adams
logon = heath
password = P@ssw0rd
```

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FxUsZFXWmoa98XfgA0SqC%2Fimage.png?alt=media\&token=b32aa846-09af-4ac4-9a9b-a83a40527798)

### Service Account

Go ahead and copy he Administrator account to create the service account.

```
First = SQL
Last = Service
logon = SQLService
password = MiP@ssw0rd!
Description = Devs pls take note: password = "MiP@ssw0rd!"
```

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2Fsu4BAA2gcHPTDJDVtHAS%2Fimage.png?alt=media\&token=96e68b60-64ee-45fa-9635-89db18b5e3c6)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FN5qUpL6kBJJEfqppUyYP%2Fimage.png?alt=media\&token=4b513607-5589-4352-8197-0b8be1932621)

### Service Principal Name (SPN) setup

A service principal name (SPN) is **a unique identifier of a service instance**. SPNs are used by Kerberos authentication to associate a service instance with a service logon account. Lets go ahead and create that.

```
setspn -a 4pfsec-DC/SQLService.4pfsec.local:60111 4pfsec\SQLService
```

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FyMn8jifnMstNtmhY077w%2Fimage.png?alt=media\&token=54b77ae1-e545-4fa1-8201-150958b66431)

#### Verify SPN

Now that we have setup the SPN, lets verify that its up and running as per expectations.

```
setspn -T 4pfsec.local -Q */*
```

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FKWgQRUIqakXzoD1inWE6%2Fimage.png?alt=media\&token=212a5bee-7472-4881-80c1-52481304ed3c)

## SMB Share

### Create a folder

First, create a folder that you'd like to share out to your network.

```
important
```

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2F5Mh7Yz4Mq5TZfGUIhs7R%2Fimage.png?alt=media\&token=a81db669-e88d-4581-9571-3bdfcf26ea80)

### Create New Share

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2F1DX0MGfvWUy5TaNjickM%2Fimage.png?alt=media\&token=59c02d4d-7da2-4f0c-a430-0e62034ac91d)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FTZCA04mCUgOl49792iWV%2Fimage.png?alt=media\&token=b502e431-f731-4b48-9cdb-56a393a2667c)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2F5Dtv8qn4gJzNVDkyI9NG%2Fimage.png?alt=media\&token=d8b1d0cd-71eb-4005-b6d6-49db985c2c0d)

![Hit create](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FwUbRtrPw1DRuxUx2IbNB%2Fimage.png?alt=media\&token=5d1ada03-bcc9-410a-b46c-f8fab8f44d74)


# Endpoint 1

These steps can be replicated to create other endpoints.

## Rename PC

The first thing is to rename the pc for your network. Do restart once renamed.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FoQOy8raPM6vqMTkwhCib%2Fimage.png?alt=media\&token=7e93f5b5-9d57-481b-9e5a-eac68c1aa0b7)

## Disabling Windows Security

### Virus & Threat Protection

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FP5KupxUuCVenfyekdqtV%2Fimage.png?alt=media\&token=c70a5cc4-d202-4760-8a11-854e8c6371ac)

### Registry

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2Fu51fL2bJjcy8YyHBjV4n%2Fimage.png?alt=media\&token=c669c2b0-bc21-49ef-9c51-f09475f8641e)

```
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender
```

* DisableAntiSpyware => 1
* DisableRealtimeMonitoring => 1
* DisableRoutinelyTakingAction => 1
* DisableAntiVirus => 1
* DisableSpecialRunningModes => 1
* ServiceKeepAlive => 0

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FcoRpzP0c9sHkdpx4xbxY%2Fimage.png?alt=media\&token=6237e7cb-a089-4080-b2f1-03ba9f97f1fd)

```
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Signature Updates
```

* ForceUpdateFromMU => 0

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FIguG4OSh9f4iW4nY65ot%2Fimage.png?alt=media\&token=6434b97c-ed9b-4e43-a5f4-a26da4cc2cee)

```
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection
```

* DisableRealtimeMonitoring => 1
* DisableOnAccessProtection => 1
* DisableBehaviorMonitoring => 1
* DisableScanOnRealtimeEnable => 1

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2Fhopy8PHqtYfgF2P4jSAb%2Fimage.png?alt=media\&token=6c59a8c9-a021-4ec3-a087-91ef621147ee)

```
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet
```

* DisableBlockAtFirstSeen => 1

## Join the Domain

Now that our client is prepped, its time to join the Domain.

### Changing DNS Server

To be able to join the domain, we need to set the AD server as our DNS server.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FfpBFgOovao3NxhwkfeM9%2Fimage.png?alt=media\&token=95798352-d4f3-4280-a210-5733af727a57)

#### Check Connectivity

```
PS C:\Users\ladmin> ping dc1.4pfsec.local
```

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2F2ORLvt4r8FfJB2RkbY6x%2Fimage.png?alt=media\&token=1d63a142-0fae-41c2-8e7f-adf9dbda3a18)

### Join Domain

Search for `Access work or school` and hit `connect`.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2Fnud2zCrw7oAC2NDpiF8f%2Fimage.png?alt=media\&token=9b14dfb6-1f7a-4e8d-b458-620574474bea)

Now we want to select `Join this device to a local Active Directory domain`.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FmVv3vgkfqudry9tlyAdE%2Fimage.png?alt=media\&token=d5b002fa-9dd4-4caa-ab67-89bc721bae57)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FSDezrqSlY9NjJ3bavq6E%2Fimage.png?alt=media\&token=1542277b-5c71-4935-8c35-facaf49d28af)

Now enter the domain name.

`4pfsec.local`

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FgI9euKDTlcKpjD2zzSrR%2Fimage.png?alt=media\&token=79b97cbf-ec9f-42ec-a479-1e195b4ec9c1)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FrGyt6js4sKo4ztR4h4IK%2Fimage.png?alt=media\&token=04da70ca-f948-4e5c-a28d-9228ed0d4840)

There should be a pop up asking for credentials as shown below and hit skip.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FyvKhhg3ijjyTQs0Hminx%2Fimage.png?alt=media\&token=9627769c-ec77-4922-85e9-711a0924072b)

Hit skip upon seeing the following prompt.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2Fau1644bNvJTYcKoC1ehF%2Fimage.png?alt=media\&token=db306af6-4156-400b-a2f1-ac5cdd8cfebf)

Once done, hit restart.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2F5idNbZVw8FraelFK6Er0%2Fimage.png?alt=media\&token=8cf3ea3e-0672-46c8-8fa6-59f37a940e97)

Upon seeing the login screen, hit `other user` and you should see that now you're signing into the domain `4pfsec`.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2F9qAhoIZo10snLaj83hdm%2Fimage.png?alt=media\&token=86b682bc-a76d-490b-8074-37e4981c026e)

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FmqWk8ECYJvhBSr9MnMaC%2Fimage.png?alt=media\&token=bb7c3fd2-6f8d-47cc-a79f-d54acc98c43a)

### Verify Domain Join

Now that we have successfully joined the domain, we can verify this over on the Server. Head to `Tools > Active Directory Users and Computers` on Server Manager.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FWhW50fQUYvGhPPVBCCmz%2Fimage.png?alt=media\&token=f54bc19a-dbdb-4fad-8b79-aa3c6b8bc693)

Next, hit `Computers` and you should be able to see your newly domain joined computer as shown below.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FVsxxdMPAeJoMM35kHmjQ%2Fimage.png?alt=media\&token=08f3a8c0-0470-44cf-8da2-b6fed9da5b83)

## Set up Local Administrators

First, login to the endpoint using the Domain Admin account.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FHVnQSbJywXhdPcXxzQ2T%2Fimage.png?alt=media\&token=9b6a11b2-85e1-4567-8707-c6b950404778)

Next, open up computer management.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2Fp1CcMRktv5p29D9yTcst%2Fimage.png?alt=media\&token=cbedfd7f-2976-495a-930f-1000f7a5274a)

Under Local Users and Groups, head to Groups and select Administrators.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2F5WN7ah9vsmMPSydIStQn%2Fimage.png?alt=media\&token=2ce1f00f-27f5-4050-81a8-97548793295f)

Now hit add, enter a partial name and hit `check names`. It should auto complete if the user is detected. Hit `ok` after the user autocompletes.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FQ8nUi00NnKCj0Y50rU0e%2Fimage.png?alt=media\&token=f830e56b-4b56-4563-8532-4d116f4c5876)

You can opt to add more administrators into your lab for various reasons.

## Enable Network Discovery (SMB/Print Service)

Head over to `Control Panel\Network and Internet\Network and Sharing Center\Advanced sharing settings` on your control panel and turn `Network Discovery` and `File and Printer Sharing` on as shown below.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2F1oLcerbGeZXAZUnavKQp%2Fimage.png?alt=media\&token=0f745d94-ee48-47dc-b750-e70f354fc5c7)

### Test Network Discovery

Type `\\{DCName}` into explorer to see if the shares show up. If the shares you setup on the DC shows up, you're all set.

![](https://1937192737-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObuEPM0wMmlYGGoxYCbD%2Fuploads%2FAszGSTh2iHoS5WdS5VN7%2Fimage.png?alt=media\&token=fd3e61ba-bd09-4df3-b0ec-9b3651e25dff)


# Introduction

This section is in progress.


