As a red teamer and penetration tester, I’ve compromised several networks from small/medium businesses to enterprises in a very short time via Active Directory exploits that take advantage of default policy settings or common misconfigurations. Often times, businesses will focus on a vulnerability scan to gauge their vulnerability posture when in reality, 90% of engagements are done purely through exploiting Active Directory — something vulnerability scans miss.. This presentation highlights some of the most common and recent attacks I’ve conducted in an AD environment, from a technical overview to live demonstrations. In addition, mitigations for these attacks are given and can be accomplished without needing any paid tools. This talk is targeted to both red teamers and blue teamers