Windows’ recent ports of OpenSSH allows admins to access their Windows estate with the same tools as their Linux estate. This talk will show how a misconfigured Windows SSH service combines the worst case scenarios of both AD and SSH and can even allow the theft of plaintext domain credentials. Those well-versed in Active Directory exploitation will see how a few old favourite techniques can be weaponised in a new context, and how the particular quirks of Windows OpenSSH can make them even more potent.