Zero2AD — Ethical Hacking & Active Directory, From Basics to Domain Admin

Course Description

Zero2AD is a hands-on cybersecurity course that takes learners from networking and security fundamentals through offensive security techniques, culminating in Active Directory exploitation and full domain compromise. Through 16 progressive modules and practical lab exercises, learners build the skills needed to perform real-world penetration testing — from reconnaissance to Domain Admin — in an ethical, authorized lab environment. Learning Outcomes By the end of this course, learners will be able to: Perform reconnaissance, scanning, and vulnerability analysis on target systems. Exploit common vulnerabilities and escalate privileges on Windows and Linux systems. Enumerate and map Active Directory environments to identify attack paths. Execute credential and Kerberos-based attacks to gain and escalate domain access. Chain techniques together to compromise a domain and report findings professionally.

Course Fee Seats Limited

₹1800.00

Course Details

Duration
Duration
70 HRS
Duration
Course Label
SkillDevelopment
Certificate
Certificate
Yes
Course Language
English
Duration
Course Mode
Online
Duration
Timings
6 PM - 8 PM
Days
Monday to Friday
Registration Till
10 Aug 2026
Duration
Tentative ClassStart Date
4th Week of August
Duration
Eligible Schools:
Certificate Criteria
Certificate Criteria
75% attendance, 50% score in all Exams/CA

Curriculum Snapshot

Explore the comprehensive course modules

1 - Set up Kali Linux (VM / WSL / bare metal) - Set up a Windows Server as a Domain Controller - Join Windows 10/11 client VMs to the domain - Networking refresher: IP addressing, subnetting, ARP - DNS and DHCP fundamentals - Ethical legal framework, rules of engagement - Pentest methodology overview (PTES / MITRE ATTCK) - TCP/IP deep dive: 3-way handshake, common ports/services - Linux CLI mastery: filesystem, permissions, bash basics - Windows CLI PowerShell basics, WMI - AD concepts intro: forests, domains, OUs, GPOs - Default AD groups (Domain Admins, Enterprise Admins) - Lab: Build a 3-machine lab (Kali attacker, DC, workstation) - Basic Bash and PowerShell scripting for automation - Intro to Python for security tooling - Lab: Write a simple script to automate a repetitive lab task

Goal: Stand up the attack lab and get comfortable with core Linux/Windows/networking concepts before touching offensive tools.

2 - Passive recon: OSINT, Google dorking, Shodan - DNS enumeration zone transfers - Nmap fundamentals: host discovery, port scanning, NSE scripts - Banner grabbing service fingerprinting - SMB / NetBIOS / LDAP enumeration basics - Lab: Full Nmap scan + enumeration; write a recon report - Vulnerability scanning tools: Nessus, OpenVAS, Nikto - Reading interpreting CVE / CVSS scores - Manual vs automated vulnerability discovery - Web app scanning basics: Burp Suite, OWASP ZAP - Prioritizing vulnerabilities for exploitation - Lab: Scan a vulnerable VM and produce a prioritized vuln list - Hands-on lab: Burp Suite proxy walkthrough on a test web app - Combining recon + vuln scan results into a full attack surface map - Lab: Deliver a consolidated target profile for a multi-host network

Goal: Learn to map a target environment - hosts, services, shares, and vulnerabilities - before attempting exploitation.

3 - Exploit theory buffer overflow overview - Exploit-DB, searchsploit - Metasploit Framework: msfconsole, modules, payloads - Reverse vs bind shells; payloads with msfvenom - Netcat fundamentals for listeners shells - Lab: Exploit a vulnerable box to gain initial access - Windows priv esc enumeration: winPEAS, Seatbelt - Unquoted service paths, weak service permissions - AlwaysInstallElevated, scheduled tasks - Token impersonation: JuicyPotato, PrintSpoofer - Credential hunting on disk registry - UAC bypass concepts - Lab: Escalate from a low-priv shell to SYSTEM - Linux priv esc enumeration: LinPEAS - SUID/SGID binaries, cron jobs, PATH hijacking - Sudo misconfigurations (GTFOBins) - Lab: Escalate privileges on a vulnerable Linux VM

Goal: Turn a discovered vulnerability into a working shell, then escalate that access to full administrative/root control.

4 - AD architecture: domains, forests, trusts, FSMO roles - NTLM vs Kerberos - deep technical walkthrough - Kerberos ticket flow: AS-REQ/REP, TGT, TGS-REQ/REP - Group Policy Objects how they're abused - ACLs, ACEs, and SPNs in AD - Lab: Map a domain with BloodHound / SharpHound - Authenticated vs unauthenticated AD enumeration - BloodHound + SharpHound, PowerView, ADRecon - Identifying Kerberoastable AS-REP roastable accounts - Finding misconfigured permissions (GenericAll, WriteDACL) - Lab: Run SharpHound; analyze attack paths in BloodHound - Password spraying (lockout-safe methodology) - LLMNR / NBT-NS poisoning with Responder

Goal: Understand how Active Directory works and learn to enumerate it thoroughly before attacking it.

5 - SMB relay attacks with ntlmrelayx - Exploiting misconfigured services (null sessions, anon FTP) - Lab: Capture relay NTLM hashes for domain access - Kerberoasting: theory + Rubeus / GetUserSPNspy - Cracking captured hashes with Hashcat - AS-REP Roasting: theory and execution - Golden Tickets: forging TGTs with the krbtgt hash - Silver Tickets: forging TGS tickets for a service - Delegation abuse: unconstrained, constrained, RBCD - Overpass-the-Hash / Pass-the-Key - Lab: Kerberoast, crack the hash, run a Golden Ticket attack - AD CS / PKI fundamentals in Windows environments - Enumerating certificate templates with Certipy/Certify - ESC1-ESC8 misconfiguration classes - Lab: Escalate to Domain Admin via ESC1

Goal: Execute credential and Kerberos-based attacks and abuse AD Certificate Services to escalate toward Domain Admin.

6 - Pass-the-Hash (PtH) and Pass-the-Ticket (PtT) - Remote execution: PsExec, WMIExec, Evil-WinRM - Living-off-the-land binaries (LOLBins) - Pivoting: SSH tunneling, Chisel, Ligolo-ng - Lab: Pivot through hosts to a segmented subnet - ACL abuse chains: GenericAll, WriteOwner, WriteDACL - DCSync attack: extracting hashes via replication rights - AdminSDHolder abuse; GPO abuse for persistence - Shadow credentials (msDS-KeyCredentialLink) - Lab: Chain an ACL misconfiguration into a DCSync attack - Capstone: chain recon -> access -> priv esc -> AD enum - Kerberos/ACL abuse -> lateral movement -> DCSync - Extract ntdsdit and SAM/SYSTEM hives - Lab: Full domain compromise, foothold to Domain Admin

Goal: Move across the network from a single compromised host, and establish footholds that survive password changes and reboots.

7 - Writing a professional pentest report structure - Executive summary, findings, and risk ratings - Mapping findings to MITRE ATTCK - Report writing workshop: drafting findings from your own capstone lab - Sample report walkthrough (real-world report structure) - Peer review exercise on draft findings - Communicating risk to non-technical stakeholders - Post-engagement cleanup evidence handling - Certification roadmap: eJPT, OSCP, CRTP, CRTE, OSEP - Course wrap-up QA - Deliverable: final capstone penetration test report

Goal: Translate the technical attack chain into a clear, professional deliverable for both technical and non-technical stakeholders.

Instructor Spotlight

Learn from leading experts in stem cell research

Alok Kumar Ranjan

Alok Kumar Ranjan

Assistant Professor

https://thealokverse.xyz/