> For the complete documentation index, see [llms.txt](https://htb.linuxsec.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://htb.linuxsec.org/active-directory.md).

# Active Directory

- [Basic Command](https://htb.linuxsec.org/active-directory/basic-command.md): The basic of Command Prompt and PowerShell
- [Enumeration](https://htb.linuxsec.org/active-directory/enumeration.md): Basic Enumeration using Command Prompt and PowerShell
- [PowerView](https://htb.linuxsec.org/active-directory/enumeration/powerview.md): Active Directory Enumeration Checklists with PowerView
- [Service Exploitation](https://htb.linuxsec.org/active-directory/service.md): Basic Service Exploitation in Windows or Active Directory
- [LDAP](https://htb.linuxsec.org/active-directory/service/ldap.md): LDAP Enumeration and Exploitation
- [SMB](https://htb.linuxsec.org/active-directory/service/smb.md): Basic SMB Enumeration and Exploitation
- [MS17-010](https://htb.linuxsec.org/active-directory/service/smb/ms17-010.md): SMB Exploit MS17-010
- [MSSQL](https://htb.linuxsec.org/active-directory/service/mssql.md): Recon and pwning MSSQL Server
- [Privilege Escalation](https://htb.linuxsec.org/active-directory/privilege-escalation.md): Windows Privilege Escalation Checks
- [Unquoted Service Path](https://htb.linuxsec.org/active-directory/privilege-escalation/unquoted-service-path.md): Unquoted Service Paths – Windows Privilege Escalation
- [UAC Bypass](https://htb.linuxsec.org/active-directory/privilege-escalation/uac-bypass.md): Common UAC Bypass Checklists
- [Token Abuse](https://htb.linuxsec.org/active-directory/privilege-escalation/token-abuse.md): Abusing Token for Privilege Escalation
- [Post Exploitation](https://htb.linuxsec.org/active-directory/post-exploitation.md): Active Directory Post Exploitation Checklists
- [Tunneling with Ligolo-ng](https://htb.linuxsec.org/active-directory/post-exploitation/tunneling-with-ligolo-ng.md): Tunneling with Ligolo-ng
- [Credential Hunting](https://htb.linuxsec.org/active-directory/credential-hunting.md): Common technique and tools to hunt credentials on Windows or Active Directory
- [Group Policy Preferences](https://htb.linuxsec.org/active-directory/credential-hunting/group-policy-preferences.md): Finding Passwords in SYSVOL & Exploiting Group Policy Preferences
- [DPAPI](https://htb.linuxsec.org/active-directory/credential-hunting/dpapi.md): Credentials Dumping from Data Protection API
