Home
Talks
CFP Guide
What is BSides?
About
Contact
Light
← All talks
Topic
Active Directory talks at BSides
172 talks tagged
Active Directory
from 69 chapters of BSides events worldwide.
Related topics
Technical
Red
Talk
Blue
Purple
Intermediary
51:35
Attacking Kerberos: Kicking the Guard Dog of Hades
Tim Medin
BSides Orlando
· 2015
Technical
Active Directory
Kerberos
Intermediary
Red
Talk
Open →
2015-11
48:21
PowerShell Security: Defending the Enterprise from the Latest Attack Platform
Sean Metcalf
BSides DC
· 2016
Technical
Active Directory
Blue
Talk
Open →
2016-10
1:05:41
Hunting for Credential Dumping Attacks in Modern Windows Environments
Andrew Case
BSides Philly
· 2023
Technical
Active Directory
DFIR
Malware Analysis
Blue
Talk
Open →
2024-01
36:58
Cracking The Perimeter: How Red Teams Penetrate
Dominic Chell
BSides Manchester
· 2018
Technical
Active Directory
Malware Analysis
Advanced
Red
Talk
Open →
2018-08
30:07
Local Admin in less than 60 seconds
Nikos Vourdas
BSides Budabest
· 2024
Technical
Active Directory
Kerberos
Vulnerability Research
Red
Technical Deep-dives
Talk
Open →
2025-01
51:46
Understanding and Attacking Delegations in Active Directory
Venkatraman K
BSides SATX
· 2021
Technical
Active Directory
Kerberos
Red
Demo
Talk
Open →
2021-06
50:12
Active Directory Password Blacklisting
Leeren Chang
BSides Las Vegas
· 2018
Technical
Active Directory
Blue
Demo
Talk
Open →
2018-09
55:18
Windows Credential Attacks and Mitigations
Chad Tilbury
BSides SLC
· 2017
Technical
Active Directory
Purple
Red
Talk
Open →
2017-07
1:12:47
Metlstorm's Empiricism Emporium: Unpleasant Truths Our Speciality
Adam Boileau
BSides Wellington
· 2017
Technical
War Stories
Active Directory
Kerberos
Supply Chain Security
Threat Intel
Advanced
Red
+1
Open →
2018-02
27:36
Requiem For An Admin: Orchestrating BloodHound and Empire for Automated AD Post-Exploitation
Walter Legowski
BSides Amsterdam
· 2017
Technical
Active Directory
Red
Demo
Open →
2017-09
48:41
Offensive Ansible For Red Teams
Leo McCavana
BSides Belfast
· 2020
Technical
Active Directory
Tooling
Red
Demo
Talk
Open →
2020-01
8:43:32
Passwords, Policies, Securing, Cracking and More
Derek Melber
BSides Las Vegas
· 2023
Technical
Active Directory
Cloud IAM
Kerberos
Talk
Open →
2023-08
29:35
LSASS - What should we be doing?
Robert Wilson
BSides Augusta
· 2021
Technical
Active Directory
Threat Modeling
Intermediary
Blue
Talk
Open →
2021-10
49:52
Abusing Windows with PowerShell and Microsoft debuggers
Pierre-Alexandre Braeken
BSides DC
· 2016
Technical
Active Directory
Advanced
Red
Talk
Open →
2016-10
44:54
A Quick, Efficient Yet Not Entirely Sane Introduction to Deception
John Strand
BSides Frankfurt
Technical
Active Directory
Detection Engineering
Intermediary
Blue
Demo
Talk
Open →
2025-03
48:55
AD CS means "Active Directory is Cheese (Swiss)" - Misconfigurations & Remediation
Jake Hildreth
BSides Charm
· 2022
Technical
Active Directory
Cryptography
Talk
Open →
2022-07
27:32
Access Control with Concierge: One Tool to Rule Them All
Karthik Rangarajan
BSidesSF
· 2017
Technical
Active Directory
Cloud IAM
Talk
Open →
2017-03
51:17
BSidesSF 2023 - Advanced Attack Vectors in Azure Environments (Zur Ulianitzky, Bill Ben Haim)
Zur Ulianitzky
Bill Ben Haim
BSidesSF
· 2023
Technical
Active Directory
Cloud IAM
Advanced
Red
Technical Deep-dives
Talk
Open →
2023-05
32:59
EDR Evasion Primer
Jorge Gimenez
BSides Berlin
· 2022
Technical
Active Directory
Malware Analysis
Advanced
Red
Technical Deep-dives
Talk
Open →
2023-02
40:27
The Insider - Users
Neil Lines
BSides London
· 2018
Technical
Active Directory
Talk
Open →
2018-06
32:33
L0ss sans C St0 - PAMdemonium! Privileged Access Management
BSides Perth
· 2023
Technical
Active Directory
Cryptography
Vulnerability Research
Advanced
Red
Talk
Open →
2023-08
48:49
Demystifying Common Active Directory Attacks | Venkatraman K | BSides Delhi 2020
Venkatraman K
BSides Delhi
· 2020
Technical
Active Directory
Kerberos
Red
Talk
Open →
2020-11
52:17
The Current State of Microsoft Identity Security: Common Security Issues
Sean Metcalf
BSides Charm
· 2024
Technical
Active Directory
Cloud IAM
Threat Intel
Blue
Case Studies and Incidents Analysis
Talk
Open →
2024-06
31:05
Advanced Persistent Teenagers: Understanding the Lapsus$ Playbook
Benjamin Hering
BSidesSF
· 2024
Technical
Active Directory
Social Engineering
Threat Intel
Case Studies and Incidents Analysis
Talk
Open →
2024-07
1:07:30
BSIDESLV 2018 - Proving Ground - Day One
Erik Bryan
BSides Las Vegas
· 2018
Technical
Active Directory
Vulnerability Research
Talk
Open →
2018-08
17:17
The Ace is the Place: Stealthy LDAP Domain Reconnaissance - BSides Portland 2022
Garrett Foster
BSides PDX
· 2022
Technical
Active Directory
Red
Talk
Open →
2022-10
22:26
Treat the Problems, Not the Symptoms
Igal Gofman
Yaron Shani
BSidesSF
· 2019
Technical
Active Directory
Talk
Open →
2019-03
54:52
Protecting the Forest, Starting at the Roots: AD Hardening & Defence using Modern Techniques
James Spencer
BSides Canberra
· 2025
Technical
Active Directory
Kerberos
Intermediary
Blue
Talk
Open →
2025-11
12:24
PE03 - Dumping LSASS when Debug Privilege is Disabled - Bleon Proko
Bleon Proko
BSides Athens
Technical
Active Directory
Advanced
Red
Talk
Open →
2024-06
34:29
BSides DC 2017 - Beyond the Domain: Exploiting Hidden Critical Assets on Red Teams
Brandon Arvanaghi
BSides DC
· 2017
Technical
Active Directory
Red
Talk
Open →
2017-10
47:32
Up Is Down Black Is White: SCCM for Offense and Defense
Matt Nelson
Will Schroeder
BSides Boston
· 2016
Technical
Active Directory
Tooling
Intermediary
Purple
Talk
Open →
2016-08
9:17:44
2016 BSides - Breaking Ground - Day Two
BSides Las Vegas
Technical
Active Directory
Vulnerability Research
Red
Talk
Open →
2025-07
52:07
Purple View
Haydn Johnson
Laura Rafferty
BSides Toronto
· 2015
Technical
Active Directory
Purple
Talk
Open →
2015-11
57:12
Assume Breach: Practical Active Directory Abuses
Ko Steve Nyan Lin
BSides Myanmar
· 2020
Technical
Active Directory
Red
Talk
Open →
2021-01
50:50
Push comes to shove: exploring SCCM attack paths - Brandon Colley
Brandon Colley
BSides KC
· 2022
Technical
Active Directory
Red
Demo
Talk
Open →
2022-10
24:50
The Top 5 Ways I Own Your Internal Network
Heath Adams
BSides RDU
· 2019
Technical
Active Directory
Kerberos
Intermediary
Blue
Red
Demo
Talk
Open →
2019-10
45:25
Active Directory Enumeration with LDAP
Stephen Bradshaw
BSides Canberra
· 2024
Technical
Active Directory
Talk
Open →
2024-10
43:12
Tracking Malicious Logon: Visualize and Analyze Active Directory Event Logs
Shusei Tomonaga
Tomoaki Tani
BSides Las Vegas
· 2018
Technical
Active Directory
DFIR
Threat Intel
Blue
Talk
Open →
2018-09
40:55
Quando o Simples Vence: Anatomia Real dos Ataques que Continuam Funcionando
Ricardo Tavares
BSides São Paulo
· 2025
War Stories
Active Directory
Detection Engineering
Malware Analysis
Threat Intel
Blue
Purple
Case Studies and Incidents Analysis
+1
Open →
2025-06
32:39
Unpacking Impacket: Detect remote execution of offensive tools
Tyler Bohlmann
BSides SLC
· 2022
Technical
Active Directory
DFIR
Detection Engineering
Blue
Talk
Open →
2023-01
44:29
0xDEAD: Domain Exploitation and Domination
Jon Milkins
Bsides CT
· 2025
Technical
Active Directory
Threat Modeling
Intermediary
Red
Case Studies and Incidents Analysis
Talk
Open →
2025-12
32:47
Domain Persistence in Active Directory: Detection, Triage, and Recovery
Nicolas Shyne
BSides Belfast
· 2025
Technical
Active Directory
Kerberos
Blue
Talk
Open →
2025-02
27:22
Pentests: The Jason Bourne Approach — Turning Regular Biros Into Weapons
Andy Gill
BSides Leeds
· 2023
War Stories
Active Directory
Social Engineering
Red
Talk
Open →
2023-07
18:48
Think You're Stealthy? How to Detect Attacks in AD
Rachit Arora
Sai Sathvik Ruppa
Aakash Raman
BSides Charm
· 2025
Technical
Active Directory
DFIR
Detection Engineering
Intermediary
Blue
Talk
Open →
2025-05
35:12
Using BloodHound as a Defender: Tips from the Red Team
Andrew McNicol
BSides Charm
· 2024
Technical
Active Directory
Detection Engineering
Threat Modeling
Blue
Talk
Open →
2024-06
32:16
Breaking Entra: Real-World Cloud Identity Attacks You Can Recreate
Tomer Nahum
Jonathan Elkabas
BSides Frankfurt
· 2025
Technical
Active Directory
Cloud IAM
Intermediary
Blue
Red
Technical Deep-dives
Demo
+1
Open →
2025-12
18:50
The Top 5 Ways I Own Your Internal Network
Heath Adams
BSides Charleston
· 2019
Technical
Active Directory
Kerberos
Network Security
Red
Talk
Open →
2019-11
43:36
The Count's A-to-Z of Windows Privilege Escalation
Lukasz Gogolkiewicz
BSides Canberra
· 2018
Technical
Active Directory
Red
Talk
Open →
2018-08
25:40
Red and Blue Ping Pong: Living Off the Land in Windows Attack and Defense
Lee Kagan
Anton Ovrutsky
BSides Toronto
· 2017
Technical
Active Directory
Malware Analysis
Purple
Demo
Talk
Open →
2018-01
57:04
Network Segmentation without a Network Engineer
Mike Burns
BSides Charm
· 2024
Technical
Active Directory
Detection Engineering
Network Security
Talk
Open →
2024-06
45:25
How occult ransomware gangs will sacrifice your domain admin
Nikos Mantas
BSides Tallinn
· 2021
Technical
Active Directory
Case Studies and Incidents Analysis
Talk
Open →
2021-11
18:14
Make Red Teaming Fun Again
Redon Gashi
BSides Prishtina
· 2022
Technical
Active Directory
OSINT
Social Engineering
Red
Talk
Open →
2022-05
1:02:12
Pentesting: Tips, Tricks and Stories
Patrick Laverty
Aaron Herndon
Bsides CT
· 2018
Technical
Active Directory
OSINT
Social Engineering
Threat Intel
Red
Talk
Open →
2018-11
56:12
Kerberos Authentication in Plain Urdu - Part 1
Said Wali
BSides Pakistan
Technical
Active Directory
Kerberos
Talk
Open →
2021-08
21:55
LSA-Reaper: A Remote LSASS Extraction Tool
Daniel Cornett
BSides Augusta
· 2023
Technical
Active Directory
Malware Analysis
Reverse Engineering
Advanced
Red
Talk
Open →
2023-10
27:15
Abusing Azure Arc: From Service Principal Exposed To Reverse Shell
Christian Bortone
BSides Leeds
· 2024
Technical
Active Directory
Cloud IAM
Advanced
Red
Technical Deep-dives
Talk
Open →
2024-07
45:57
Identity Security Pitfalls: Common Issues and Misconfigurations in Entra ID
Alistair Pugin
BSides Joburg
· 2025
Technical
Active Directory
Cloud IAM
Talk
Open →
2025-08
50:12
Protect Your Most Sensitive Users With the Protected Users Group
Jake Hildreth
BSides Charm
· 2024
Technical
Active Directory
Kerberos
Blue
Talk
Open →
2024-06
26:03
Pwning Zee Cloud: Microsoft Edition
Alberto Rodriguez
BSides Augusta
· 2021
Technical
Active Directory
Cloud IAM
Blue
Red
Talk
Open →
2021-10
24:38
A Practical Approach to Hacking an Enterprise with YASUO
BSides Toronto
· 2014
Technical
Active Directory
Red
Talk
Open →
2014-12
28:47
We Have C2 at Home - Leveraging Microsoft's C2 Framework
Garrett Foster
BSides PDX
· 2023
Technical
Active Directory
Intermediary
Red
Talk
Open →
2023-11
40:07
Active Directory ain't going anywhere, so we might as well secure it
Eric Woodruff
BSides KC
Technical
Active Directory
Blue
Talk
Open →
2024-05
49:40
Top 10 AD Mistakes that can lead to being Pwned
Adam Steed
BSides San Diego
· 2017
Technical
Active Directory
Kerberos
Blue
Talk
Open →
2017-01
46:05
From NTLM to Kerberos: The Evolution of Authentication Relaying Attacks
Alberto Rodriguez
BSides Augusta
· 2025
Technical
Active Directory
Kerberos
Red
Talk
Open →
2025-10
51:40
Let the Children Play — Leveraging ADCS for Persistence in Parent-Child Configured Forests
Tinus Green
BSides Cape Town
· 2023
Technical
Active Directory
Kerberos
Vulnerability Research
Advanced
Blue
Red
Technical Deep-dives
+1
Open →
2023-12
6:06:45
BSides Delaware 2017 - Day 2
Alex Rubin
BSides Delaware
· 2017
Technical
Active Directory
Reverse Engineering
Tooling
Red
Talk
Open →
2017-11
12:49
An Off-The-Cuff Filler Talk By The Mentor Of #CloudWhistler
BSides London 2025
Career
Active Directory
Intro
Blue
Talk
Open →
2026-03
40:23
Ten Ways to Frustrate Attackers in 2023
Justin Palk
BSides Charm
· 2023
Technical
Active Directory
Network Security
Vulnerability Research
Red
Talk
Open →
2023-06
45:49
Scan Pwn Next! – exploiting service accounts in Windows
Andrey Dulkin
Matan Hart
BSidesSF
· 2016
Technical
Active Directory
Kerberos
Vulnerability Research
Red
Talk
Open →
2016-04
31:15
Unconditionally Conditional – Strong Authentication in Microsoft Entra ID
Don Mallory
BSides Toronto
· 2023
Technical
Active Directory
Cloud IAM
Blue
Talk
Open →
2023-11
41:33
Use What You Have
Corey Bussard
BSides Peru
· 2023
Technical
Active Directory
Detection Engineering
Network Security
Blue
Talk
Open →
2023-08
47:01
Nightmare on NTLM Street: Legacy's Revenge
Marina Bochenkova
BSides Lisbon
· 2025
Technical
War Stories
Active Directory
Kerberos
Talk
Open →
2025-12
45:14
The Art of Infiltration: Leveraging Trusted Relationships
Vladimir Ožura
BSides Zagreb
Technical
Active Directory
DFIR
Threat Intel
Blue
Case Studies and Incidents Analysis
Talk
Open →
2025-03
29:50
Harvesting Low-Hanging Fruit in Red Teaming Exercises
Nick Kapellos
BSides Athens
· 2024
Technical
Active Directory
Kerberos
Vulnerability Research
Red
Talk
Open →
2024-03
45:47
Bye Bye NTLM
Evgenij Smirnov
BSides Berlin
· 2023
Technical
Active Directory
Kerberos
Blue
Talk
Open →
2024-01
37:01
BSides Sofia 2022: AD Reconnaissance Red Team Exercise in Finding Hidden AD Relationships
Kristian Mladenov
Tsvyatko Bikov
BSides Sofia
· 2022
Technical
Active Directory
Red
Talk
Open →
2022-04
32:09
BSides DC 2019 - Digital Canaries in Coal Mines: Detecting Adversarial Enumeration with DNS & AD
Stephan Borosh
BSides DC
· 2019
Technical
Active Directory
Talk
Open →
2019-10
37:13
Wild Wild Web App to Domain Admin: A Case Study
Nacho Sorribas
BSides Lisbon
· 2017
Technical
Active Directory
Web AppSec
Case Studies and Incidents Analysis
Talk
Open →
2017-11
42:50
Privilege Escalation Capabilities in AD Certificate Services
Brady McLaughlin
BSides Charlotte
· 2025
Technical
Active Directory
Vulnerability Research
Blue
Red
Technical Deep-dives
Demo
Talk
Open →
2025-05
49:51
Movement After Initial Compromise
Matthew Batten
Collyn Hartley
BSides Augusta
· 2018
Technical
Active Directory
Threat Intel
Red
Talk
Open →
2018-11
27:28
Profiling "VIP Accounts" Access Patterns in User-Centric Data Streams
Rod Soto
Joseph Zadeh
Xiodan Li
BSidesSF
· 2019
Technical
Active Directory
Detection Engineering
Kerberos
Threat Intel
Talk
Open →
2019-03
27:26
Don't Turn Your Back on Ransomware
BSides Newcastle
· 2022
Technical
Active Directory
DFIR
Malware Analysis
Demo
Talk
Open →
2022-09
59:02
My Pen Test Toolbox
Octavio Paguaga
BSides NoVa
· 2021
Technical
Active Directory
Kerberos
Threat Intel
Red
Talk
Open →
2021-07
26:59
The Katz Out Of The Bag
Sándor Fehér
BSides Budabest
· 2019
Technical
Active Directory
Kerberos
Malware Analysis
Intermediary
Blue
Technical Deep-dives
Talk
Open →
2019-06
44:25
Domain Persistence- Detection, Triage, and Recovery - Joshua Prager
Joshua Prager
BSides SATX
· 2024
Technical
Active Directory
Blue
Red
Talk
Open →
2024-06
39:41
Catch Me if You Can
Michael Bryant
BSides Asheville
· 2016
Technical
Active Directory
Detection Engineering
Threat Intel
Red
Talk
Open →
2018-06
43:38
Passwords: Policies, Securing, Cracking, and More
Derek Melber
BSides Las Vegas
· 2023
Technical
Active Directory
Kerberos
Talk
Open →
2023-10
13:24
Turning To The Dark Side: Utilizing Offensive Techniques In Incident Response
Archie Essien
BSides London
· 2025
Technical
Active Directory
DFIR
OSINT
Threat Intel
Talk
Open →
2025-02
23:50
"Identifying and Abusing Vulnerable Configurations in MS AD Group Policy" - Mike Loss
Mike Loss
BSides Canberra
· 2018
Technical
Active Directory
Talk
Open →
2018-08
42:59
Go Hack Yourself
Jason Frank
BSides Augusta
· 2015
Technical
Active Directory
Network Security
Vulnerability Research
Talk
Open →
2015-09
18:17
Top Ways I Still Hack Your Company (and How to Defend Against Them)
Bennett Warner
BSides Charm
· 2024
Technical
Active Directory
Network Security
Vulnerability Research
Web AppSec
Red
Talk
Open →
2024-06
32:23
The Emotional Rollercoaster That Is Penetration Testing
Kurt Pomeroy
BSides Vancouver
· 2022
Career
War Stories
Active Directory
Malware Analysis
Red
Talk
Open →
2022-07
33:43
Operation Grand Mars: Defending Against Carbanak
Thanassis Diogos
BSides Athens
· 2017
Technical
Active Directory
DFIR
Malware Analysis
Blue
Case Studies and Incidents Analysis
Talk
Open →
2017-10
51:28
Measures for Securing Privileged Users in M365&Azure Every Organization Should Take by Eric Woodruff
Eric Woodruff
BSides Tampa
Technical
Active Directory
Cloud IAM
Blue
Talk
Open →
2024-05
41:57
Lying to your fACE: Deploying an ADCS honeypot the easy way
Zdravko Petričušić
Josip Pavičić
BSides Zagreb
· 2026
Technical
Active Directory
Detection Engineering
Threat Intel
Blue
Technical Deep-dives
Talk
Open →
2026-03
38:29
Fantastic Persistence: Creative backdoors & where you will NOT find them
Yossi Sassi
BSides Budabest 2025
Technical
Active Directory
DFIR
Detection Engineering
Demo
Talk
Open →
2026-03
37:26
Identity At Risk: Identity-Centric Threat Modeling - Apostolos Giannakidis
Apostolos Giannakidis
BSides Dublin
· 2024
Technical
Active Directory
Cloud IAM
Threat Modeling
Talk
Open →
2024-06
43:44
Bridging Clouds and Domains, Expanding Risks
Guillaume Bossiroy
BSides Limburg
· 2026
Technical
Active Directory
Cloud IAM
Blue
Red
Demo
Talk
Open →
2026-04
26:16
Chris Horner - How to Lose Your Credentials and Gain a New Domain Admin
Chris Horner
BSides Augusta
· 2025
Technical
Active Directory
Red
Talk
Open →
2025-10
42:59
Icebreaker: From internal jumpbox to domain admin in one command
Dan McInerney
BSides SLC
· 2018
Technical
Active Directory
Kerberos
Red
Talk
Open →
2018-12
View all 172 talks tagged Active Directory →