The Red Team Fundamentals for Active Directory (RTFM4AD) course is a two-day class focused on explaining the fundamentals of Active Directory and how different aspects can be exploited when performing penetration tests.
Next scheduled date:March 23rd, 2026 @ 10:00 AM EDT
Description
The Red Team Fundamentals for Active Directory (RTFM4AD) course is a two-day class focused on explaining the fundamentals of Active Directory and how different aspects can be exploited when performing penetration tests. The goal is to not only cover different attacks, but also explain the details of why they work and how an environment can be made resilient to them and potentially detect malicious activity. This combination opens the course to those looking to hone their offensive skills, as well as those who are protecting an enterprise network.
The course mixes lecture with a number of hands-on exercises to reinforce the information and techniques. The activities will cover ways to examine an Active Directory environment, looking for a variety of misconfigurations which are commonly seen in Active Directory implementations (even by some security conscious entities), and then exploit these issues to pivot and escalate our access.
Students will be provided access to a lab to learn both the attacks and defenses while in class which will contain realistic targets and tools. This environment enables the attendees to understand how the covered techniques are used in the real world.
By the end of the course, students will be able to:
Perform structured AD enumeration using native and third‑party tools
Identify high‑value targets and privilege escalation paths
Understand and weaponize key AD attack primitives (Kerberoasting, DCSync, PtT, RBCD, etc.)
Analyze and exploit misconfigurations in domains, forests, and trust relationships
Apply credential harvesting and abuse techniques ethically
Understand defensive logs and how attacks manifest for blue teams
Approach enterprise AD environments with a red‑team mindset
While attendees don’t necessarily need any prior security experience to take this course, they will get the most out of it with a basic grasp of the following:
Windows Operating Systems
PowerShell
System Requirements
Windows or MacOS system that can run the Amazon Workspaces Client (https://clients.amazonworkspaces.com/ ) and Remote Desktop / Windows App
Lab Information
Access to the AWS hosted lab will be provided on the first day of the class.
This course is suitable for students who are new to using PowerShell and/or testing Windows networks, but it helps to have some general networking and Windows experience.
Eric Kuehn is a principal security consultant at Secure Ideas, as well as an IANS faculty member. He leverages his extensive experience with Microsoft infrastructures and Active Directory to perform penetration tests and offer guidance on system security and architecture. He also is the author of the “Red Team Fundamentals for Active Directory” course, where he explains the concepts, techniques, and best practices for exploiting and defending AD environments. Eric has been working with Active Directory since its release and was the technical leader and architect of one of the largest and most complex AD implementations out there. He holds the CISSP certification and is passionate about sharing his knowledge and skills with others. Eric has delivered talks on Active Directory security and other topics at various conferences, events, and webcasts, and via Antisyphon Training.
• Virtual Ticket to WWHF • $100 off next AT class • 12 months Cyber Range Access • T-Shirt • The Future Is ****** comic • Sticker Pack • Certificate of completion • 6 months class recording access via Discord • Pay it forward to 6 students • Free ACE-T Core certification test
• $50 off next AT class • 12 months Cyber Range Access • T-Shirt • The Future Is ****** comic • Sticker Pack • Certificate of completion • 6 months class recording access via Discord • Pay it forward to 3 students • Free ACE-T Core certification test
• T-Shirt • The Future Is ****** comic • Sticker Pack • Certificate of completion • 6 months class recording access via Discord • Pay it forward to 1 student • Free ACE-T Core certification test
• Certificate of completion • 6 months class recording access via Discord • Our appreciation for supporting PFWYC Training • Free ACE-T Core certification test
For tuition assistance with this course please send an email to: [email protected]