🚨 Workshop Spotlight #9 👉 "Killing Active Directory Attack Paths Once and For All"
by Spencer Alessi (@techspence), Sr. Penetration Tester at @SecurIT360
📝 Description
Active Directory attack paths are what turn small weaknesses into full domain compromise.
After pentesting 150+ organizations in the last 5 years and performing over 1,000 hours of internal pentesting in 2025 alone, one of the biggest security mistakes I see IT Admins make is logging into untrusted workstations with their Domain Admin account.
In this workshop, we’re going to learn how easy it is for an attacker to compromise a domain from an untrusted workstation and how to prevent it, even if the attacker has Domain Admin (DA) credentials.
We’ll cover:
- Why Active Directory (AD) still matters
- AD attack path pre-requisites
- Two common lateral movement attacks
- Hardening controls to block these two attack paths
Not only will you be able to play the role of the attacker and carry out the attacks yourself, but you’ll also be put in the defender seat and guided through setup and configuration of security controls in Active Directory to block the attacks.
If you’re responsible for managing and/or securing Active Directory, this workshop is for you.
🎟️ Only at ContinuumCon 2026: June 12-14
Work through it live, or revisit the lab on your own time. Own it forever. The workshop doesn't end when the conference does.
Got your ticket yet? 👉 https://t.co/N7pFB85xsS
Hosted by @_JohnHammond, @JustHackingHQ, @AnthonyBendas, and @Level_Effect !
6pts clear at 3rd & there’s a meltdown on the timeline after a draw without 3/4 key players una we were sitting 17th praying we don’t get relegated this time last season & ppl were content with that btw