Game of Active Directory (GOAD): The Ultimate Pentest Lab for Active Directory Attacks Link to heading

A comprehensive guide to the leading open-source lab for Active Directory penetration testing


Introduction: What is GOAD? Link to heading

Game of Active Directory (GOAD) is a revolutionary open-source project by Orange Cyberdefense that provides penetration testers and security professionals with a fully vulnerable Active Directory environment. The project, developed and maintained by Cyril Servières (known as @M4yFly), enables practitioners to practice realistic AD attack techniques in a safe, isolated environment.

The name is a nod to the HBO series “Game of Thrones” – and indeed, all users, domains, and servers are named after characters and locations from Westeros and Essos. This creative design makes the lab not only technically valuable but also entertaining.

The Philosophy Behind GOAD Link to heading

GOAD can be thought of as a “DVWA for Active Directory” – similar to how the Damn Vulnerable Web Application serves web security training, GOAD provides an intentionally vulnerable environment for learning and practice. The goal is clear: to give pentesters a platform where they can train all common AD attack techniques without legal concerns and without risk to production systems.

Important Note: GOAD is extremely vulnerable and should never be deployed in production environments or connected to the internet without proper isolation.


Available Labs Link to heading

GOAD offers various lab variants that cater to different hardware requirements and learning objectives:

1. GOAD (Full Version) Link to heading

The main variant of the lab consists of 5 virtual machines spanning 2 forests and 3 domains:

Domain: sevenkingdoms.local

  • Kingslanding (DC01): Domain Controller on Windows Server 2019 with Windows Defender enabled
  • Administrators: robert.baratheon, cersei.lannister

Domain: north.sevenkingdoms.local

  • Winterfell (DC02): Domain Controller on Windows Server 2019 with Windows Defender enabled
  • Castelblack (SRV02): Server on Windows Server 2019 with Windows Defender disabled, equipped with IIS, MSSQL, and SMB shares
  • Administrators: eddard.stark, catelyn.stark, robb.stark

Domain: essos.local

  • Meereen (DC03): Domain Controller on Windows Server 2016 with Windows Defender enabled
  • Braavos (SRV03): Server on Windows Server 2016 with MSSQL and SMB shares
  • Administrators: daenerys.targaryen, khal.drogo

2. GOAD-Light Link to heading

A more resource-friendly version with 3 VMs, 1 forest, and 2 domains – ideal for users with less powerful hardware.

3. MINILAB Link to heading

The minimal variant with only 2 VMs: one Domain Controller (Windows Server 2019) and one Workstation (Windows 10).

4. SCCM Lab Link to heading

A specialized variant with 4 VMs that includes Microsoft Configuration Manager (SCCM/MECM) – perfect for practicing SCCM-specific attacks.

5. NHA (No Help Available) Link to heading

A challenge lab with 5 VMs and 2 domains where no schema is provided. Here, the attacker must figure out how to compromise the network themselves – ideal for advanced exercises.


System Requirements Link to heading

Installing GOAD requires significant hardware resources:

Resource GOAD-Light GOAD (Full Version)
RAM minimum 20 GB minimum 24-32 GB
Storage ~77 GB (without snapshots) ~115 GB (with VM images)
CPU 4+ cores recommended 8+ cores recommended

The Windows Server VM images require additional storage:

  • Windows Server 2016 image: ~22 GB
  • Windows Server 2019 image: ~14 GB

Supported Platforms and Providers Link to heading

GOAD can be operated on various virtualization platforms and cloud providers:

Local Virtualization:

  • VirtualBox
  • VMware Workstation (now free for personal use)
  • Proxmox

Cloud Providers:

  • AWS
  • Azure

Special Platforms:

  • VMware ESXi
  • Ludus

Installation Link to heading

Prerequisites (Linux) Link to heading

# Install VirtualBox
sudo apt install virtualbox

# Install Vagrant
wget -O- https://apt.releases.hashicorp.com/gpg | sudo gpg --dearmor -o /usr/share/keyrings/hashicorp-archive-keyring.gpg
echo "deb [signed-by=/usr/share/keyrings/hashicorp-archive-keyring.gpg] https://apt.releases.hashicorp.com $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/hashicorp.list
sudo apt update && sudo apt install vagrant

# Install Vagrant Plugins
vagrant plugin install vagrant-reload vagrant-vbguest winrm winrm-fs winrm-elevated

# Additional dependencies
sudo apt install sshpass lftp rsync openssh-client python3.10-venv

Clone and Install GOAD Link to heading

git clone https://github.com/Orange-Cyberdefense/GOAD.git
cd GOAD

# Verify installation
./goad.sh -t check -l GOAD -p virtualbox

# Start installation
./goad.sh -t install -l GOAD -p virtualbox

# Or start interactive mode
./goad.sh

Note: The installation can take several hours. Patience is required!


MITRE ATT&CK Framework Mapping Link to heading

One of the most valuable aspects of GOAD is that it allows practitioners to train real-world attack techniques that are documented in the MITRE ATT&CK framework. Below is a comprehensive mapping of GOAD vulnerabilities to their corresponding ATT&CK techniques.

Quick Reference: MITRE ATT&CK Techniques in GOAD Link to heading

GOAD Vulnerability MITRE ATT&CK ID Technique Name Tactic
AS-REP Roasting T1558.004 Steal or Forge Kerberos Tickets: AS-REP Roasting Credential Access
Kerberoasting T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting Credential Access
Password Spraying T1110.003 Brute Force: Password Spraying Credential Access
LLMNR/NBT-NS Poisoning T1557.001 Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay Credential Access
Golden Ticket T1558.001 Steal or Forge Kerberos Tickets: Golden Ticket Credential Access
Silver Ticket T1558.002 Steal or Forge Kerberos Tickets: Silver Ticket Credential Access
DCSync T1003.006 OS Credential Dumping: DCSync Credential Access
LSASS Dump T1003.001 OS Credential Dumping: LSASS Memory Credential Access
GPO Abuse T1484.001 Domain Policy Modification: Group Policy Modification Defense Evasion, Privilege Escalation
Domain Trust Discovery T1482 Domain Trust Discovery Discovery
Trust Modification T1484.002 Domain Policy Modification: Trust Modification Defense Evasion, Privilege Escalation
Password in LDAP T1552.006 Unsecured Credentials: Group Policy Preferences Credential Access
Password in SYSVOL T1552.006 Unsecured Credentials: Group Policy Preferences Credential Access
Pass-the-Hash T1550.002 Use Alternate Authentication Material: Pass the Hash Defense Evasion, Lateral Movement
Pass-the-Ticket T1550.003 Use Alternate Authentication Material: Pass the Ticket Defense Evasion, Lateral Movement
Unconstrained Delegation T1558 Steal or Forge Kerberos Tickets Credential Access
Constrained Delegation T1558 Steal or Forge Kerberos Tickets Credential Access
ADCS Abuse (ESC1-ESC8) T1649 Steal or Forge Authentication Certificates Credential Access
SMB Null Session T1087.002 Account Discovery: Domain Account Discovery
ACL Abuse T1222.001 File and Directory Permissions Modification: Windows File and Directory Permissions Modification Defense Evasion

Practical Attack Scenarios with MITRE ATT&CK Mapping Link to heading

Scenario 1: From Anonymous Access to Domain Admin Link to heading

This attack chain demonstrates how an attacker can escalate from zero credentials to full domain compromise.

Step Action MITRE ATT&CK ID Technique
1 SMB Null Session on Winterfell T1087.002 Account Discovery: Domain Account
2 Extract user list via LDAP T1069.002 Permission Groups Discovery: Domain Groups
3 AS-REP Roasting on brandon.stark T1558.004 Steal or Forge Kerberos Tickets: AS-REP Roasting
4 Crack hash offline T1110.002 Brute Force: Password Cracking
5 Kerberoasting with compromised account T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting
6 BloodHound enumeration T1087.002 Account Discovery: Domain Account
7 ACL abuse along identified path T1222.001 File and Directory Permissions Modification
8 DCSync to obtain KRBTGT hash T1003.006 OS Credential Dumping: DCSync
9 Golden Ticket creation T1558.001 Steal or Forge Kerberos Tickets: Golden Ticket

Detailed ATT&CK Analysis:

Initial Access → Discovery → Credential Access → Privilege Escalation → Persistence
     ↓              ↓              ↓                    ↓                   ↓
    None       T1087.002      T1558.004           T1003.006           T1558.001
               T1069.002      T1558.003
                              T1110.002

Scenario 2: LLMNR Poisoning Chain Link to heading

This scenario exploits legacy name resolution protocols to capture and relay credentials.

Step Action MITRE ATT&CK ID Technique
1 Start Responder for LLMNR/NBT-NS poisoning T1557.001 Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay
2 Capture NetNTLMv2 hash from eddard.stark T1040 Network Sniffing
3a Crack hash offline (Option A) T1110.002 Brute Force: Password Cracking
3b NTLM Relay to target (Option B) T1557.001 Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay
4 Access with Domain Admin credentials T1078.002 Valid Accounts: Domain Accounts
5 Dump LSASS for additional credentials T1003.001 OS Credential Dumping: LSASS Memory

ATT&CK Kill Chain:

┌─────────────────────────────────────────────────────────────────────────────┐
│ TACTIC          │ TECHNIQUE                                                │
├─────────────────┼───────────────────────────────────────────────────────────┤
│ Collection      │ T1557.001 - LLMNR/NBT-NS Poisoning                       │
│ Credential Access│ T1040 - Network Sniffing                                 │
│ Credential Access│ T1110.002 - Password Cracking                            │
│ Defense Evasion │ T1078.002 - Valid Accounts: Domain Accounts              │
│ Credential Access│ T1003.001 - LSASS Memory Dumping                         │
└─────────────────┴───────────────────────────────────────────────────────────┘

Scenario 3: ADCS Exploitation (ESC8) Link to heading

This scenario demonstrates certificate abuse through NTLM relay to AD Certificate Services.

Step Action MITRE ATT&CK ID Technique
1 PetitPotam coercion (unauthenticated) T1187 Forced Authentication
2 NTLM Relay to ADCS Web Enrollment T1557.001 Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay
3 Request certificate for DC machine account T1649 Steal or Forge Authentication Certificates
4 Pass-the-Certificate for authentication T1550 Use Alternate Authentication Material
5 DCSync with machine account T1003.006 OS Credential Dumping: DCSync
6 Full domain compromise T1558.001 Steal or Forge Kerberos Tickets: Golden Ticket

ADCS ESC Techniques Mapping:

ESC Vulnerability Description Related ATT&CK
ESC1 Enrollee Supplies Subject T1649
ESC2 Any Purpose EKU T1649
ESC3 Certificate Request Agent T1649
ESC4 Vulnerable Certificate Template ACL T1649, T1222
ESC6 EDITF_ATTRIBUTESUBJECTALTNAME2 T1649
ESC8 NTLM Relay to Web Enrollment T1557.001, T1649

Scenario 4: ACL Abuse Chain (Sevenkingdoms Domain) Link to heading

This scenario demonstrates how misconfigured ACLs can be chained for privilege escalation.

Step User Action MITRE ATT&CK ID ACL Exploited
1 tywin.lannister Force password change T1098 ForceChangePassword on jaime.lannister
2 jaime.lannister Modify user attributes T1222.001 GenericWrite on joffrey.baratheon
3 joffrey.baratheon Modify DACL T1222.001 WriteDACL on tyron.lannister
4 tyron.lannister Add self to privileged group T1098.002 Self-Membership on Small Council
5 Small Council Add member to DragonStone T1098.002 AddMember on DragonStone group
6 DragonStone Modify ownership T1222.001 WriteOwner on KingsGuard
7 KingsGuard Full control over user T1098 GenericAll on stannis.baratheon
8 stannis.baratheon Full control over DC T1098 GenericAll on Kingslanding (DC)

ACL Abuse Kill Chain Visualization:

tywin.lannister
      │ ForceChangePassword
      ▼
jaime.lannister
      │ GenericWrite
      ▼
joffrey.baratheon
      │ WriteDACL
      ▼
tyron.lannister
      │ Self-Membership
      ▼
Small Council ──────► DragonStone ──────► KingsGuard ──────► stannis.baratheon
                WriteOwner            GenericAll                    │
                                                                    │ GenericAll on DC
                                                                    ▼
                                                           DOMAIN ADMIN

Scenario 5: Cross-Forest Attack Path Link to heading

This scenario demonstrates trust relationship exploitation between forests.

Step Action MITRE ATT&CK ID Technique
1 Enumerate domain trusts T1482 Domain Trust Discovery
2 Identify foreign group members T1069.002 Permission Groups Discovery: Domain Groups
3 Compromise user in cross-forest group T1078.002 Valid Accounts: Domain Accounts
4 Access resources in trusted forest T1550.003 Use Alternate Authentication Material: Pass the Ticket
5 SID History injection (if enabled) T1134.005 Access Token Manipulation: SID-History Injection
6 Escalate to Enterprise Admin T1558.001 Steal or Forge Kerberos Tickets: Golden Ticket

Included Vulnerabilities and Attack Vectors Link to heading

GOAD offers an impressive collection of vulnerabilities and misconfigurations that reflect typical problems in real Active Directory environments:

Initial Access Vectors Link to heading

Password Spraying (T1110.003)

  • Users like hodor have passwords identical to their username
  • Seasonal passwords like “WinterYYYY” for rickon.stark

AS-REP Roasting (T1558.004)

  • brandon.stark is vulnerable to AS-REP Roasting (no Kerberos Pre-Authentication required)
  • missande in the essos.local domain

Kerberoasting (T1558.003)

  • jon.snow has SPNs configured and is vulnerable to Kerberoasting
  • Service accounts with weak passwords

Passwords in LDAP (T1552.006)

  • samwell.tarly has his password stored in the LDAP description field

Passwords in SYSVOL (T1552.006)

  • tywin.lannister has an encrypted password in SYSVOL
  • jeor.mormont has his password in a SYSVOL script

LLMNR/NBT-NS Poisoning (T1557.001)

  • Bots simulate LLMNR requests for eddard.stark and robb.stark
  • Enables NTLM relay attacks with Responder

Privilege Escalation and Lateral Movement Link to heading

ACL Abuse (T1222.001, T1098) The lab contains numerous ACL-based attack paths:

  • tywin.lannister → ForceChangePassword on jaime.lannister
  • jaime.lannister → GenericWrite on joffrey.baratheon
  • tyron.lannister → Self-Membership on “Small Council”
  • joffrey.baratheon → WriteDACL on tyron.lannister
  • stannis.baratheon → GenericAll on Computer “Kingslanding”
  • lord.varys → GenericAll on Domain Admins and SDHolder
  • khal.drogo → GenericAll on viserys.targaryen (Shadow Credentials)

Kerberos Delegation (T1558)

  • Unconstrained Delegation: sansa.stark
  • Constrained Delegation: jon.snow with S4U2Self abuse

MSSQL Attacks

  • MSSQL Impersonation: samwel.tarlly → sa, arya.stark → dbo
  • MSSQL Trusted Links between Castelblack and Braavos

GPO Abuse (T1484.001)

  • samwell.tarly can edit the “STARKWALLPAPER” GPO

AD Certificate Services (ADCS) (T1649) Link to heading

GOAD includes a complete ADCS installation with vulnerable certificate templates:

  • ESC1: Enrollee Supplies Subject
  • ESC2: Any Purpose EKU
  • ESC3: Certificate Request Agent
  • ESC4: Vulnerable Certificate Template Access Control
  • ESC6: EDITF_ATTRIBUTESUBJECTALTNAME2
  • ESC8: NTLM Relay to AD CS HTTP Endpoints (PetitPotam + ADCS)

Cross-Forest and Cross-Domain Attacks (T1482, T1484.002) Link to heading

  • Bidirectional trust between north.sevenkingdoms.local and sevenkingdoms.local (Child/Parent)
  • Forest trust between essos.local and sevenkingdoms.local
  • Special cross-forest groups: AcrossTheSea, AccrossTheNarrowSea, DragonsFriends, Spys

MITRE ATT&CK Navigator Layer Link to heading

For visual analysis and tracking of techniques practiced in GOAD, you can import the following techniques into MITRE ATT&CK Navigator:

Credential Access Techniques:

  • T1558 (all sub-techniques) - Kerberos Ticket Attacks
  • T1003 (especially .001, .006) - Credential Dumping
  • T1110 (.002, .003) - Brute Force
  • T1557.001 - LLMNR Poisoning
  • T1552.006 - Unsecured Credentials
  • T1649 - Certificate Theft

Privilege Escalation Techniques:

  • T1484 (all sub-techniques) - Domain Policy Modification
  • T1098 - Account Manipulation
  • T1078.002 - Valid Accounts: Domain

Discovery Techniques:

  • T1482 - Domain Trust Discovery
  • T1087.002 - Account Discovery: Domain
  • T1069.002 - Permission Groups Discovery

Lateral Movement Techniques:

  • T1550 (.002, .003) - Pass-the-Hash/Ticket
  • T1021.002 - SMB/Windows Admin Shares

Extensions Link to heading

GOAD offers various extensions that add additional functionality to the lab:

Guacamole Link to heading

A web-based remote desktop solution for easy access to VMs without a local RDP client.

Exchange Link to heading

Microsoft Exchange Server integration for Exchange-specific attack techniques.

ELK Stack Link to heading

Elasticsearch, Logstash, and Kibana for log analysis and monitoring – ideal for learning detection engineering.

Wazuh Link to heading

Open-source SIEM for security monitoring and incident response training.

Additional Workstations (ws01) and Linux Servers (lx01) Link to heading

Extends the lab with additional attack surfaces.


Learning Resources and Writeups Link to heading

The developer @M4yFly has published an extensive 12-part writeup series covering all aspects of the lab:

  1. Reconnaissance and Scanning – Network discovery and service enumeration
  2. Anonymous Enumeration – What’s possible without credentials
  3. Enumeration with User Context – BloodHound and LDAP queries
  4. Poisoning and NTLM Relay – Responder, mitm6, and relay attacks
  5. Exploitation with User Context – Credential harvesting
  6. ADCS Attacks – Certificate abuse
  7. MSSQL Attacks – Impersonation and trusted links
  8. Kerberos Attacks – Golden/Silver tickets
  9. Privilege Escalation – Local privilege escalation
  10. Delegation Attacks – Unconstrained and constrained delegation
  11. ACL Abuse – Access Control List exploitation
  12. Trust Exploitation – Cross-forest and cross-domain attacks

These writeups are available at: https://mayfly277.github.io/categories/goad/


The following tools are recommended for working with GOAD:

Enumeration:

  • BloodHound / SharpHound
  • CrackMapExec (cme) / NetExec
  • ldapdomaindump
  • adidnsdump

Credential Attacks:

  • Responder
  • Impacket Suite (GetUserSPNs, secretsdump, etc.)
  • Hashcat
  • Kerbrute

Exploitation:

  • Certipy (ADCS attacks)
  • Rubeus
  • Mimikatz
  • donPAPI
  • lsassy

Lateral Movement:

  • PsExec
  • WMIexec
  • Evil-WinRM

Best Practices for Working with GOAD Link to heading

1. Keep Documentation Link to heading

Maintain a detailed log of all actions – this improves both learning and reproducibility.

2. Use BloodHound Link to heading

BloodHound is essential for visualizing attack paths. Learn the Cypher query language for advanced queries.

3. Proceed Step by Step Link to heading

Start with simple attacks and work your way up to more complex techniques. GOAD is extensive – take your time.

4. Explore Multiple Paths Link to heading

There are almost always multiple paths to Domain Admin. Try to find and document different routes.

5. Don’t Forget Cleanup Link to heading

When you make changes (e.g., changing passwords or adding SPNs), document them for later reversal.

6. Map to MITRE ATT&CK Link to heading

Use the ATT&CK framework to categorize and document the techniques you practice. This helps in understanding real-world attack patterns.


Conclusion Link to heading

Game of Active Directory (GOAD) is undoubtedly one of the most valuable open-source projects for Active Directory security training. It offers:

  • Realistic Scenarios: The included vulnerabilities reflect real problems in enterprise environments
  • Comprehensive Coverage: From initial access vectors to cross-forest attacks
  • MITRE ATT&CK Alignment: Techniques map directly to industry-standard frameworks
  • Active Development: Regular updates with new vulnerabilities and techniques
  • Excellent Documentation: The writeup series by @M4yFly is a learning treasure

For anyone working in or interested in Active Directory penetration testing, GOAD is an absolute must. The investment in hardware and time for installation pays off many times over through the practical knowledge gained.



Note: This lab uses free Windows Server evaluation versions (180 days). After this period expires, licenses must be entered or the lab must be rebuilt.


License: GOAD is licensed under GPL-3.0 and is fully open source.

Responsible Use: Use this knowledge exclusively for legal purposes such as authorized penetration tests and security audits. Attacking systems without explicit permission is illegal.