Game of Active Directory (GOAD): The Ultimate Pentest Lab for Active Directory Attacks Link to heading
A comprehensive guide to the leading open-source lab for Active Directory penetration testing
Introduction: What is GOAD? Link to heading
Game of Active Directory (GOAD) is a revolutionary open-source project by Orange Cyberdefense that provides penetration testers and security professionals with a fully vulnerable Active Directory environment. The project, developed and maintained by Cyril Servières (known as @M4yFly), enables practitioners to practice realistic AD attack techniques in a safe, isolated environment.
The name is a nod to the HBO series “Game of Thrones” – and indeed, all users, domains, and servers are named after characters and locations from Westeros and Essos. This creative design makes the lab not only technically valuable but also entertaining.
The Philosophy Behind GOAD Link to heading
GOAD can be thought of as a “DVWA for Active Directory” – similar to how the Damn Vulnerable Web Application serves web security training, GOAD provides an intentionally vulnerable environment for learning and practice. The goal is clear: to give pentesters a platform where they can train all common AD attack techniques without legal concerns and without risk to production systems.
Important Note: GOAD is extremely vulnerable and should never be deployed in production environments or connected to the internet without proper isolation.
Available Labs Link to heading
GOAD offers various lab variants that cater to different hardware requirements and learning objectives:
1. GOAD (Full Version) Link to heading
The main variant of the lab consists of 5 virtual machines spanning 2 forests and 3 domains:
Domain: sevenkingdoms.local
- Kingslanding (DC01): Domain Controller on Windows Server 2019 with Windows Defender enabled
- Administrators: robert.baratheon, cersei.lannister
Domain: north.sevenkingdoms.local
- Winterfell (DC02): Domain Controller on Windows Server 2019 with Windows Defender enabled
- Castelblack (SRV02): Server on Windows Server 2019 with Windows Defender disabled, equipped with IIS, MSSQL, and SMB shares
- Administrators: eddard.stark, catelyn.stark, robb.stark
Domain: essos.local
- Meereen (DC03): Domain Controller on Windows Server 2016 with Windows Defender enabled
- Braavos (SRV03): Server on Windows Server 2016 with MSSQL and SMB shares
- Administrators: daenerys.targaryen, khal.drogo
2. GOAD-Light Link to heading
A more resource-friendly version with 3 VMs, 1 forest, and 2 domains – ideal for users with less powerful hardware.
3. MINILAB Link to heading
The minimal variant with only 2 VMs: one Domain Controller (Windows Server 2019) and one Workstation (Windows 10).
4. SCCM Lab Link to heading
A specialized variant with 4 VMs that includes Microsoft Configuration Manager (SCCM/MECM) – perfect for practicing SCCM-specific attacks.
5. NHA (No Help Available) Link to heading
A challenge lab with 5 VMs and 2 domains where no schema is provided. Here, the attacker must figure out how to compromise the network themselves – ideal for advanced exercises.
System Requirements Link to heading
Installing GOAD requires significant hardware resources:
| Resource | GOAD-Light | GOAD (Full Version) |
|---|---|---|
| RAM | minimum 20 GB | minimum 24-32 GB |
| Storage | ~77 GB (without snapshots) | ~115 GB (with VM images) |
| CPU | 4+ cores recommended | 8+ cores recommended |
The Windows Server VM images require additional storage:
- Windows Server 2016 image: ~22 GB
- Windows Server 2019 image: ~14 GB
Supported Platforms and Providers Link to heading
GOAD can be operated on various virtualization platforms and cloud providers:
Local Virtualization:
- VirtualBox
- VMware Workstation (now free for personal use)
- Proxmox
Cloud Providers:
- AWS
- Azure
Special Platforms:
- VMware ESXi
- Ludus
Installation Link to heading
Prerequisites (Linux) Link to heading
# Install VirtualBox
sudo apt install virtualbox
# Install Vagrant
wget -O- https://apt.releases.hashicorp.com/gpg | sudo gpg --dearmor -o /usr/share/keyrings/hashicorp-archive-keyring.gpg
echo "deb [signed-by=/usr/share/keyrings/hashicorp-archive-keyring.gpg] https://apt.releases.hashicorp.com $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/hashicorp.list
sudo apt update && sudo apt install vagrant
# Install Vagrant Plugins
vagrant plugin install vagrant-reload vagrant-vbguest winrm winrm-fs winrm-elevated
# Additional dependencies
sudo apt install sshpass lftp rsync openssh-client python3.10-venv
Clone and Install GOAD Link to heading
git clone https://github.com/Orange-Cyberdefense/GOAD.git
cd GOAD
# Verify installation
./goad.sh -t check -l GOAD -p virtualbox
# Start installation
./goad.sh -t install -l GOAD -p virtualbox
# Or start interactive mode
./goad.sh
Note: The installation can take several hours. Patience is required!
MITRE ATT&CK Framework Mapping Link to heading
One of the most valuable aspects of GOAD is that it allows practitioners to train real-world attack techniques that are documented in the MITRE ATT&CK framework. Below is a comprehensive mapping of GOAD vulnerabilities to their corresponding ATT&CK techniques.
Quick Reference: MITRE ATT&CK Techniques in GOAD Link to heading
| GOAD Vulnerability | MITRE ATT&CK ID | Technique Name | Tactic |
|---|---|---|---|
| AS-REP Roasting | T1558.004 | Steal or Forge Kerberos Tickets: AS-REP Roasting | Credential Access |
| Kerberoasting | T1558.003 | Steal or Forge Kerberos Tickets: Kerberoasting | Credential Access |
| Password Spraying | T1110.003 | Brute Force: Password Spraying | Credential Access |
| LLMNR/NBT-NS Poisoning | T1557.001 | Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay | Credential Access |
| Golden Ticket | T1558.001 | Steal or Forge Kerberos Tickets: Golden Ticket | Credential Access |
| Silver Ticket | T1558.002 | Steal or Forge Kerberos Tickets: Silver Ticket | Credential Access |
| DCSync | T1003.006 | OS Credential Dumping: DCSync | Credential Access |
| LSASS Dump | T1003.001 | OS Credential Dumping: LSASS Memory | Credential Access |
| GPO Abuse | T1484.001 | Domain Policy Modification: Group Policy Modification | Defense Evasion, Privilege Escalation |
| Domain Trust Discovery | T1482 | Domain Trust Discovery | Discovery |
| Trust Modification | T1484.002 | Domain Policy Modification: Trust Modification | Defense Evasion, Privilege Escalation |
| Password in LDAP | T1552.006 | Unsecured Credentials: Group Policy Preferences | Credential Access |
| Password in SYSVOL | T1552.006 | Unsecured Credentials: Group Policy Preferences | Credential Access |
| Pass-the-Hash | T1550.002 | Use Alternate Authentication Material: Pass the Hash | Defense Evasion, Lateral Movement |
| Pass-the-Ticket | T1550.003 | Use Alternate Authentication Material: Pass the Ticket | Defense Evasion, Lateral Movement |
| Unconstrained Delegation | T1558 | Steal or Forge Kerberos Tickets | Credential Access |
| Constrained Delegation | T1558 | Steal or Forge Kerberos Tickets | Credential Access |
| ADCS Abuse (ESC1-ESC8) | T1649 | Steal or Forge Authentication Certificates | Credential Access |
| SMB Null Session | T1087.002 | Account Discovery: Domain Account | Discovery |
| ACL Abuse | T1222.001 | File and Directory Permissions Modification: Windows File and Directory Permissions Modification | Defense Evasion |
Practical Attack Scenarios with MITRE ATT&CK Mapping Link to heading
Scenario 1: From Anonymous Access to Domain Admin Link to heading
This attack chain demonstrates how an attacker can escalate from zero credentials to full domain compromise.
| Step | Action | MITRE ATT&CK ID | Technique |
|---|---|---|---|
| 1 | SMB Null Session on Winterfell | T1087.002 | Account Discovery: Domain Account |
| 2 | Extract user list via LDAP | T1069.002 | Permission Groups Discovery: Domain Groups |
| 3 | AS-REP Roasting on brandon.stark | T1558.004 | Steal or Forge Kerberos Tickets: AS-REP Roasting |
| 4 | Crack hash offline | T1110.002 | Brute Force: Password Cracking |
| 5 | Kerberoasting with compromised account | T1558.003 | Steal or Forge Kerberos Tickets: Kerberoasting |
| 6 | BloodHound enumeration | T1087.002 | Account Discovery: Domain Account |
| 7 | ACL abuse along identified path | T1222.001 | File and Directory Permissions Modification |
| 8 | DCSync to obtain KRBTGT hash | T1003.006 | OS Credential Dumping: DCSync |
| 9 | Golden Ticket creation | T1558.001 | Steal or Forge Kerberos Tickets: Golden Ticket |
Detailed ATT&CK Analysis:
Initial Access → Discovery → Credential Access → Privilege Escalation → Persistence
↓ ↓ ↓ ↓ ↓
None T1087.002 T1558.004 T1003.006 T1558.001
T1069.002 T1558.003
T1110.002
Scenario 2: LLMNR Poisoning Chain Link to heading
This scenario exploits legacy name resolution protocols to capture and relay credentials.
| Step | Action | MITRE ATT&CK ID | Technique |
|---|---|---|---|
| 1 | Start Responder for LLMNR/NBT-NS poisoning | T1557.001 | Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay |
| 2 | Capture NetNTLMv2 hash from eddard.stark | T1040 | Network Sniffing |
| 3a | Crack hash offline (Option A) | T1110.002 | Brute Force: Password Cracking |
| 3b | NTLM Relay to target (Option B) | T1557.001 | Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay |
| 4 | Access with Domain Admin credentials | T1078.002 | Valid Accounts: Domain Accounts |
| 5 | Dump LSASS for additional credentials | T1003.001 | OS Credential Dumping: LSASS Memory |
ATT&CK Kill Chain:
┌─────────────────────────────────────────────────────────────────────────────┐
│ TACTIC │ TECHNIQUE │
├─────────────────┼───────────────────────────────────────────────────────────┤
│ Collection │ T1557.001 - LLMNR/NBT-NS Poisoning │
│ Credential Access│ T1040 - Network Sniffing │
│ Credential Access│ T1110.002 - Password Cracking │
│ Defense Evasion │ T1078.002 - Valid Accounts: Domain Accounts │
│ Credential Access│ T1003.001 - LSASS Memory Dumping │
└─────────────────┴───────────────────────────────────────────────────────────┘
Scenario 3: ADCS Exploitation (ESC8) Link to heading
This scenario demonstrates certificate abuse through NTLM relay to AD Certificate Services.
| Step | Action | MITRE ATT&CK ID | Technique |
|---|---|---|---|
| 1 | PetitPotam coercion (unauthenticated) | T1187 | Forced Authentication |
| 2 | NTLM Relay to ADCS Web Enrollment | T1557.001 | Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay |
| 3 | Request certificate for DC machine account | T1649 | Steal or Forge Authentication Certificates |
| 4 | Pass-the-Certificate for authentication | T1550 | Use Alternate Authentication Material |
| 5 | DCSync with machine account | T1003.006 | OS Credential Dumping: DCSync |
| 6 | Full domain compromise | T1558.001 | Steal or Forge Kerberos Tickets: Golden Ticket |
ADCS ESC Techniques Mapping:
| ESC Vulnerability | Description | Related ATT&CK |
|---|---|---|
| ESC1 | Enrollee Supplies Subject | T1649 |
| ESC2 | Any Purpose EKU | T1649 |
| ESC3 | Certificate Request Agent | T1649 |
| ESC4 | Vulnerable Certificate Template ACL | T1649, T1222 |
| ESC6 | EDITF_ATTRIBUTESUBJECTALTNAME2 | T1649 |
| ESC8 | NTLM Relay to Web Enrollment | T1557.001, T1649 |
Scenario 4: ACL Abuse Chain (Sevenkingdoms Domain) Link to heading
This scenario demonstrates how misconfigured ACLs can be chained for privilege escalation.
| Step | User | Action | MITRE ATT&CK ID | ACL Exploited |
|---|---|---|---|---|
| 1 | tywin.lannister | Force password change | T1098 | ForceChangePassword on jaime.lannister |
| 2 | jaime.lannister | Modify user attributes | T1222.001 | GenericWrite on joffrey.baratheon |
| 3 | joffrey.baratheon | Modify DACL | T1222.001 | WriteDACL on tyron.lannister |
| 4 | tyron.lannister | Add self to privileged group | T1098.002 | Self-Membership on Small Council |
| 5 | Small Council | Add member to DragonStone | T1098.002 | AddMember on DragonStone group |
| 6 | DragonStone | Modify ownership | T1222.001 | WriteOwner on KingsGuard |
| 7 | KingsGuard | Full control over user | T1098 | GenericAll on stannis.baratheon |
| 8 | stannis.baratheon | Full control over DC | T1098 | GenericAll on Kingslanding (DC) |
ACL Abuse Kill Chain Visualization:
tywin.lannister
│ ForceChangePassword
▼
jaime.lannister
│ GenericWrite
▼
joffrey.baratheon
│ WriteDACL
▼
tyron.lannister
│ Self-Membership
▼
Small Council ──────► DragonStone ──────► KingsGuard ──────► stannis.baratheon
WriteOwner GenericAll │
│ GenericAll on DC
▼
DOMAIN ADMIN
Scenario 5: Cross-Forest Attack Path Link to heading
This scenario demonstrates trust relationship exploitation between forests.
| Step | Action | MITRE ATT&CK ID | Technique |
|---|---|---|---|
| 1 | Enumerate domain trusts | T1482 | Domain Trust Discovery |
| 2 | Identify foreign group members | T1069.002 | Permission Groups Discovery: Domain Groups |
| 3 | Compromise user in cross-forest group | T1078.002 | Valid Accounts: Domain Accounts |
| 4 | Access resources in trusted forest | T1550.003 | Use Alternate Authentication Material: Pass the Ticket |
| 5 | SID History injection (if enabled) | T1134.005 | Access Token Manipulation: SID-History Injection |
| 6 | Escalate to Enterprise Admin | T1558.001 | Steal or Forge Kerberos Tickets: Golden Ticket |
Included Vulnerabilities and Attack Vectors Link to heading
GOAD offers an impressive collection of vulnerabilities and misconfigurations that reflect typical problems in real Active Directory environments:
Initial Access Vectors Link to heading
Password Spraying (T1110.003)
- Users like
hodorhave passwords identical to their username - Seasonal passwords like “WinterYYYY” for
rickon.stark
AS-REP Roasting (T1558.004)
brandon.starkis vulnerable to AS-REP Roasting (no Kerberos Pre-Authentication required)missandein the essos.local domain
Kerberoasting (T1558.003)
jon.snowhas SPNs configured and is vulnerable to Kerberoasting- Service accounts with weak passwords
Passwords in LDAP (T1552.006)
samwell.tarlyhas his password stored in the LDAP description field
Passwords in SYSVOL (T1552.006)
tywin.lannisterhas an encrypted password in SYSVOLjeor.mormonthas his password in a SYSVOL script
LLMNR/NBT-NS Poisoning (T1557.001)
- Bots simulate LLMNR requests for
eddard.starkandrobb.stark - Enables NTLM relay attacks with Responder
Privilege Escalation and Lateral Movement Link to heading
ACL Abuse (T1222.001, T1098) The lab contains numerous ACL-based attack paths:
tywin.lannister→ ForceChangePassword onjaime.lannisterjaime.lannister→ GenericWrite onjoffrey.baratheontyron.lannister→ Self-Membership on “Small Council”joffrey.baratheon→ WriteDACL ontyron.lannisterstannis.baratheon→ GenericAll on Computer “Kingslanding”lord.varys→ GenericAll on Domain Admins and SDHolderkhal.drogo→ GenericAll onviserys.targaryen(Shadow Credentials)
Kerberos Delegation (T1558)
- Unconstrained Delegation:
sansa.stark - Constrained Delegation:
jon.snowwith S4U2Self abuse
MSSQL Attacks
- MSSQL Impersonation:
samwel.tarlly→ sa,arya.stark→ dbo - MSSQL Trusted Links between Castelblack and Braavos
GPO Abuse (T1484.001)
samwell.tarlycan edit the “STARKWALLPAPER” GPO
AD Certificate Services (ADCS) (T1649) Link to heading
GOAD includes a complete ADCS installation with vulnerable certificate templates:
- ESC1: Enrollee Supplies Subject
- ESC2: Any Purpose EKU
- ESC3: Certificate Request Agent
- ESC4: Vulnerable Certificate Template Access Control
- ESC6: EDITF_ATTRIBUTESUBJECTALTNAME2
- ESC8: NTLM Relay to AD CS HTTP Endpoints (PetitPotam + ADCS)
Cross-Forest and Cross-Domain Attacks (T1482, T1484.002) Link to heading
- Bidirectional trust between north.sevenkingdoms.local and sevenkingdoms.local (Child/Parent)
- Forest trust between essos.local and sevenkingdoms.local
- Special cross-forest groups: AcrossTheSea, AccrossTheNarrowSea, DragonsFriends, Spys
MITRE ATT&CK Navigator Layer Link to heading
For visual analysis and tracking of techniques practiced in GOAD, you can import the following techniques into MITRE ATT&CK Navigator:
Credential Access Techniques:
- T1558 (all sub-techniques) - Kerberos Ticket Attacks
- T1003 (especially .001, .006) - Credential Dumping
- T1110 (.002, .003) - Brute Force
- T1557.001 - LLMNR Poisoning
- T1552.006 - Unsecured Credentials
- T1649 - Certificate Theft
Privilege Escalation Techniques:
- T1484 (all sub-techniques) - Domain Policy Modification
- T1098 - Account Manipulation
- T1078.002 - Valid Accounts: Domain
Discovery Techniques:
- T1482 - Domain Trust Discovery
- T1087.002 - Account Discovery: Domain
- T1069.002 - Permission Groups Discovery
Lateral Movement Techniques:
- T1550 (.002, .003) - Pass-the-Hash/Ticket
- T1021.002 - SMB/Windows Admin Shares
Extensions Link to heading
GOAD offers various extensions that add additional functionality to the lab:
Guacamole Link to heading
A web-based remote desktop solution for easy access to VMs without a local RDP client.
Exchange Link to heading
Microsoft Exchange Server integration for Exchange-specific attack techniques.
ELK Stack Link to heading
Elasticsearch, Logstash, and Kibana for log analysis and monitoring – ideal for learning detection engineering.
Wazuh Link to heading
Open-source SIEM for security monitoring and incident response training.
Additional Workstations (ws01) and Linux Servers (lx01) Link to heading
Extends the lab with additional attack surfaces.
Learning Resources and Writeups Link to heading
The developer @M4yFly has published an extensive 12-part writeup series covering all aspects of the lab:
- Reconnaissance and Scanning – Network discovery and service enumeration
- Anonymous Enumeration – What’s possible without credentials
- Enumeration with User Context – BloodHound and LDAP queries
- Poisoning and NTLM Relay – Responder, mitm6, and relay attacks
- Exploitation with User Context – Credential harvesting
- ADCS Attacks – Certificate abuse
- MSSQL Attacks – Impersonation and trusted links
- Kerberos Attacks – Golden/Silver tickets
- Privilege Escalation – Local privilege escalation
- Delegation Attacks – Unconstrained and constrained delegation
- ACL Abuse – Access Control List exploitation
- Trust Exploitation – Cross-forest and cross-domain attacks
These writeups are available at: https://mayfly277.github.io/categories/goad/
Recommended Tools Link to heading
The following tools are recommended for working with GOAD:
Enumeration:
- BloodHound / SharpHound
- CrackMapExec (cme) / NetExec
- ldapdomaindump
- adidnsdump
Credential Attacks:
- Responder
- Impacket Suite (GetUserSPNs, secretsdump, etc.)
- Hashcat
- Kerbrute
Exploitation:
- Certipy (ADCS attacks)
- Rubeus
- Mimikatz
- donPAPI
- lsassy
Lateral Movement:
- PsExec
- WMIexec
- Evil-WinRM
Best Practices for Working with GOAD Link to heading
1. Keep Documentation Link to heading
Maintain a detailed log of all actions – this improves both learning and reproducibility.
2. Use BloodHound Link to heading
BloodHound is essential for visualizing attack paths. Learn the Cypher query language for advanced queries.
3. Proceed Step by Step Link to heading
Start with simple attacks and work your way up to more complex techniques. GOAD is extensive – take your time.
4. Explore Multiple Paths Link to heading
There are almost always multiple paths to Domain Admin. Try to find and document different routes.
5. Don’t Forget Cleanup Link to heading
When you make changes (e.g., changing passwords or adding SPNs), document them for later reversal.
6. Map to MITRE ATT&CK Link to heading
Use the ATT&CK framework to categorize and document the techniques you practice. This helps in understanding real-world attack patterns.
Conclusion Link to heading
Game of Active Directory (GOAD) is undoubtedly one of the most valuable open-source projects for Active Directory security training. It offers:
- Realistic Scenarios: The included vulnerabilities reflect real problems in enterprise environments
- Comprehensive Coverage: From initial access vectors to cross-forest attacks
- MITRE ATT&CK Alignment: Techniques map directly to industry-standard frameworks
- Active Development: Regular updates with new vulnerabilities and techniques
- Excellent Documentation: The writeup series by @M4yFly is a learning treasure
For anyone working in or interested in Active Directory penetration testing, GOAD is an absolute must. The investment in hardware and time for installation pays off many times over through the practical knowledge gained.
Further Links Link to heading
- GitHub Repository: https://github.com/Orange-Cyberdefense/GOAD
- Official Documentation: https://orange-cyberdefense.github.io/GOAD/
- Writeups by @M4yFly: https://mayfly277.github.io/categories/goad/
- Sponsor @M4yFly: https://github.com/sponsors/Mayfly277
- MITRE ATT&CK Framework: https://attack.mitre.org/
Note: This lab uses free Windows Server evaluation versions (180 days). After this period expires, licenses must be entered or the lab must be rebuilt.
License: GOAD is licensed under GPL-3.0 and is fully open source.
Responsible Use: Use this knowledge exclusively for legal purposes such as authorized penetration tests and security audits. Attacking systems without explicit permission is illegal.