blog_tech/i18n/en/docusaurus-plugin-content-docs/current/projets-openclassrooms/p12-audit-securite-ad.md
Tellsanguis 816e50ae84 Amélioration i18n et navigation catégories
- Add English translations for presentation page and homepage
- Remove project numbers (P02-P13) from OpenClassrooms project titles
- Convert category pages to show content with DocCardList component
- Fix broken links to category pages
2025-11-22 18:07:34 +01:00

2.3 KiB

sidebar_position
12

Active Directory Security Audit

Context

Offensive security audit of a clinic's Windows domain and Active Directory: penetration testing, vulnerability identification and remediation plan.

Objectives

  • Perform a complete AD security audit
  • Identify exploitable vulnerabilities
  • Demonstrate risks through proof of concepts
  • Propose a corrective action plan aligned with ANSSI/NIST

Methodology

  1. Reconnaissance: domain enumeration
  2. Exploitation: controlled penetration tests
  3. Post-exploitation: privilege escalation
  4. Report: vulnerabilities and remediations

Tools Used

Tool Usage
nmap Network and service scanning
enum4linux SMB/AD enumeration
Kerberoasting Kerberos ticket extraction
Mimikatz Credential extraction
BloodHound AD attack path analysis

Identified Vulnerabilities (Examples)

Vulnerability Criticality Risk
Accounts with SPN and weak password Critical Kerberoasting -> privileged access
NTLM enabled High Pass-the-Hash
Unconstrained delegation High Identity impersonation
Cleartext passwords (GPP) Critical Immediate compromise

Deliverables

Pentest Report (PDF)

Detailed document of penetration tests performed and identified vulnerabilities.

Corrective Action Plan (PDF)

Remediation plan with action prioritization according to criticality level.

Presentation (PDF)

Presentation slides for stakeholder reporting.

Skills Acquired

  • Security audit methodology
  • Pentesting tools usage
  • Active Directory vulnerability analysis
  • Audit report writing
  • Remediation plan development
  • Results presentation to stakeholders