The document by Karl Fosaaen discusses various methods for externally testing modern Active Directory domains, including domain enumeration, credential brute forcing, and pivoting to internal networks. Key topics include the use of Graph API, ADFS, Office 365, and Skype for Business for exploiting weak logins and phishing vulnerabilities. It concludes with recommendations for attack mitigations such as enabling multi-factor authentication and limiting federation to trusted domains.
Related topics: