logo

Follow the Adversary: The Top 3 Red Team Exploitation Paths from 2024

ID: 3f0d09cc-3bf8-53d5-923d-1416b8cdc2b1

STIX ID: report--3f0d09cc-3bf8-53d5-923d-1416b8cdc2b1

Feed Name: Crowdstrike Blog

Date Published: 2025-03-19

Date Updated: 2026-04-27

Author: Brent Harrell

...
...

This article outlines three prevalent exploitation paths observed by a red team—unsecured credentials, Active Directory Certificate Services (AD CS) abuses (ESC1, ESC4, ESC8) often via NTLM relay, and excessive or misconfigured Active Directory permissions that enable shadow credentials and RBCD. It explains how these techniques enable rapid privilege escalation and domain compromise, highlights common exposure points (SharePoint, file shares, code repos), and provides concrete mitigations such as secure credential management, tightening AD CS templates and web enrollment protections, enforcing tiered administration, reviewing ACEs with tools like Certipy and BloodHound, and strengthening policies for object lifecycle management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.