Identify and close AD attack paths.

See what attackers see – with BloodHound. A full-day workshop for AD administrators who want to understand their own environment from the attacker's perspective and systematically harden it.

Workshop details
Format
Full-day workshop
Date
Thursday, 3th December 2026 Thursday, 18th of March 2027
Time of day
8:30 – 16:30
Participants
12 max
Price
€895 per person net
En casa
On request
Certification
Practical focus / no certificate

What attackers see – and admins not see.

Active Directory environments grow over years. Permissions are granted and rarely revoked. The result is attack vectors that are visible to a penetration tester in minutes.

Established structures

Active Directory permissions are granted for years and never systematically reviewed. Inheritance, group relationships, and service account rights are rarely documented and even more rarely up-to-date.

Lack of attacker perspective

Anyone who doesn't view their own AD environment from an attacker's perspective won't see the critical paths. BloodHound makes these paths visible, but is rarely used defensively.

Unclear priorities

Not every weakness is equally critical. Without structured evaluation, endless to-do lists are created without any effect. This workshop teaches you how to prioritize findings.

External dependency

Those who only see attack vectors through penetration tests are reactive. Those who can use BloodHound themselves analyze proactively, without having to outsource every finding.

"

Penetration testers typically identify multiple paths to domain administrator access within a few hours of an Active Directory assessment. Most of these paths are not new; they are simply... never before viewed from this perspective.

For those who use AD daily responsible.

Not for beginners. Not for penetration testers. But for the people who have to operate and secure Active Directory in the company.

👤

AD administrators

With 2-3 years of practical experience. Responsible for users, groups, GPOs and authorization structures.

🛡️

IT security manager

Blue team involvement, monitoring, and hardening work. Basic understanding of AD is required.

🏳️

System architects

Technical decision-makers who want to understand attack paths structurally and evaluate hardening measures.

⚠️

Not suitable for: Beginners without AD practical experience · Penetration tester (JPT and PPT• Managers without a technical background. Basic knowledge of Kerberos, group structures, and GPOs is required.

Five blocks. One red thread.

From basic conceptual understanding to practical analysis and documented hardening measures – all in one day.

  • What does a graph show that a table or an AD snapshot does not?
  • What is an attack path and how does it differ from a single vulnerability?
  • Nodes, edges, paths: The basic logic before the tool arrives
  • Side-by-side: The same finding in the classic view and in the graph.
  • Real anonymized findings from a ProSec assessment.
  • BloodHound & SharpHound: Architecture and Configuration
  • Running SharpHound in a laboratory environment
  • Data import and initial graph exploration
  • Safety aspects when used in a production environment
  • Guided analysis: Three scenarios – ACL, groups, Kerberoasting
  • Free analysis: Independently find paths to the domain admin
  • Documenting findings: basis for the afternoon modules
  • Trainer's comment: Comparison with real project findings
  • Assessment framework: exploitability, exposure, impact
  • Prioritization exercise: Evaluate your own findings from Module 3
  • Pitfalls: What distorts prioritization?
  • Internal communication: Presenting findings in an understandable way
  • Quick wins vs. structural measures: which comes first?
  • Measures catalog: ACL clearance, Kerberoasting hardening, animal model
  • Action sheet: Document the top 3 findings – the key takeaway
  • Typical pitfalls in implementation

Developed by penetration testers. For administrators. thought.

The workshop is conducted by practitioners from the ProSec project business. The lab scenarios are based on real AD assessments.

Real Lab Scenarios

The training environment reflects patterns that ProSec regularly encounters in real AD assessments. It's not a contrived teaching scenario, but rather what actually occurs in practice.

Trainers from the project business

The workshop leaders come from ProSec's active penetration testing and consulting operations – people who see and document attack paths themselves on a daily basis.

Direct transferability

Participants leave the workshop with a clear logic of action that they can apply in their own environment — without external commissioning for each subsequent step.

Two formats. One Resume.

Both formats share the same content structure. The difference lies in the context, not the content.

In-house at the customer's premises


On request
  • ProSec comes to you. Particularly useful as a follow-up format after a penetration test or AD assessment: The attack paths from the project are directly embedded.
  • Advantage: ProSec's knowledge of the customer environment
  • Environment: ProSec Lab (brought with me)
  • GROUP - Possible from 4 people

Open Workshop

3 December 2026
per person net 895 €,-
  • Fixed dates, open to all participants. Bookable as an individual or as a team. Conducted using the ProSec Lab environment.
  • Advantage: Flexible booking without project-specific requirements
  • Advantage: Exchange with participants from other companies
  • Participants: 12 max
12 max

Open Workshop

March 18, 2027
per person net 895 €,-
  • Fixed dates, open to all participants. Bookable as an individual or as a team. Conducted using the ProSec Lab environment.
  • Advantage: Flexible booking without project-specific requirements
  • Advantage: Exchange with participants from other companies
  • Participants: 12 max
12 max

Workshop

Open workshop: €895 per person net. In-house format: On request. Contact us – we'll discuss dates and formats.

Contact form

Share your feedback and help us improve our services!

Share your feedback and help us improve our services!

Take 1 minute to give us some feedback. This way we can ensure that our IT security solutions meet your exact needs.