Five blocks. One red thread.
From basic conceptual understanding to practical analysis and documented hardening measures – all in one day.
01 · Why a graph? — Conceptual foundations
- What does a graph show that a table or an AD snapshot does not?
- What is an attack path and how does it differ from a single vulnerability?
- Nodes, edges, paths: The basic logic before the tool arrives
- Side-by-side: The same finding in the classic view and in the graph.
- Real anonymized findings from a ProSec assessment.
02 · Tool setup in the lab
- BloodHound & SharpHound: Architecture and Configuration
- Running SharpHound in a laboratory environment
- Data import and initial graph exploration
- Safety aspects when used in a production environment
03 · Identifying attack paths
- Guided analysis: Three scenarios – ACL, groups, Kerberoasting
- Free analysis: Independently find paths to the domain admin
- Documenting findings: basis for the afternoon modules
- Trainer's comment: Comparison with real project findings
04 · Evaluate and prioritize findings
- Assessment framework: exploitability, exposure, impact
- Prioritization exercise: Evaluate your own findings from Module 3
- Pitfalls: What distorts prioritization?
- Internal communication: Presenting findings in an understandable way
05 · Derive hardening measures
- Quick wins vs. structural measures: which comes first?
- Measures catalog: ACL clearance, Kerberoasting hardening, animal model
- Action sheet: Document the top 3 findings – the key takeaway
- Typical pitfalls in implementation