GPEN › Kerberos Attacks
This domain covers abusing Kerberos authentication in Windows Active Directory: pre-auth weaknesses, ticket forgery, delegation misconfigurations, and service account cracking. GPEN questions present traffic captures, extracted hashes, or account attributes and require you to select the correct attack, tool, or defensive control rather than recall theory alone.
GPEN Kerberos Attacks — All 31 Questions
Every question in this domain with answers and detailed explanations.
Attacking Password Hashes
Password Attacks and Formats
Scanning and Host Discovery
Metasploit
Vulnerability Scanning
Reconnaissance
Command and Control
Exploitation Fundamentals
Azure AD Integration
Domain Escalation and Persistence
Azure Apps and Attacks
Escalation and Exploitation
Advanced Password Attacks
Pen Test Planning