
Workshop: A Hands-On Path from HTTP to DA
Type: Hands-on Technical Workshop
Level: Advanced
Duration: 6 Hours
Format: Instructor-led + Hands-on Labs
Target Audience:
Penetration Testers, Red Teamers, Security Engineers, SOC/Detection Engineers, Application Security Professionals, and Cybersecurity Researchers.
Workshop Abstract:
Modern enterprise attacks rarely stop at the first vulnerability discovered in a web application. A seemingly isolated web application weakness can become the initial access point into an organization's internal environment, followed by credential discovery, lateral movement, privilege escalation, and ultimately Active Directory compromise.
This advanced hands-on workshop demonstrates how professional penetration testers approach an enterprise attack path from external web application exposure to internal Active Directory compromise.
Participants will begin by assessing a deliberately vulnerable web application and identifying vulnerabilities that can provide an initial foothold. The workshop will then transition into post-exploitation, internal enumeration, credential discovery, lateral movement, and Active Directory attack techniques.
Rather than focusing only on individual vulnerabilities, the session emphasizes attack-chain thinking—understanding how seemingly independent weaknesses can be combined to achieve meaningful security impact.
The entire workshop will be conducted in an isolated, purpose-built lab environment.
![]()