Agentic Research

Read these first

This article assumes the following earlier in its learning path.

Credentials and AD Concepts: The Most Critical Link in the Attack Chain, Explained Plainly

2026/10/1114 min readBryan Chan閱讀中文原文
TopicsCredential SecurityActive DirectoryAuthenticationDefense StrategyConcepts

Core premise: the truly scarce resource in an attack chain is not vulnerabilities — it is credentials. An attacker who has landed inside a network but holds no valid account is actually in a weak position. Angle: concepts and defense. Principles and prevention only — no operational detail.

Where credentials sit in the attack chain

Why credentials are the pivot of the whole chain

Picture a corporate network as a building:

  • Vulnerabilities are unlatched windows;
  • A foothold is the window the attacker climbed through;
  • Credentials are the access card.

Climbing through a window only gets you into one room. What lets an attacker roam the whole building is an access card — a valid account and password (or its equivalent).

This is why public exercise postmortems consistently show that the final mile stalls at credentials, requiring a human expert to step in.

Four concepts worth separating

Concept one: a password is not a hash

  • A password is the string a user types;
  • A hash is a fixed-length string produced by a one-way transformation of that password.

The key word is one-way: you cannot reverse a hash back into the password, but you can try candidates one by one (hash each and compare).

Defensive meaning: if hashes leak, weak passwords are effectively exposed — no need to break the algorithm. This is why password strength and length matter so much.

Concept two: why you can log in without typing a password (pass-the-hash)

In many older authentication protocols, the system compares hashes, not plaintext passwords. That means: if you hold the hash, you can authenticate directly without knowing the original password.

Hence the counter-intuitive result: an attacker who "does not know the password" can still log in.

Defensive meaning: this is exactly why modern practice pushes toward authentication that does not depend on hashes (certificate-based logon, hardened Kerberos configurations), and why "hash captured" must be treated as seriously as "password captured".

Concept three: Kerberos — the internal "pass system"

Active Directory (the common enterprise identity system) uses Kerberos by default. Its operation can be understood as:

  1. The user proves identity to a ticket authority (usually using a hash);
  2. The authority issues a ticket, which grants access to a specific service;
  3. Presenting the ticket grants access — no need to re-enter the password each time.

The design exists for efficiency and security, but its properties also create classes of risk (tickets can be replayed, can be requested for the wrong target, and so on).

Defensive meaning: enterprises should care not only about "is the password strong" but also "how long do tickets live" and "who can request high-privilege tickets".

Concept four: lateral movement — from one machine to the whole domain

After obtaining a first set of credentials, the attacker's goal is to repeat the process: log into another machine with those credentials → find more credentials there → expand further.

This is lateral movement. Its danger is that every success makes the next one easier — privilege snowballs.

Where attackers "pick up" credentials

Understanding the sources is how you design defenses:

SourcePlain explanation
MemorySome systems cache authentication material in memory
Config files / scriptsAccounts hard-coded in automation
Browsers / mail clientsCredentials saved when users tick "remember me"
Shared filesDocuments and backups containing credentials
Service accountsLong-lived, over-privileged machine accounts

Notably: most credentials are not "cracked" — they are left in places they should not be.

Why credential isolation has the highest return

Condense everything above into one defensive line: make sure that even if an attacker obtains one set of credentials, they cannot travel far.

Concretely:

  • Least privilege: daily work never uses administrator accounts;
  • Just-in-time access: elevate temporarily when needed, revoke immediately after;
  • Segmentation: separate admin accounts per system, so one key does not open every door;
  • Centralised privileged account management: log who used which privileged account and when;
  • Regular rotation: especially service and machine accounts.

Nothing here is novel — but each maps directly onto the weakest link in the chain.

One line for non-technical readers

If you remember only one thing: an organisation's security posture largely depends on "how far an attacker can travel after one password leaks". That depends on how account privileges are designed, not on how many firewalls you own.

Next steps

  • To see where credentials sit in the overall chain, read the case study
  • To see how an attacker builds a channel after landing, read tunnel techniques explained
  • For a systematic defensive review, read defense lessons from the red-team postmortem

Next on this path