> For the complete documentation index, see [llms.txt](https://aas-s3curity.gitbook.io/cheatsheet/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://aas-s3curity.gitbook.io/cheatsheet/internalpentest/active-directory/exploitation.md).

# Exploitation

- [Exploit Without Account](https://aas-s3curity.gitbook.io/cheatsheet/internalpentest/active-directory/exploitation/exploit-without-account.md)
- [SMB Relay](https://aas-s3curity.gitbook.io/cheatsheet/internalpentest/active-directory/exploitation/exploit-without-account/smb-relay.md): This page deals with gaining code execution relaying NTLMv1/2 hashes in a very effective manner.
- [Exploit With Account](https://aas-s3curity.gitbook.io/cheatsheet/internalpentest/active-directory/exploitation/exploit-with-account.md)
- [Kerberoast Attack](https://aas-s3curity.gitbook.io/cheatsheet/internalpentest/active-directory/exploitation/exploit-with-account/kerberoast-attack.md): This page deals with compromising Active Directory with Kerberoast attack.
