Active Directory Members Only

NTLM & Kerberos Internals

NTLM and Kerberos are the two authentication protocols that run everything in Active Directory. Every lateral movement technique, every credential attack, every pass-the-hash or pass-the-ticket — they all exploit specific weaknesses in how these protocols work. Understanding the actual handshake mechanics is what separates guessing from knowing.

Related Articles