The OSCP AD Sets Guide is built around one of the most important parts of OSCP+ preparation: understanding how Windows hosts, credentials, service accounts, internal networks, and Active Directory relationships combine into a complete attack path.
An AD set should not be approached as several unrelated Windows machines. A workstation may expose credentials that unlock a server; that server may reveal another subnet or service account; and the resulting domain access may expose the relationship needed to progress further.
The objective is therefore not simply to compromise each host. It is to understand why access to one system makes the next stage possible.
How to Approach an OSCP AD Sets Guide
Start by building an environment map before committing too much time to exploitation. Track the domain, workstations, servers, Domain Controller, users, credentials, services, network interfaces, and every authentication result.
A compact structure works well:
Host → User → Credential → Access → Privilege → Next Host
For an oscp.exam-style environment, your notes might gradually contain assets such as:
- domain:
oscp.exam - initial workstation / WS host
- internal SRV systems
- Domain Controller
- standard domain users
- administrative users
- service accounts
- recovered application credentials
- DPAPI-protected credentials
- internal network ranges
Do not assume that the first system you compromise contains the final privilege-escalation path. Its real value may be the information it provides about the rest of the domain.
Initial Enumeration
For each reachable host, establish:
- open ports and services;
- SMB access and shares;
- web applications;
- WinRM/RDP exposure;
- LDAP/Kerberos information;
- MSSQL or other internal services;
- accessible files;
- known usernames;
- authentication opportunities.
Then prioritize findings based on what they can reveal.
A configuration file containing credentials can be more useful than an unusual service version. An accessible SMB share can expose information that changes your entire attack map.
The OSCP AD Sets Guide methodology is therefore:
Enumerate broadly → identify relationships → form an attack hypothesis → validate it → re-enumerate.
Credentials, DPAPI and User Context
Credential discovery is frequently what connects separate stages of an Active Directory attack path.
Useful sources can include:
- configuration files;
- PowerShell scripts;
- backup directories;
- browser profiles;
- application secrets;
- Windows Credential Manager;
- DPAPI-protected data;
- scheduled tasks;
- database configuration;
- shared documents.
Application variables such as API_USER and API_PASSWORD should never be dismissed because they appear unrelated to Windows authentication.
Ask instead:
Who owns this credential? Where could it logically be used? What does successful authentication reveal next?
DPAPI artifacts deserve similar attention. Under the appropriate user context, protected credentials may expose saved passwords, application secrets, browser credentials, or tokens. The security value is not merely recovering the secret; it is identifying what that secret unlocks elsewhere.
Maintain a credential matrix:
| Account | Source | SMB | WinRM | MSSQL | Other |
|---|---|---|---|---|---|
| Domain user | Config / DPAPI | Test | Test | Test | Record |
| Service account | Application | Test | Test | Test | Record |
| Local account | Host | Local scope | — | — | Record |
This avoids repeatedly testing the same credentials and makes reuse patterns easier to recognize.
User Context Changes What You Can See
A low-privileged domain account is not necessarily a weak finding.
Access as a user such as OSCP.EXAM\v.perry, r.andrews, or another domain identity can reveal resources that anonymous enumeration could not:
- domain users and groups;
- authenticated SMB shares;
- internal documentation;
- service information;
- user-specific files;
- domain relationships;
- additional systems.
Every new identity should therefore trigger another enumeration phase.
Preparing for the OSCP+ Active Directory portion?
Get our OSCP preparation resources with AD sets, standalone scenarios and exam-focused material in one place.✓ Instant digital access · ✓ Free updates · ✓ Multiple ADSet resources
Mapping the Active Directory Attack Path
Once domain credentials become available, stop thinking only in terms of vulnerabilities and start mapping relationships.
Focus on:
Users → Groups → Computers → Services → Permissions → Credentials
For example, discovering a user such as r.gallagher is not important merely because the account exists. Determine where that identity appears:
- group membership;
- accessible shares;
- service configuration;
- scheduled tasks;
- administrative relationships;
- application configuration;
- remote-access permissions.
Likewise, internal hosts such as a 172.16.x.x SRV system should be treated as part of the larger graph.
Ask:
- Who can authenticate?
- Which services are exposed?
- Does the server contain configuration secrets?
- Does it have another network interface?
- Is MSSQL or another service available?
- Can access to this host expose another credential or identity?
Service Accounts and MSSQL
Service accounts can become important because they connect applications to Active Directory.
An identity such as svc_mssql should trigger questions about:
- SQL Server access;
- service ownership;
- group membership;
- authentication privileges;
- configuration files;
- stored credentials;
- linked resources.
Do not assume that a service account is privileged simply because of its name.
Verify the relationship.
The same principle applies to MSSQL. Finding SQL Server does not automatically make it the attack path. Determine who can authenticate, what the account can access, and whether the service exposes additional system or domain context.
Internal Networks and Pivoting
A compromised Windows system may expose an internal network that Kali cannot reach directly.
Always inspect:
- interfaces;
- routes;
- DNS configuration;
- active connections;
- internal hostnames.
If a workstation can communicate with another subnet, update the attack map immediately.
A conceptual OSCP AD attack chain may look like:
Initial WS
→ User Access
→ Credential / DPAPI / Configuration Discovery
→ Domain Authentication
→ Internal SRV
→ Service or Credential Relationship
→ Additional Domain User
→ Domain Controller Path
This is a methodology model, not a claimed exact exam solution. Your real path should be constructed from evidence discovered during the authorized environment.
Re-Enumeration Is the Core OSCP AD Habit
One of the easiest ways to get stuck is to enumerate each machine once.
Instead use:
Enumerate → Gain Access → Re-enumerate → Correlate → Move → Repeat
After obtaining a new user, revisit SMB.
After obtaining a service account, revisit services.
After compromising a server, inspect routes.
After reaching another network, scan the newly reachable attack surface.
After changing privilege level, repeat local enumeration.
This is particularly important because information discovered earlier may only become useful later.
A restricted share found at the beginning of the assessment may become accessible after recovering domain credentials. A server discovered hours earlier may become relevant after identifying the account that manages it.
Good OSCP AD methodology therefore depends as much on revisiting findings as discovering new ones.
Common OSCP ADSet Mistakes
Most wasted time comes from a few recurring problems.
Treating hosts independently.
An AD set is a connected environment. Information from WS01 may be intended for SRV01 or the domain rather than WS01 itself.
Running tools without a question.
WinPEAS, BloodHound-style relationship analysis where permitted, SMB tools, LDAP enumeration, and credential-testing utilities are valuable only when you understand what you are trying to learn.
Ignoring application credentials.
Database and API credentials can lead to another service or expose a reusable identity.
Forgetting DPAPI and user artifacts.
User context can expose credentials that system-level service enumeration misses.
Assuming account names prove privilege.
Names such as svc_mssql or _adm are clues, not evidence.
Forgetting internal interfaces.
The compromised host may be your route to the next network.
Not recording failed authentication.
Knowing where a credential does not work is useful and prevents repeated testing.
Leaving reporting until the end.
OffSec’s current authoritative OSCP+ objectives give substantial weight to documenting findings. Capture evidence while you still have the shell and context.
OSCP AD Set Workflow
Use a compact workflow throughout your practice:
1. Map the environment. Identify reachable hosts, services, domain information and possible internal networks.
2. Gain the initial foothold. Exploit only after sufficient enumeration supports the hypothesis.
3. Enumerate the user and host. Search files, applications, credentials, DPAPI artifacts, services, tasks and network configuration.
4. Build the credential matrix. Test discovered identities only against logically relevant services.
5. Enumerate Active Directory. Map users, groups, computers, service accounts, shares and privilege relationships.
6. Follow the relationship. Determine which credential, permission or host expands your access.
7. Re-enumerate. Every new user, host, privilege level or subnet changes what is visible.
8. Capture evidence immediately. Save commands, outputs, screenshots, credentials and proof as the attack path develops.
This workflow is more transferable than memorizing individual ADSet solutions.
Need More OSCP ADSet Practice?
If Active Directory is the part of OSCP preparation where you lose the most time, use structured ADSet material to compare attack paths, credential discoveries and enumeration decisions across multiple scenarios.
→ Explore OSCP+ ADSet & Exam Resources
Why Active Directory Matters for OSCP+
Active Directory remains a major component of the current OSCP+ objectives. OffSec’s authoritative reference list assigns 26% of the objectives to Active Directory, covering areas including AD enumeration, authentication attacks, lateral movement and related domain techniques. Documentation carries an additional 33% of the objective weighting.
That makes AD preparation about more than learning individual techniques.
You need to be comfortable moving through the complete process:
Enumeration → Foothold → Credential Discovery → Domain Enumeration → Lateral Movement → Privilege Relationships → Evidence
The official OffSec OSCP+ authoritative references should remain the primary reference for current exam objectives.
OSCP AD Sets Guide FAQ
What is an OSCP AD set?
An OSCP-style AD set is a connected Windows and Active Directory environment where progress depends on correlating hosts, users, credentials, services and domain relationships rather than treating each machine independently.
What should I practice for OSCP Active Directory?
Prioritize Windows and domain enumeration, SMB, LDAP/Kerberos concepts, credential discovery, DPAPI, service accounts, lateral movement, internal-network mapping, privilege relationships and evidence collection.
Why do I keep getting stuck on OSCP AD sets?
A common cause is incomplete re-enumeration. When you obtain a new credential, host, privilege level or
Vendor: https://www.offsec.com/certifications/offsec/oscp/
Service List: https://cyberservices.store/certifications/offsec/oscp/
