Skip to main content
noPac: sAMAccountName Spoofing to Domain Admin operation cover
COMING SOONIntermediatePRO

noPac: sAMAccountName Spoofing to Domain Admin

A low-privilege domain user creates a machine account, renames it to match a domain controller, and exploits a Kerberos principal-resolution flaw to obtain a domain-admin service ticket without ever holding elevated rights. Trace the two-CVE privilege escalation from the first LDAP rename event through to the credential harvest.

45m
7 tasks
50 points
Pro

Launches in 5 days

Oct 6, 2026

Tuesday, October 6, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

SIEMXDRQuery

What you'll investigate

7 objectives unlock when this operation goes live.

1Spot the new account that should not exist
2Identify the renaming event at the heart of the attack
3Confirm the KDC issued a ticket during the race window
4Trace the S4U2self ticket that granted domain admin access
5Confirm the credential harvest technique
6Find the workstation that ran the exploit toolchain
7Classify the privilege escalation root cause

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Oct 6, 2026, you can jump straight in.

Get Started Free