25.7.3
This website uses cookies to ensure you get the best experience on our website. Learn more
EXPIRED ON FEBRUARY 25, 2024 This credential has expired and is no longer valid.

Certified Enterprise Security Specialist (PACES)

Zachary Fleming

This is one of a kind certification. To earn the PACES certification, students need to compromise and fix a multi-forest exam lab environment. It needs a thorough understanding of both attack and defense of Active Directory to achieve this rare certification. The 48-hour hands-on exam tests students' ability to apply both attack and defense concepts. Success in the exam depends on the quality of report submitted after the exam, forests compromised with minimal alerts and forests secured. PACES is a certification for highly skilled security professionals and not many have achieved this rare distinction. A PACES holder has at least the following skills: - Abuse defence mechanisms like LAPS, exploit modern Windows features like WSL and extract secrets - Abusing user simulation and exploit enterprise applications - Pivot across forest trusts - Bypass logon restrictions, play with Kerberos tickets, in-depth understanding of TGT and TGS abuse - Tackle Kerberos double hop issues within forest and across forest trust - Extract credentials from DC in the other forest and escalate from child to forest root in the other forests - Abuse JEA endpoints and evade restrictions - Plan and execute phishing attacks against user simulation - Abuse MS Exchange permissions - Bypass WDAC, ASR and CLM to compromise machines - Execute multi-forest hop completely using in-memory code execution - Exploit air-gapped servers by abusing Windows features - Exploit hypervisors and offline domain controllers - Advanced Inter-forest trust attacks

Skills / Knowledge

  • active directory
  • windows security
  • red team
  • cyber security
  • infosec
  • penetration testing
  • network security
  • information security
  • powershell
  • blue team
  • active directory security

Issued on

February 25, 2021

Expired on

February 25, 2024