Red Team Operator

JAY TIWARI

Active Directory Exploitation  ·  EDR Evasion  ·  Adversary Simulation

Threat Profile

OPERATOR BRIEF

Offensive security specialist focused on enterprise Active Directory environments and defeating modern endpoint detection technologies.

jay@kali: ~ $ whoami
$ cat operator.json

name  : Jay Tiwari
role  : Red Team Operator
focus  : AD Exploitation · EDR Bypass
emulation  : MITRE ATT&CK Aligned
blog  : blog.jaytiwari.me
linkedin  : jaytiwari05

$ cat mission.txt

Find, exploit, and document weaknesses
before the real adversary does.
Enterprise AD compromise and modern
AV/EDR evasion are the primary domains.

$
AD
Primary Domain
Active Directory Exploitation
EDR
Evasion Focus
CrowdStrike · Defender · S1
C2
Framework Ops
Cobalt Strike · Sliver · Havoc
RT
Full Lifecycle
End-to-end engagement execution
Core Capabilities

SPECIALIZATIONS

ACTIVE DIRECTORY

Deep expertise in exploiting enterprise AD environments - from enumeration through full domain compromise using detection-aware techniques.

  • Kerberoasting & AS-REP Roasting
  • BloodHound / SharpHound Recon
  • DCSync & DCShadow Attacks
  • ADCS Exploitation (ESC1–ESC8)
  • Golden & Silver Ticket Forging
  • ACL Abuse & GPO Hijacking
  • Trust Relationship Exploitation

EDR / AV EVASION

Crafting payloads that survive modern endpoint detection - userland hooks through kernel callbacks, bypassing the full detection stack.

  • AMSI & ETW Bypass Techniques
  • Direct & Indirect Syscalls
  • Process Injection (Classic → BOF)
  • Sleep Obfuscation Primitives
  • Reflective DLL Development
  • Memory Evasion & PE Stomping
  • LOLBins & Proxy Execution

RED TEAM OPS

Full-spectrum engagement execution - OSINT through objective, with OPSEC-conscious tradecraft mapped to MITRE ATT&CK.

  • C2 Framework Operations
  • Lateral Movement & Pivoting
  • Persistence & Defense Evasion
  • Phishing & Initial Access
  • OPSEC-Aware Tradecraft
  • Data Exfiltration Techniques
  • Adversary Emulation Planning
Tradecraft

ARSENAL

KerberoastingAS-REP RoastingDCSyncDCShadowBloodHoundSharpHoundPowerViewRubeusGolden TicketSilver TicketPass-the-HashPass-the-TicketOverpass-the-HashADCS ESC1–ESC8Certipy-ADACL AbuseGPO HijackingLAPS BypassConstrained DelegationUnconstrained DelegationRBCD AbuseS4U2Self / S4U2ProxyForest Trust AbuseSMB RelayLLMNR PoisoningLDAP EnumerationMimikatzimpacketCrackMapExecEvil-WinRM
AMSI BypassETW PatchingDirect SyscallsIndirect SyscallsHalosGateSysWhispersProcess HollowingProcess DoppelgängingThread HijackingEarly Bird APC InjectionMapViewOfSection InjectionReflective DLL InjectionBOF DevelopmentSleep ObfuscationEkko SleepFoliage ObfuscationPE StompingModule StompingShellcode ObfuscationString EncryptionStack SpoofingPPID SpoofingUserland UnhookingWDAC BypassAppLocker BypassKernel Callback Evasion
Cobalt StrikeSliver C2Havoc C2MetasploitBurp Suite ProBloodHound CENmapNucleiNessusLigolo-ngChiselProxychainsResponderInveighNetExecimpacket SuiteRubeusMimikatzx64dbgWinDbgIDA ProProcess HackerKali LinuxVillain C2PowerShell Empire
Technique Showcase

AD KILL CHAIN

A representative enterprise AD compromise - initial foothold through full domain takeover.

🌐
Initial Access
Phishing / Exploit
🛡️
App Control
WDAC / AppLocker bypass
🔍
Recon
BloodHound, LDAP
🔑
ACL Abuse
WriteDACL, GenericAll
↔️
Lateral Move
PTH / WMI / SMB
📜
ADCS Abuse
ESC1–17 cert → DA auth
DCSync
Dump NTDS hashes
♾️
Persistence
Golden Ticket, Skeleton Key
Current Phase
Initializing…
Progress
0%
Knowledge Base

FIELD NOTES

📓
blog.jaytiwari.me

Technical write-ups on Active Directory attacks, EDR evasion research, red team tool development, and offensive security tradecraft. Hands-on content for practitioners.

Active DirectoryEDR ResearchRed TeamMalware DevCTF Write-ups
Read Articles ↗
Reach Out

CONNECT

Open to red team engagements, security research collaboration, and adversary simulation discussions.