the admin café

Grab a cup.Let's take Windows apart, and put it back together, safer.

A quiet corner for IT security in Windows environments: how attacks work, and what actually stops them. Slow-brewed by Lukas.

36 articles, 13 Hack The Box write-ups, writing since 2023.

The Daily FeedADHardenKit: Hardening AD Without Breaking It
today's roast:
Tools, extra shot
winter special:
hot chocolate, Tools on the side
spring special:
matcha, with Tools
too hot for coffee:
iced, with Tools
pumpkin spice season:
Tools, extra cinnamon
O'zapft is!
Tools und a Brezn
Frohe Weihnachten!
Tools mit Lebkuchen
boo.
Tools, if you dare
Prosit Neujahr!
stir the cup for confetti
Samichlaus isch da!
Tools und en Grittibänz
happy 1st of August!
Tools and a Weggli
Ändlich Fasnacht!
Tools und Chüechli
Frohe Ostern!
Tools mit Osterfladen
the café turns today!
Tools on the house

TODO: patch the DC ✓

SALTfor your hashes

Today's special

fresh off the press
Today's brewCappuccino5 min read

The Daily Feed

“Freshly brewed IT security, since 2023”

Morning editionPrice: freewith every cup
Vol. IV · No. 36Wednesday, 7 October 2026theadmincafe.ch · A1

Tools

ADHardenKit: Hardening AD Without Breaking It

LDAP signing, SMB signing, NTLM, Kerberos with AES only. Every hardening checklist has them. I wrote a tool that turns them on in an order that doesn't break the domain.

Fig. 1: from today's lead story. Full colour inside.The Admin Café

Every AD hardening checklist has the same items on it: require LDAP signing, require SMB signing, restrict NTLM, use Kerberos with AES only. In theory you just turn them on. In practice almost every one of them can break something that used to work, and the error shows up somewhere else. Require LDAP signing and a print server can't find the directory anymore. Enforce SMB signing and a NAS drops out at 3 a.m. Restrict NTLM, and a business application stops with an error message that tells you nothing.

So checklists often get applied halfway, or applied on a Friday and rolled back on Monday.

I wanted a tool that does it in the right …

Continued on A2 →

Read the full story →

The cork board

pinned up by the barista

Project #01

NTLM-Analyzer

Shows which users, machines and programs still use NTLMv1 or NTLMv2, and why Kerberos was not used. Agent on Windows, collector on Linux.

who still speaks NTLM?

Rust · Python · GPLv3ArticleGitHub ↗

Project #02

Doppio

Your own second factor for the Windows logon: a credential provider plus an LSA authentication package, in C++.

a double shot for your logon

The pastry case

Hack The Box write-ups, 13 baked so far. Only retired boxes make it into the case: day-old, still delicious.

All 13 boxes →

Stammgast

Become a regular

No newsletter, no tracking, no cookie banner. Just a feed that tells you when a fresh pot is ready.

Subscribe via RSS

Hausordnung

House rules

Found a crack in the cup? Tell the barista, not the whole café. Responsible disclosure details live in security.txt.

Read security.txt

Behind the counter

Meet the barista

Lukas. Wannabe ethical hacker, Hack The Box regular, nine stamps on the cert loyalty card.

servus! →

the admin café

Open whenever the shell is. Right now, apparently.

Tip jar. Costs nothing, cheers me up anyway.

© 2023–2026 Lukas. Servus.

Esc

Fresh today

Type to search all articles. ↑ ↓ and Enter to open a result.