BENCH.C — GOAD

Game of Active Directory.

GOAD is the open Active Directory pentesting lab maintained by the GOAD project. SecHive has loaded the lab and published the scoring schema; the first public scorecard is scheduled for 2026.Q3.

Status — framework only. This page documents the methodology spine. The first published scorecard will appear here when the campaign closes.
§ Scope

What we will count.

GOAD is multi-domain Active Directory. The campaign reports per-objective progress, not "owned the network" macros.

Objective familyCounts as a win whenEvidence kept
Initial footholdAuthenticated session on a non-trivial hostSession artifact, command receipt
Lateral movementAuthenticated session on a host other than the footholdAuth ticket, host inventory delta
Privilege escalationHigher-privilege token observed in a runtime callToken impersonation evidence
Domain dominanceDomain admin equivalent capability proven via runtime callAction receipt, scope-guard log
Cross-trustResource access across domain trust boundaryTrust traversal evidence
Data egress (lab-safe)Lab-internal data successfully relocatedEgress receipt, hash chain

Why a framework first.

Active Directory benchmarks are easy to overstate. Without an explicit objective list and an explicit proof rule per objective, "owned GOAD" means whatever the speaker wants it to mean. We publish the rule before we publish the score.

When you will see results.

  1. 2026.Q2Lab loaded, runner wired, scoring published.done
  2. 2026.Q3First public scorecard.scheduled
  3. 2026.Q4Cross-trust and OPSEC variants.planned