Active Directory (AD) security descriptors hold secret pathways often unnoticed by both attackers and defenders. This SpecterOps research report explores how these hidden pathways can empower both attackers and defenders to navigate the covert landscape of AD, shedding light on overlooked opportunities for domain persistence.