Active Directory Compromise Recovery
Active Directory compromise response: domain admin access, Golden Ticket, DCSync, DC takeover. Systematic recovery to prevent attacker re-entry.
Preparation
1 steps- Establish AD security monitoring baseline
Logon (4624/4625), Account Mgmt (4720-4740), Kerberos (4768/4769/4771), Privilege Use (4672), group changes, GPO (5136). SIEM forwarding.
Identification
2 steps- Detect Active Directory compromise indicators
DCSync from a non-DC source (4662/4627), new accounts in privileged groups, KRBTGT activity, abnormal replication, Golden Ticket.
- Determine scope and persistence mechanisms
All accounts with DA rights, new/modified GPOs, modified trusts, DSRM password (4794), Skeleton Key, SIDHistory.
Containment
1 steps- Emergency AD containment
First cut the attacker's network access, isolate DCs from the internet, block attacker accounts. Assess whether a domain rebuild is required.