The Cybersecurity and Infrastructure Security Agency and international partners updated guidance on detecting and mitigating Microsoft Active Directory compromises.
Details: The guidance:
-
Describes 17 common techniques threat actors use to compromise Active Directory.
-
Provides an expansion to the "Detecting DCSync" and "Shadow Credentials" sections, highlighting new methods for threat actors to gain access to accounts in a Windows domain while evading detection.