Detecting Active Directory Compromise
Hunt for advanced identity attacks in on-premises and hybrid Active Directory environments
Most Australian ransomware incidents share a common signature: Active Directory compromise precedes encryption by days or weeks. This intensive workshop trains detection engineers and SOC analysts to identify Kerberos abuse, DCSync attacks, persistence techniques, and golden ticket scenarios using Windows event logs, Microsoft Defender for Identity, and Microsoft Sentinel — before attackers reach domain controller level.

At a Glance
Who it's for
- SOC analysts and threat hunters responsible for Active Directory threat detection
- Incident response engineers investigating ransomware precursor activity
- Identity engineers who completed the Securing Active Directory course and want detection depth
- Security architects designing detection controls for ASD Essential Eight Maturity Level 2 compliance
Course Details
Course Overview
This two-day intensive starts from the attacker's perspective. Each module begins with the attack technique — executed in the lab — and then works backwards through the artefacts it leaves in Windows Security event logs, Microsoft Defender for Identity alerts, and Sentinel analytics. Attack-then-detect sequencing is intentional: detection engineers who understand how an attack works write better detection rules than those who learn detection in isolation. The scenario set reflects real Australian incident patterns documented in ACSC Annual Cyber Threat Reports: Kerberoasting against service accounts, credential dumping from NTDS.dit, Pass-the-Hash lateral movement, and domain persistence via golden tickets and AdminSDHolder abuse. Each attack is mapped to MITRE ATT&CK and to the Essential Eight Maturity Level 2 detection requirements that frame IRAP assessment scope.
What You'll Learn
Course Curriculum
Module 1: Reconnaissance and Initial Access Detection
4 hours- Active Directory enumeration: BloodHound, SharpHound, and LDAP query detection in Security event logs
- Kerberoasting: SPN enumeration, TGS-REQ patterns, and detection via Event ID 4769 and Defender for Identity
- AS-REP Roasting: detecting user accounts with Kerberos pre-authentication disabled
- Password spray and credential stuffing: detecting distributed authentication attempts across DCs
- ACSC threat context: how initial access translates to AD enumeration in Australian ransomware incidents
Module 2: Credential Theft and Privilege Escalation Detection
4 hours- LSASS credential dumping: detecting process access events (Event ID 4656, 10) and Defender for Endpoint alerts
- DCSync detection: replication directory service changes (Event ID 4662) and Defender for Identity DCSync alert
- NTDS.dit theft: VSS shadow copy abuse, ntdsutil.exe usage, and backup operator privilege abuse
- Mimikatz detection: process signatures, command-line patterns, and AMSI bypass techniques
- Pass-the-Hash lateral movement: Event IDs 4624 (Logon Type 3) and 4648 tracking across DCs
Module 3: Lateral Movement and Domain Persistence Detection
4 hours- Pass-the-Ticket and Overpass-the-Hash: Kerberos ticket anomalies and encryption downgrade alerts
- Golden ticket detection: Defender for Identity golden ticket alert and Event ID 4769 anomaly patterns
- Domain persistence: AdminSDHolder abuse, DCSync rights delegation, and Group Policy Object modification
- Skeleton key malware: detecting LSASS patching and authentication bypass techniques
- Microsoft Sentinel KQL hunting: building cross-DC correlation queries for lateral movement chains
Module 4: Detection Engineering and Incident Response Capstone
4 hours- Write Microsoft Sentinel analytics rules for the attack patterns from Modules 1-3
- Build a Defender for Identity custom detection tuning plan: reducing false positives while maintaining coverage
- Incident response tabletop: complete AD compromise kill chain from initial access to golden ticket
- ASD Essential Eight Maturity Level 2 detection evidence: mapping alerts to ISM control families
- Detection runbook deliverable: AD compromise detection playbook for SOC integration
Who Should Attend
- SOC analysts and threat hunters responsible for Active Directory detection coverage
- Detection engineers writing Sentinel analytics rules for identity attack patterns
- Incident responders investigating ransomware precursor activity in Australian organisations
- Identity engineers who completed Securing Active Directory and want detection depth
- Security architects evidencing Essential Eight Maturity Level 2 detect controls for IRAP scope
- MSSP analysts monitoring hybrid Active Directory estates across multiple client tenants
Prerequisites
Before enrolling, please ensure you meet these requirements:
- • Completion of Securing Active Directory (AD-SEC-001) or equivalent hands-on AD security experience
- • Working knowledge of Windows Security event logging and event ID interpretation
- • Basic KQL or Splunk query experience — advanced query construction is taught in the course
- • Microsoft Defender for Identity or Microsoft Sentinel access (trial acceptable)
- • A laptop with a modern browser — the domain-joined lab environment is provided
Delivery, Format and Logistics
Delivery Mode
Live online attack-then-detect workshop — 2 days intensive with a provided lab forest
Maximum 10 participants — intensive lab-first format with attack-then-detect scenarios
What You'll Need
- Completion of Securing Active Directory (AD-SEC-001) or equivalent hands-on AD security experience
- Working knowledge of Windows event logging and basic KQL or Splunk query experience
- Microsoft Defender for Identity or Microsoft Sentinel access (trial acceptable for lab exercises)
- Lab environment with domain-joined Windows VMs provided — participants require laptop with browser access
What You'll Receive
- 16 hours of lab-first instruction capped at 10 participants
- Pre-built lab forest with domain-joined Windows Server and Windows 11 VMs
- Mimikatz and BloodHound attack exercises paired with the detection artefacts they leave behind
- Microsoft Defender for Identity deployment and a Sentinel workspace pre-loaded with AD connector data
- Sentinel analytics rules and hunting queries for every attack technique covered
- Defender for Identity alert tuning plan for reducing false positives without losing coverage
- AD compromise detection runbook deliverable ready for SOC playbook integration
- Recorded sessions for 6 months and a certificate of completion
Frequently Asked Questions
Not Ready to Enrol?
Join our mailing list to receive updates about courses, resources, and cybersecurity insights tailored for Australian organisations.
Early-bird rate — apply your promo code at checkout.
Secure payment via Stripe · Promo codes accepted
Next Intake
September 2026 — register your interest at educ4te.com
Format
Live online attack-then-detect workshop — 2 days intensive with a provided lab forest
Group & Enterprise Options
Discounted rates available for teams of 3+ delegates. Contact us for in-house delivery options.
What's Included
- 16 hours of lab-first instruction capped at 10 participants
- Pre-built lab forest with domain-joined Windows Server and Windows 11 VMs
- Mimikatz and BloodHound attack exercises paired with the detection artefacts they leave behind
- Microsoft Defender for Identity deployment and a Sentinel workspace pre-loaded with AD connector data
- Sentinel analytics rules and hunting queries for every attack technique covered
- Defender for Identity alert tuning plan for reducing false positives without losing coverage
- AD compromise detection runbook deliverable ready for SOC playbook integration
- Recorded sessions for 6 months and a certificate of completion
Have questions about this course?