AdvancedAD-DET-001

Detecting Active Directory Compromise

Hunt for advanced identity attacks in on-premises and hybrid Active Directory environments

Most Australian ransomware incidents share a common signature: Active Directory compromise precedes encryption by days or weeks. This intensive workshop trains detection engineers and SOC analysts to identify Kerberos abuse, DCSync attacks, persistence techniques, and golden ticket scenarios using Windows event logs, Microsoft Defender for Identity, and Microsoft Sentinel — before attackers reach domain controller level.

16 hours (2 days intensive)
New course
Certificate Included
Detecting Active Directory Compromise

At a Glance

Who it's for

  • SOC analysts and threat hunters responsible for Active Directory threat detection
  • Incident response engineers investigating ransomware precursor activity
  • Identity engineers who completed the Securing Active Directory course and want detection depth
  • Security architects designing detection controls for ASD Essential Eight Maturity Level 2 compliance

Course Details

Duration:16 hours (2 days intensive)
Format:Live online attack-then-detect workshop — 2 days intensive with a provided lab forest
Next intake:September 2026 — register your interest at educ4te.com
Alignment:Aligned to MITRE ATT&CK for Enterprise — Credential Access, Lateral Movement, and Privilege Escalation tactics. Aligns to ACSC Essential Eight detect controls.

Course Overview

This two-day intensive starts from the attacker's perspective. Each module begins with the attack technique — executed in the lab — and then works backwards through the artefacts it leaves in Windows Security event logs, Microsoft Defender for Identity alerts, and Sentinel analytics. Attack-then-detect sequencing is intentional: detection engineers who understand how an attack works write better detection rules than those who learn detection in isolation. The scenario set reflects real Australian incident patterns documented in ACSC Annual Cyber Threat Reports: Kerberoasting against service accounts, credential dumping from NTDS.dit, Pass-the-Hash lateral movement, and domain persistence via golden tickets and AdminSDHolder abuse. Each attack is mapped to MITRE ATT&CK and to the Essential Eight Maturity Level 2 detection requirements that frame IRAP assessment scope.

What You'll Learn

Identify Kerberoasting and AS-REP Roasting attack artefacts in Windows Security event logs and Defender for Identity alerts
Detect credential dumping techniques: LSASS memory access, NTDS.dit theft, and DCSync via Mimikatz
Hunt for Pass-the-Hash and Pass-the-Ticket lateral movement using Sentinel KQL queries
Detect domain persistence techniques: golden tickets, silver tickets, AdminSDHolder abuse, and skeleton keys
Write Microsoft Sentinel analytics rules and hunting queries for Active Directory attack patterns
Triage Defender for Identity alerts and correlate with Windows event logs for incident investigation
Map detections to MITRE ATT&CK techniques and to ASD Essential Eight Maturity Level 2 detect controls
Build an AD compromise detection runbook ready for SOC playbook integration

Course Curriculum

Module 1: Reconnaissance and Initial Access Detection

4 hours
  • Active Directory enumeration: BloodHound, SharpHound, and LDAP query detection in Security event logs
  • Kerberoasting: SPN enumeration, TGS-REQ patterns, and detection via Event ID 4769 and Defender for Identity
  • AS-REP Roasting: detecting user accounts with Kerberos pre-authentication disabled
  • Password spray and credential stuffing: detecting distributed authentication attempts across DCs
  • ACSC threat context: how initial access translates to AD enumeration in Australian ransomware incidents

Module 2: Credential Theft and Privilege Escalation Detection

4 hours
  • LSASS credential dumping: detecting process access events (Event ID 4656, 10) and Defender for Endpoint alerts
  • DCSync detection: replication directory service changes (Event ID 4662) and Defender for Identity DCSync alert
  • NTDS.dit theft: VSS shadow copy abuse, ntdsutil.exe usage, and backup operator privilege abuse
  • Mimikatz detection: process signatures, command-line patterns, and AMSI bypass techniques
  • Pass-the-Hash lateral movement: Event IDs 4624 (Logon Type 3) and 4648 tracking across DCs

Module 3: Lateral Movement and Domain Persistence Detection

4 hours
  • Pass-the-Ticket and Overpass-the-Hash: Kerberos ticket anomalies and encryption downgrade alerts
  • Golden ticket detection: Defender for Identity golden ticket alert and Event ID 4769 anomaly patterns
  • Domain persistence: AdminSDHolder abuse, DCSync rights delegation, and Group Policy Object modification
  • Skeleton key malware: detecting LSASS patching and authentication bypass techniques
  • Microsoft Sentinel KQL hunting: building cross-DC correlation queries for lateral movement chains

Module 4: Detection Engineering and Incident Response Capstone

4 hours
  • Write Microsoft Sentinel analytics rules for the attack patterns from Modules 1-3
  • Build a Defender for Identity custom detection tuning plan: reducing false positives while maintaining coverage
  • Incident response tabletop: complete AD compromise kill chain from initial access to golden ticket
  • ASD Essential Eight Maturity Level 2 detection evidence: mapping alerts to ISM control families
  • Detection runbook deliverable: AD compromise detection playbook for SOC integration

Who Should Attend

  • SOC analysts and threat hunters responsible for Active Directory detection coverage
  • Detection engineers writing Sentinel analytics rules for identity attack patterns
  • Incident responders investigating ransomware precursor activity in Australian organisations
  • Identity engineers who completed Securing Active Directory and want detection depth
  • Security architects evidencing Essential Eight Maturity Level 2 detect controls for IRAP scope
  • MSSP analysts monitoring hybrid Active Directory estates across multiple client tenants

Prerequisites

Before enrolling, please ensure you meet these requirements:

  • • Completion of Securing Active Directory (AD-SEC-001) or equivalent hands-on AD security experience
  • • Working knowledge of Windows Security event logging and event ID interpretation
  • • Basic KQL or Splunk query experience — advanced query construction is taught in the course
  • • Microsoft Defender for Identity or Microsoft Sentinel access (trial acceptable)
  • • A laptop with a modern browser — the domain-joined lab environment is provided

Delivery, Format and Logistics

Delivery Mode

Live online attack-then-detect workshop — 2 days intensive with a provided lab forest

Maximum 10 participants — intensive lab-first format with attack-then-detect scenarios

What You'll Need

  • Completion of Securing Active Directory (AD-SEC-001) or equivalent hands-on AD security experience
  • Working knowledge of Windows event logging and basic KQL or Splunk query experience
  • Microsoft Defender for Identity or Microsoft Sentinel access (trial acceptable for lab exercises)
  • Lab environment with domain-joined Windows VMs provided — participants require laptop with browser access

What You'll Receive

  • 16 hours of lab-first instruction capped at 10 participants
  • Pre-built lab forest with domain-joined Windows Server and Windows 11 VMs
  • Mimikatz and BloodHound attack exercises paired with the detection artefacts they leave behind
  • Microsoft Defender for Identity deployment and a Sentinel workspace pre-loaded with AD connector data
  • Sentinel analytics rules and hunting queries for every attack technique covered
  • Defender for Identity alert tuning plan for reducing false positives without losing coverage
  • AD compromise detection runbook deliverable ready for SOC playbook integration
  • Recorded sessions for 6 months and a certificate of completion

Frequently Asked Questions

Not Ready to Enrol?

Join our mailing list to receive updates about courses, resources, and cybersecurity insights tailored for Australian organisations.

By subscribing, you agree to receive email updates from Educ4te. You can unsubscribe at any time. We respect your privacy and will never share your information.

$799AUD
$999EARLY BIRD

Early-bird rate — apply your promo code at checkout.

1

Secure payment via Stripe · Promo codes accepted

Next Intake

September 2026 — register your interest at educ4te.com

Format

Live online attack-then-detect workshop — 2 days intensive with a provided lab forest

Group & Enterprise Options

Discounted rates available for teams of 3+ delegates. Contact us for in-house delivery options.

What's Included

  • 16 hours of lab-first instruction capped at 10 participants
  • Pre-built lab forest with domain-joined Windows Server and Windows 11 VMs
  • Mimikatz and BloodHound attack exercises paired with the detection artefacts they leave behind
  • Microsoft Defender for Identity deployment and a Sentinel workspace pre-loaded with AD connector data
  • Sentinel analytics rules and hunting queries for every attack technique covered
  • Defender for Identity alert tuning plan for reducing false positives without losing coverage
  • AD compromise detection runbook deliverable ready for SOC playbook integration
  • Recorded sessions for 6 months and a certificate of completion

Have questions about this course?