1. Prerequisites
- Domain Controller logs
- Authentication telemetry
- Privileged account activity
- EDR alerts
- SIEM detections
- Access to Active Directory
- Access to EDR platform
- Access to SIEM
- Access to identity provider
- Access to PowerShell
- Access to AD auditing tools
2. Step-by-Step Instructions
Common Failure Modes
- Leaving privileged sessions active
- Failing to rotate service account credentials
- Ignoring shadow admin persistence
- Restoring systems before AD validation
-
Review Privileged Account Activity
- Identify:
- Domain Admin usage
- Enterprise Admin activity
- Service account anomalies
- Newly created privileged accounts
- Identify:
-
Disable Suspected Compromised Accounts
- Immediately:
- Disable compromised privileged accounts
- Rotate privileged credentials
- Reset KRBTGT if required
- Immediately:
-
Identify Persistence Mechanisms
- Review for:
- Scheduled tasks
- Startup scripts
- GPO modifications
- Malicious services
- Shadow admin accounts
- Review for:
-
Protect Domain Controllers
- Restrict administrative access
- Isolate DCs if required
- Review replication anomalies
- Monitor authentication spikes
-
Validate Identity Infrastructure Integrity
- Confirm:
- GPO integrity
- Replication health
- Authentication stability
- Administrative group integrity
- Confirm:
3. Post-Action
- Document all containment steps taken in the incident ticket, along with the time each action was taken
Contributor
Vishal Thakur GitHub: https://github.com/malienist
Jayden Vo GitHub: https://github.com/jayden-vo
Contributed to the Arcana Incident Response Documentation Framework.
