Top 10 Active Directory Attack Methods and How to Defend Against Them
Discover the top 10 Active Directory attacks like Kerberoasting, pass-the-hash, and LLMNR poisoning—plus expert tips to secure your AD environment.
Quick answer: Attackers target Active Directory because it controls identity across a Windows network. Common techniques include password spraying, Kerberoasting, AS-REP roasting, LLMNR and NTLM relay, pass-the-hash, pass-the-ticket and Golden Ticket, DCSync, delegation abuse, certificate services (AD CS) abuse and attack-path enumeration. Defences are strong credentials, tiered administration, monitoring and patching.
Key takeaways
- AD is a prime target because compromising it gives control of most users, servers and data in a Windows environment.
- Most AD attacks abuse legitimate features and weak configuration, such as weak service account passwords, old protocols and excess privilege.
- Defence is mostly hygiene: strong and long service account passwords, disable legacy protocols, tiered admin model, LAPS, patching and monitoring.
- Know a few event IDs: 4625, 4768, 4769, 4662 and 5136 appear in many detections.
- Practise only in your own AD lab. Testing a real directory needs written authorisation under India's IT Act.
Why is Active Directory a favourite target?
Active Directory (AD) holds identities, groups and policies for most Windows networks. Whoever controls it, especially the domain controllers and privileged groups, can reach almost everything. Attackers usually start with an ordinary user account, then enumerate, steal or crack credentials, move sideways and climb to domain administrator. The techniques below are described at concept level for defenders and students. For exploit tooling and practice, use an isolated lab and written authorisation.
The ten techniques
| # | Technique | Idea | Detect with | Mitigate with |
|---|---|---|---|---|
| 1 | Password spraying | Try one or few common passwords across many accounts to avoid lockout | Many 4625 or 4771 failures across many users from one source | MFA, banned password lists, smart lockout, monitoring |
| 2 | Kerberoasting | Request service tickets for accounts with SPNs, then crack them offline | 4769 spikes, especially with weak encryption types | Long random service account passwords, gMSA, AES only |
| 3 | AS-REP roasting | Request authentication data for accounts with pre-authentication disabled, crack offline | 4768 for accounts that do not require pre-auth | Keep pre-authentication enabled, audit the setting |
| 4 | LLMNR and NBT-NS poisoning, NTLM relay | Answer broadcast name lookups to capture or relay NTLM authentication | Unexpected NTLM authentications, network monitoring | Disable LLMNR and NBT-NS, require SMB and LDAP signing, restrict NTLM |
| 5 | Pass-the-hash | Use a stolen NTLM hash instead of the password | NTLM logons from unusual hosts, 4624 type 3 or 9 | Restrict NTLM, LAPS, credential guard, limit local admin |
| 6 | Pass-the-ticket and Golden Ticket | Reuse or forge Kerberos tickets, including with the krbtgt key | Tickets with odd lifetimes, 4769 without matching 4768 | Protect domain controllers, rotate krbtgt twice after compromise, tiering |
| 7 | DCSync | Abuse replication rights to pull password data from a domain controller | 4662 with directory replication rights from non-DC hosts | Limit replication permissions, monitor, protect privileged accounts |
| 8 | Delegation abuse | Misconfigured Kerberos delegation lets a service impersonate users | Changes in delegation attributes (5136), unusual service tickets | Avoid unconstrained delegation, protect sensitive accounts, audit |
| 9 | AD CS (certificate services) abuse | Weak certificate templates let low-privilege users get certificates for privileged identities | Certificate issuance events, template changes | Review templates, restrict enrolment, patch, audit AD CS |
| 10 | Attack-path enumeration | Map group and permission relationships to find routes to admin, using tools like BloodHound | Large LDAP queries from a single host | Fix risky ACLs and nested groups, tier admins, audit paths yourself |
The MITRE ATT&CK knowledge base lists these under credential access, lateral movement and privilege escalation, and is useful for mapping detections.
How can you harden Active Directory?
- Tiered administration. Domain admin accounts should log on only to domain controllers and dedicated admin hosts, never to workstations or member servers.
- Protect service accounts. Long random passwords or group managed service accounts, least privilege, no interactive logon.
- Retire legacy protocols. Disable LLMNR and NetBIOS name resolution, require SMB signing and LDAP signing and channel binding, reduce NTLM use.
- Use LAPS so local administrator passwords are unique per machine.
- MFA and conditional access for remote and privileged access.
- Patch domain controllers and AD CS servers quickly.
- Audit dangerous settings: pre-authentication disabled, delegation, stale privileged accounts, weak ACLs, risky certificate templates.
- Monitor with a SIEM and the right audit policy. Forward domain controller logs.
- Back up AD and rehearse forest recovery.
Which event IDs should defenders know?
| Event ID | Meaning |
|---|---|
| 4624 / 4625 | Successful or failed logon |
| 4768 / 4769 / 4771 | Kerberos ticket granting ticket request, service ticket request and pre-authentication failure |
| 4662 | An operation was performed on an object (used for DCSync detection when auditing is enabled) |
| 4728 / 4732 / 4756 | Member added to a privileged group |
| 5136 | A directory object was modified |
Event availability depends on audit policy and Windows version. Microsoft documents them on Microsoft Learn.
How do you practise safely?
Build an isolated lab: a domain controller, a member server and a workstation in virtual machines on a host-only network. Practise both sides, simulate in the lab, then find the events and fix the weakness. A real directory must never be tested without written authorisation, and even then in agreed windows.
What about real-world examples?
Public incident reports of ransomware and intrusions often describe attackers gaining domain admin through stolen credentials and AD weaknesses. This article does not cite specific incidents or statistics. For case studies, read primary sources such as government advisories and vendor incident reports. A good start is MITRE's technique pages, which list known groups and references.
Next steps
To learn AD defence and testing, see WebAsha's VAPT training and SOC training. Related reading: dangerous Active Directory misconfigurations.
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0