Top 10 Active Directory Attack Methods and How to Defend Against Them

Discover the top 10 Active Directory attacks like Kerberoasting, pass-the-hash, and LLMNR poisoning—plus expert tips to secure your AD environment.

Jul 25, 2025 - 11:43
Updated: 2 days ago
104k
Top 10 Active Directory Attack Methods and How to Defend Against Them

Quick answer: Attackers target Active Directory because it controls identity across a Windows network. Common techniques include password spraying, Kerberoasting, AS-REP roasting, LLMNR and NTLM relay, pass-the-hash, pass-the-ticket and Golden Ticket, DCSync, delegation abuse, certificate services (AD CS) abuse and attack-path enumeration. Defences are strong credentials, tiered administration, monitoring and patching.

Key takeaways

  • AD is a prime target because compromising it gives control of most users, servers and data in a Windows environment.
  • Most AD attacks abuse legitimate features and weak configuration, such as weak service account passwords, old protocols and excess privilege.
  • Defence is mostly hygiene: strong and long service account passwords, disable legacy protocols, tiered admin model, LAPS, patching and monitoring.
  • Know a few event IDs: 4625, 4768, 4769, 4662 and 5136 appear in many detections.
  • Practise only in your own AD lab. Testing a real directory needs written authorisation under India's IT Act.

Why is Active Directory a favourite target?

Active Directory (AD) holds identities, groups and policies for most Windows networks. Whoever controls it, especially the domain controllers and privileged groups, can reach almost everything. Attackers usually start with an ordinary user account, then enumerate, steal or crack credentials, move sideways and climb to domain administrator. The techniques below are described at concept level for defenders and students. For exploit tooling and practice, use an isolated lab and written authorisation.

The ten techniques

#TechniqueIdeaDetect withMitigate with
1Password sprayingTry one or few common passwords across many accounts to avoid lockoutMany 4625 or 4771 failures across many users from one sourceMFA, banned password lists, smart lockout, monitoring
2KerberoastingRequest service tickets for accounts with SPNs, then crack them offline4769 spikes, especially with weak encryption typesLong random service account passwords, gMSA, AES only
3AS-REP roastingRequest authentication data for accounts with pre-authentication disabled, crack offline4768 for accounts that do not require pre-authKeep pre-authentication enabled, audit the setting
4LLMNR and NBT-NS poisoning, NTLM relayAnswer broadcast name lookups to capture or relay NTLM authenticationUnexpected NTLM authentications, network monitoringDisable LLMNR and NBT-NS, require SMB and LDAP signing, restrict NTLM
5Pass-the-hashUse a stolen NTLM hash instead of the passwordNTLM logons from unusual hosts, 4624 type 3 or 9Restrict NTLM, LAPS, credential guard, limit local admin
6Pass-the-ticket and Golden TicketReuse or forge Kerberos tickets, including with the krbtgt keyTickets with odd lifetimes, 4769 without matching 4768Protect domain controllers, rotate krbtgt twice after compromise, tiering
7DCSyncAbuse replication rights to pull password data from a domain controller4662 with directory replication rights from non-DC hostsLimit replication permissions, monitor, protect privileged accounts
8Delegation abuseMisconfigured Kerberos delegation lets a service impersonate usersChanges in delegation attributes (5136), unusual service ticketsAvoid unconstrained delegation, protect sensitive accounts, audit
9AD CS (certificate services) abuseWeak certificate templates let low-privilege users get certificates for privileged identitiesCertificate issuance events, template changesReview templates, restrict enrolment, patch, audit AD CS
10Attack-path enumerationMap group and permission relationships to find routes to admin, using tools like BloodHoundLarge LDAP queries from a single hostFix risky ACLs and nested groups, tier admins, audit paths yourself

The MITRE ATT&CK knowledge base lists these under credential access, lateral movement and privilege escalation, and is useful for mapping detections.

How can you harden Active Directory?

  1. Tiered administration. Domain admin accounts should log on only to domain controllers and dedicated admin hosts, never to workstations or member servers.
  2. Protect service accounts. Long random passwords or group managed service accounts, least privilege, no interactive logon.
  3. Retire legacy protocols. Disable LLMNR and NetBIOS name resolution, require SMB signing and LDAP signing and channel binding, reduce NTLM use.
  4. Use LAPS so local administrator passwords are unique per machine.
  5. MFA and conditional access for remote and privileged access.
  6. Patch domain controllers and AD CS servers quickly.
  7. Audit dangerous settings: pre-authentication disabled, delegation, stale privileged accounts, weak ACLs, risky certificate templates.
  8. Monitor with a SIEM and the right audit policy. Forward domain controller logs.
  9. Back up AD and rehearse forest recovery.

Which event IDs should defenders know?

Event IDMeaning
4624 / 4625Successful or failed logon
4768 / 4769 / 4771Kerberos ticket granting ticket request, service ticket request and pre-authentication failure
4662An operation was performed on an object (used for DCSync detection when auditing is enabled)
4728 / 4732 / 4756Member added to a privileged group
5136A directory object was modified

Event availability depends on audit policy and Windows version. Microsoft documents them on Microsoft Learn.

How do you practise safely?

Build an isolated lab: a domain controller, a member server and a workstation in virtual machines on a host-only network. Practise both sides, simulate in the lab, then find the events and fix the weakness. A real directory must never be tested without written authorisation, and even then in agreed windows.

What about real-world examples?

Public incident reports of ransomware and intrusions often describe attackers gaining domain admin through stolen credentials and AD weaknesses. This article does not cite specific incidents or statistics. For case studies, read primary sources such as government advisories and vendor incident reports. A good start is MITRE's technique pages, which list known groups and references.

Next steps

To learn AD defence and testing, see WebAsha's VAPT training and SOC training. Related reading: dangerous Active Directory misconfigurations.

Frequently Asked Questions

Common attacks include password spraying, Kerberoasting, AS-REP roasting, LLMNR and NTLM relay, pass-the-hash, pass-the-ticket and Golden Ticket, DCSync, delegation abuse, AD CS abuse and attack-path enumeration.

Monitor event 4769 for service ticket requests, especially unusual volumes by one account or requests using weak encryption types. Long random service account passwords and group managed service accounts reduce the risk.

Use multi-factor authentication, banned password lists, smart lockout and monitoring for failed logons spread across many accounts from one source. Strong password policy alone does not stop it.

DCSync abuses replication rights to pull password data from a domain controller. Limit replication permissions to domain controllers, monitor event 4662, protect privileged accounts and respond quickly if a non-DC requests replication.

Tiering separates administrative accounts by what they manage, so domain admin credentials are used only on domain controllers and dedicated admin hosts. This stops stolen credentials on workstations from reaching the whole domain.

Yes, in your own isolated lab with virtual machines. Never test a real directory without written authorisation, since unauthorised access is an offence under India's IT Act.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.