Auditing Active Directory ACLs Before an Attacker Does
How to find dangerous AD ACLs like GenericAll and DCSync rights, clean up stale adminCount flags, and use BloodHound defensively.
Domains · Domain Controllers · Forests
A practical map of Active Directory hardening for identity, Kerberos and domain controllers. Every control comes with the Group Policy path, the attribute or registry value, the PowerShell to verify it and the things it will break.
The map
Each area groups the controls that defend against the same class of attack. Start anywhere, but the first three areas stop most real-world domain compromises.
Method
Active Directory hardening fails when it breaks authentication and gets rolled back. Audit modes exist for LDAP signing, NTLM and more: use them before you enforce.
Read the current state with PowerShell, an assessment tool or Policy Analyzer before changing anything.
Turn on the control in audit mode and collect the authentications it would have blocked.
Fix or exclude the real collisions, then enforce ring by ring with a rollback plan.
Re-check the setting and alert on drift, so the control stays on after the next change.
Guides
How to find dangerous AD ACLs like GenericAll and DCSync rights, clean up stale adminCount flags, and use BloodHound defensively.
Audit unconstrained, constrained, and resource-based constrained delegation in Active Directory, and lock down privileged accounts against abuse.
Run recurring AD posture assessments against CIS and Microsoft baselines, protect Tier 0 backups, and rehearse forest recovery before you need it for real.
Configure Advanced Audit Policy, SACLs, and Windows Event Forwarding so you can actually see Kerberoasting, DCSync, and privilege escalation in AD.
Why the forest — not the domain — is the AD security boundary, and how to lock down trusts with SID filtering, quarantine, and selective authentication.
Harden Active Directory Certificate Services against ESC1-ESC8 misconfigurations with template controls, EPA, and enrollment monitoring.