Attack path management with BloodHound for defenders
Use BloodHound defensively: tag Tier Zero correctly, find choke points, fix attack paths in the right order, and track exposure over time with safe collection.
A practical map of Active Directory hardening for identity, Kerberos and domain controllers. Every control comes with the Group Policy path, the attribute or registry value, the PowerShell to verify it and the things it will break.
89%
controls enforced
RC4 tickets
0
−100% / 30 d
NTLM auth
3.1k
in audit
Aligned with
Why it works
Every guide is built the same way, so you can go from finding to enforced control without a second tab open.
The Group Policy path, the registry value and the attribute to set. No hand-waving, no "consider hardening".
Read the current state before you change it and prove the change afterwards, with commands you can paste.
Every guide ends with the compatibility fallout, so the control is not rolled back at the first help-desk ticket.
Audit modes, event IDs and staged rings: the rollout that survives contact with legacy apps.
A map of twelve areas and a 90-day plan that puts the controls behind most real breaches first.
The map
Each area groups the controls that defend against the same class of attack. Start anywhere, but the first three areas stop most real-world domain compromises.
Roadmap
The order matters. Close the paths attackers actually use first, then fix the structure, then keep it that way.
Days 0–30
Tier 0 inventory, roastable accounts, GPP passwords, LAPS and the machine account quota.
Days 31–60
LDAP and SMB signing, LLMNR off, unconstrained delegation removed, AD CS templates fixed.
Days 61–90
PAWs, authentication silos, RC4 off, NTLM restricted, DC firewalling and ACL clean-up.
Method
Active Directory hardening fails when it breaks authentication and gets rolled back. Audit modes exist for LDAP signing, NTLM and more: use them before you enforce.
Guides
Use BloodHound defensively: tag Tier Zero correctly, find choke points, fix attack paths in the right order, and track exposure over time with safe collection.
Remove the name-resolution fallbacks attackers poison: disable LLMNR, NetBIOS and mDNS by GPO and DHCP, and block WPAD with the DNS global query block list.
Why Microsoft retired ESAE as the default, what the enterprise access model asks you to build instead, and when a bastion forest or PAM trust still makes sense.
Build an Active Directory forest recovery runbook from Microsoft's guide: clean room, first DC restore, SYSVOL, FSMO, RID pool, krbtgt resets and yearly drills.
Deploy Microsoft security baselines with Group Policy: SCT, Policy Analyzer gap analysis, LGPO testing, ring-based rollout, exceptions and drift checks.
Design AD backups that survive ransomware: system state per domain, DSRM passwords, immutable and offline copies, a backup system outside the AD it protects.
Start with the 90-day plan, or pick the area that keeps you up at night.