Skip to content

Florian Amette

Security engineer writing practical, baseline-aligned hardening guides for Active Directory: identity, Kerberos, delegation and domain controllers.

NTLM & Legacy Protocols

Disable LLMNR, NBT-NS, mDNS and WPAD in AD

Remove the name-resolution fallbacks attackers poison: disable LLMNR, NetBIOS and mDNS by GPO and DHCP, and block WPAD with the DNS global query block list.

Foundation
Assessment, Backup & Recovery

Writing and rehearsing an AD forest recovery plan

Build an Active Directory forest recovery runbook from Microsoft's guide: clean room, first DC restore, SYSVOL, FSMO, RID pool, krbtgt resets and yearly drills.

Advanced
Group Policy & SYSVOL

Deploying Microsoft security baselines with GPO

Deploy Microsoft security baselines with Group Policy: SCT, Policy Analyzer gap analysis, LGPO testing, ring-based rollout, exceptions and drift checks.

Intermediate
Assessment, Backup & Recovery

Protecting Active Directory backups from ransomware

Design AD backups that survive ransomware: system state per domain, DSRM passwords, immutable and offline copies, a backup system outside the AD it protects.

Intermediate
Object & ACL Security

AdminSDHolder and SDProp: cleanup and monitoring

Baseline the AdminSDHolder ACL, find orphaned adminCount=1 accounts, reset their ACLs safely, trigger SDProp on demand, and alert on AdminSDHolder changes.

Intermediate
Group Policy & SYSVOL

Auditing GPO permissions and gPLink rights

Find who can edit, create and link GPOs in Active Directory: GPO ACLs, gPLink rights on OUs and sites, Group Policy Creator Owners and WMI filters.

Intermediate
Assessment, Backup & Recovery

PingCastle assessment: from AD report to action plan

Run a PingCastle health check on Active Directory, read the four risk scores correctly, triage findings into owners and sprints, and track progress over time.

Foundation
Group Policy & SYSVOL

Finding and removing GPP passwords (cpassword)

Find every Group Policy Preferences cpassword in SYSVOL, backups and client caches, map it to the exposed account, rotate it and stop it coming back.

Foundation
NTLM & Legacy Protocols

Audit and restrict NTLM in Active Directory

A step-by-step NTLM reduction plan: audit with events 8001-8004, fix the causes, build an exception list, remove NTLMv1 and set LmCompatibilityLevel 5.

Advanced
Trusts & Forest Design

Cleaning up SIDHistory after AD migrations

Find, assess and safely remove sIDHistory left over from domain migrations: dangerous SIDs, ACL re-permissioning, staged removal, rollback limits and detection.

Intermediate
NTLM & Legacy Protocols

Require SMB signing and disable SMBv1 domain-wide

Enforce SMB signing on clients and servers, understand Windows 11 24H2 and Server 2025 defaults, audit SMBv1 use, and remove it without breaking file access.

Foundation
NTLM & Legacy Protocols

Enforce LDAP signing and channel binding on DCs

Roll out LDAP signing and channel binding with evidence: collect events 2887, 2889 and 3039, fix clients, then set LdapEnforceChannelBinding safely.

Intermediate
Auditing, Logging & Detection

Windows Event Forwarding for domain controllers

Build a Windows Event Forwarding pipeline for DCs: source-initiated subscriptions, GPO, log access, XPath queries, collector sizing and health checks.

Intermediate
Auditing, Logging & Detection

Active Directory security event IDs: a DC reference

Every AD security event ID worth collecting on domain controllers: logon, Kerberos, NTLM, account, group, directory and AD CS events, with fields to hunt.

Foundation
Kerberos & Authentication

Disable RC4 in Kerberos: audit, fix and enforce AES

Remove RC4 from Kerberos safely: audit 4768/4769, fix accounts without AES keys, set msDS-SupportedEncryptionTypes and DefaultDomainSupportedEncTypes, enforce.

Intermediate
Passwords & Service Accounts

Migrating service accounts to gMSA and dMSA

Step-by-step migration from static service accounts to gMSA and Windows Server 2025 dMSA: KDS root key, retrieval rights, per-app notes and rollback.

Intermediate
Assessment, Backup & Recovery

AD assessment, backup and forest recovery

Run recurring AD posture assessments against CIS and Microsoft baselines, protect Tier 0 backups, and rehearse forest recovery before you need it for real.

Foundation
Trusts & Forest Design

Hardening AD trusts and forest boundaries

Why the forest — not the domain — is the AD security boundary, and how to lock down trusts with SID filtering, quarantine, and selective authentication.

Intermediate
Domain Controller Hardening

Domain controller hardening: the DC baseline

A practical checklist for hardening domain controllers: security baselines, Print Spooler, logon rights, RDP, egress, and patch priorities.

Foundation
Group Policy & SYSVOL

Group Policy and SYSVOL hardening

Lock down GPO delegation, purge Group Policy Preferences cpassword secrets from SYSVOL, and add change control to prevent silent GPO abuse.

Foundation
NTLM & Legacy Protocols

Stop NTLM relay: LDAP, SMB signing and LLMNR

Harden LDAP signing, LDAP channel binding, SMB signing, and disable LLMNR/NBT-NS to shut down NTLM relay paths against domain controllers.

Foundation
Passwords & Service Accounts

Service account hardening: gMSA, SPNs and LAPS

A practical guide to replacing risky service accounts with gMSA/dMSA, cleaning SPN exposure, fine-grained password policies, and Windows LAPS.

Foundation