Defending against Kerberoasting and AS-REP roasting
Shrink Kerberoasting and AS-REP roasting exposure: inventory SPNs, remove stale ones, move to gMSA and AES, deploy a honey SPN and detect RC4 4769 spikes.
Guides tagged
Shrink Kerberoasting and AS-REP roasting exposure: inventory SPNs, remove stale ones, move to gMSA and AES, deploy a honey SPN and detect RC4 4769 spikes.
Audit who holds DS-Replication-Get-Changes-All and equivalent rights on the domain root, remove the ones that should not exist, and alert on DCSync.
Deploy honey accounts, honey SPNs, AS-REP decoys, fake GPP passwords and read-audited decoy objects in AD, and alert on them with near-zero false positives.
Build a Windows Event Forwarding pipeline for DCs: source-initiated subscriptions, GPO, log access, XPath queries, collector sizing and health checks.
Every AD security event ID worth collecting on domain controllers: logon, Kerberos, NTLM, account, group, directory and AD CS events, with fields to hunt.
Configure Advanced Audit Policy, SACLs, and Windows Event Forwarding so you can actually see Kerberoasting, DCSync, and privilege escalation in AD.