Skip to content

Area 11 / 12

Auditing, Logging & Detection

Hardening reduces the attack surface; detection catches what gets through. This area sets an advanced audit policy on domain controllers, adds SACLs to sensitive objects, calls out the event IDs that matter for AD attacks, and positions Microsoft Defender for Identity and honeytokens.

Start the path