Area 11 / 12
Auditing, Logging & Detection
Hardening reduces the attack surface; detection catches what gets through. This area sets an advanced audit policy on domain controllers, adds SACLs to sensitive objects, calls out the event IDs that matter for AD attacks, and positions Microsoft Defender for Identity and honeytokens.
Start the pathLearning path
0/4 done- 01AD auditing and detection: audit policy and event IDsConfigure Advanced Audit Policy, SACLs, and Windows Event Forwarding so you can actually see Kerberoasting, DCSync, and privilege escalation in AD.
- 02Active Directory security event IDs: a DC referenceEvery AD security event ID worth collecting on domain controllers: logon, Kerberos, NTLM, account, group, directory and AD CS events, with fields to hunt.
- 03AD honeytokens: honey accounts, honey SPNs and decoysDeploy honey accounts, honey SPNs, AS-REP decoys, fake GPP passwords and read-audited decoy objects in AD, and alert on them with near-zero false positives.
- 04Windows Event Forwarding for domain controllersBuild a Windows Event Forwarding pipeline for DCs: source-initiated subscriptions, GPO, log access, XPath queries, collector sizing and health checks.