Critical severityHARDEC6 steps · 6 phases
Privilege Escalation / Domain Admin Compromise
Privilege escalation / Domain/Tenant admin compromise; focused on AD forest recovery.
Information note
Informational note: When a domain administrator account is compromised, simply disabling the account is not sufficient; the attacker may know the krbtgt hash and can continue to persist in the environment using a Golden Ticket. Under MITRE T1484, reset the krbtgt password twice (due to replication latency), audit ACL changes on all domain controllers, and treat all systems where privileged accounts have logged in as within the scope of the breach.
1
Preparation
1 steps- Tiered admin + backup
Admin tiering, PAW, krbtgt rotation procedure, AD backup.
2
Identification
1 steps- Find the escalation path
Exploited vulnerability/misconfiguration (DCSync, Kerberoasting, token theft), compromised privileged accounts.
3
Containment
1 steps- Revoke privilege
Disable compromised admin accounts, restrict DC access, terminate privileged sessions.
4