Active Directory Full Compromise Response (Golden / Silver Ticket / DCSync / Delegation)
When DCSync, NTDS dump, DA/DC takeover, or Golden/Silver Ticket evidence indicates domain-compromise class; executes the destructive response encompassing krbtgt double rotation, persistence removal, and full domain recovery.
Prepare
5 steps- Verify Kerberos and replication auditing
Confirm that EID 4768, 4769, 4662 (with DS-Replication GUIDs), and 4624 auditing is enabled on DCs, and that Sysmon and Microsoft Defender for Identity (DfI) alerts are live.
- Pre-plan the krbtgt reset procedure
`New-KrbtgtKeys.ps1` was archived in March 2024; identify Microsoft Defender for Identity recommended actions or an equivalent enterprise tool for current environments; record the ≥10-hour waiting window between two resets and the change ticket requirement in change management.
- Prepare the impact analysis framework
Before the krbtgt reset: document the replication health of all writable DCs, forest trust relationships, and critical service account and scheduled task TGT cache dependencies (~10-hour lifetime, outage risk after reset).
- Define RACI and approval chain
AD owner + CISO/change board signature and a maintenance window are mandatory for krbtgt reset approval; this authority cannot be exercised by SOC L1 or L2 alone.
- Decision gate: is this the right playbook?
Do not proceed to this playbook without evidence of DCSync (EID 4662 replication GUIDs from a non-DC account), NTDS access, DA/DC takeover, Golden Ticket indicator (ghost account, abnormal ticket lifetime, DfI alert), or RBCD write (EID 5136).