BloodHound / AD Discovery Combined with Credential Theft or Lateral Movement Response
Executes extended response covering triage, evidence acquisition, account isolation, credential rotation, and ACL hardening when credential dump, LSASS access, or lateral movement evidence is found in addition to an AD discovery alarm.
Prepare
4 steps- Telemetry validation
Verify that Sysmon EID 1/3/10/18, EID 4624/4625/4662/4768/4769, LDAP query logging (EID 1644), and named pipe auditing (EID 5145) are being collected; confirm that EDR LSASS access-mask alerts (`0x1010`/`0x1410`/`0x1438`/`0x1FFFFF`) are calibrated for credential dump tools.
- Kerberos Playbook coordination
Pre-define the trigger conditions of the Kerberos Playbook to assess whether the domain-compromise dimension (DCSync, Golden/Silver Ticket, DA takeover) has been reached; be ready to execute it in parallel with this playbook.
- Escalation and RACI
SOC L2/IR → AD administrator (tier-0) → IR lead → CISO; AD owner + IR lead approval and a change ticket are required for destructive actions (bulk account reset, segment isolation); pre-inventory service and scheduled task dependencies that may be affected to assess business continuity impact.
- Honey and ACL inventory
Confirm that honey service accounts and the ACL/delegation inventory are current (see Discovery Playbook Prepare).