Domain Compromise: DCSync Rights, DA ACE, or GenericAll Chain Response (Critical)
Emergency response steps for a domain-compromise scope when unauthorized replication ACEs are added to the domain object, unauthorized members are added to Domain Admins, or privilege escalation is detected via a GenericAll/WriteDACL chain over DA/Tier-0.
Prepare
5 steps- Audit policy
`Audit Directory Service Changes` and `Audit Directory Service Access` (Success + Failure) are enabled on DCs; Advanced Audit Policy must be fully configured.
- Tier-0 inventory
The list of Domain Admins, Enterprise Admins, Schema Admins, KRBTGT, DC machine accounts, and Tier-0 service accounts must be current and signed.
- Kerberos playbook ready
The KRBTGT double-rotation procedure (≥10-hour wait, auth error KPI monitoring) must be documented and tested.
- DSRM password vault
The DSRM password for every DC must be current; access must be stored in a closed vault accessible only to the authorized IR team.
- Escalation
AD owner + CISO + change board; domain-compromise decisions require a signed change ticket at every step.