Cybersecurity agencies, including CISA and five international partners, have released detailed guidance on 17 common techniques used by hackers to compromise Microsoft Active Directory environments. The technical guide explains how attackers exploit identity configurations, legacy protocols, certificate services, and privileged systems to escalate access, move laterally, and establish long-term persistence within enterprise networks. Developed by the Australian Signals Directorate’s Australian Cyber Security Center in collaboration with the US Cybersecurity and Infrastructure Security Agency and National Security Agency, the guidance also includes contributions from the Canadian Center for Cyber Security, the UK National Cyber Security Center, and New Zealand’s National Cyber Security Center.
Shadow Credentials facilitate certificate-based authentication without altering the account's password, making unauthorized access more difficult to detect through conventional password monitoring.
Organizations should isolate privileged administration, deploy phishing-resistant multifactor authentication, use secure administrative workstations, minimize delegated permissions, remove unnecessary service principal names, and replace conventional service accounts with group Managed Service Accounts wherever possible. Administrators should enforce Kerberos pre-authentication and AES encryption, set MS-DS-MachineAccountQuota to zero, eliminate unconstrained delegation, remove legacy Group Policy passwords, disable NTLM and SMBv1 where feasible, and protect LSASS. The guidance mentions events like 4768 and 4769 for unusual Kerberos activity, 4662 and 5712 for directory replication, 4741 for unexpected computer-account creation, 4886 and 4887 for certificate requests, and 5136 for suspicious directory-object changes.











