CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

CISA, NSA, global cyber agencies issue guidance to detect and mitigate 17 Active Directory compromise techniques

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7463

As cited

Copy frozen at (site build).

identity access

CISA, NSA, global cyber agencies issue guidance to detect and mitigate 17 Active Directory compromise techniques

The Australian Signals Directorate, U.S. Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and cyber agencies from Canada, the United Kingdom, and New Zealand jointly published guidance on detecting and mitigating 17 common Active Directory (AD) compromise techniques. The document describes attack methods including Kerberoasting, AS-REP Roasting, Golden Ticket attacks, Shadow Credentials, and AD FS compromise, along with detection strategies and mitigation measures such as implementing Microsoft's Enterprise Access Model and deploying canary objects. Organizations are advised to comprehensively understand their AD configuration, secure privileged access, and monitor for suspicious authentication patterns that indicate active exploitation.

Why it matters: Enterprise security teams managing Active Directory environments must review this guidance immediately, as AD compromise directly enables attackers to escalate privileges, move laterally across the organization, and achieve complete domain control, making detection and prevention critical to preventing total infrastructure compromise.

VendorsMicrosoftAmazon Web Services
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary