CISA and NSA Lead Five-Nation Guidance on Detecting 17 Active Directory Compromise Techniques
CISA and NSA joined the Australian Signals Directorate's Cyber Security Centre, Canada's CCCS, and the UK and New Zealand NCSCs in issuing joint guidance on September 15 detailing the 17 most common techniques used to compromise Active Directory environments
This five-nation playbook shifts the burden onto enterprise security teams to reclassify domain controllers, certificate authorities, AD FS servers, and Entra Connect as Tier 0 assets and instrument event IDs 4768, 4769, 4662, and 5136 rather than relying on ad hoc hardening. A CISA-hosted document is the single primary source; Industrial Cyber, Cyber Security News, and GBHackers merely republish it without independent reporting. The near-identical reissue of September 2024 guidance indicates the underlying AD CS, AD FS, and Entra Connect misconfigurations persist industry-wide despite two years of prior warning; the timing may instead reflect scheduled maintenance rather than a new intrusion wave. Organizations that skip canary-object deployment stay dependent on log correlation the agencies themselves call difficult even for mature SOCs, leaving a durable blind spot against Golden Ticket, Golden SAML, and DCSync-based domain takeovers.
4 sources
- Detecting and Mitigating Active Directory Compromises -
CISA - CISA, NSA, global cyber agencies issue guidance to detect and mitigate 17 Active Directory compromise techniques -
Industrial Cyber - CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments -
Cyber Security News - CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks -
GBHackers Security