IC Technology & Cyber — 2026-09-19

CISA and NSA Lead Five-Nation Guidance on Detecting 17 Active Directory Compromise Techniques

BLUFReissuing nearly identical guidance two years later confirms that most enterprises still lack Tier 0 controls on Active Directory infrastructure, leaving domain takeover techniques viable at scale.

CISA and NSA joined the Australian Signals Directorate's Cyber Security Centre, Canada's CCCS, and the UK and New Zealand NCSCs in issuing joint guidance on September 15 detailing the 17 most common techniques used to compromise Active Directory environments 12. The guidance, led by ASD's ACSC, covers attacks spanning Active Directory Domain Services, Certificate Services, and Federation Services, including Kerberoasting, AS-REP Roasting, password spraying, MachineAccountQuota abuse, unconstrained delegation, Group Policy Preferences password exposure, DCSync, NTDS.dit extraction, Golden and Silver Ticket forgery, Golden SAML, Shadow Credentials abuse, SID History and Skeleton Key attacks, one-way domain-trust bypasses, and Entra Connect compromise 34. It recommends treating domain controllers, certificate authorities, AD FS servers, and Entra Connect systems as Tier 0 assets, and advises phishing-resistant MFA, Kerberos armoring, zero-trust policies, and monitoring specific Windows event IDs such as 4768, 4769, 4662, and 5136 to detect compromises 234. The document also endorses deploying canary objects in Active Directory as a detection method that does not depend on correlating event logs 2. The advisory was originally published in September 2024 and updated in January 2025; this release reflects continued attacker focus on Active Directory as a primary enterprise target 2.

Analysis
This five-nation playbook shifts the burden onto enterprise security teams to reclassify domain controllers, certificate authorities, AD FS servers, and Entra Connect as Tier 0 assets and instrument event IDs 4768, 4769, 4662, and 5136 rather than relying on ad hoc hardening. A CISA-hosted document is the single primary source; Industrial Cyber, Cyber Security News, and GBHackers merely republish it without independent reporting. The near-identical reissue of September 2024 guidance indicates the underlying AD CS, AD FS, and Entra Connect misconfigurations persist industry-wide despite two years of prior warning; the timing may instead reflect scheduled maintenance rather than a new intrusion wave. Organizations that skip canary-object deployment stay dependent on log correlation the agencies themselves call difficult even for mature SOCs, leaving a durable blind spot against Golden Ticket, Golden SAML, and DCSync-based domain takeovers.
4 sources
  1. Detecting and Mitigating Active Directory Compromises - CISA
  2. CISA, NSA, global cyber agencies issue guidance to detect and mitigate 17 Active Directory compromise techniques - Industrial Cyber
  3. CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments - Cyber Security News
  4. CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks - GBHackers Security

View in full brief →

UNCLASSIFIED // OPEN SOURCE