Active Directory Monitoring Detection Compendium by Zoran Savic, Nov 2025
This document defines a complete detection framework for on premise Active Directory monitoring using Elastic Security SIEM. It brings together every relevant detection rule that contributes to identifying compromise, persistence, or misuse within the directory environment. The rules are organized by attack phase and mapped to the MITRE ATT&CK framework to ensure full coverage across discovery, credential access, privilege escalation, persistence, and lateral movement.
The framework contains a curated set of detection rules distributed across these main chapters:
✅ Credential Access and Replication Abuse Detection of DCSync, Kerberoasting, and credential extraction through replication rights or Kerberos manipulation.
✅ Privilege Escalation and Persistence in AD Objects Monitoring of object and policy changes such as AdminSDHolder, GPO abuse, and shadow credentials.
✅ Discovery, Reconnaissance and DNS Abuse Early detection of LDAP queries, computer account manipulation, and DNS poisoning attempts.
✅ Lateral Movement and Relay Attacks Identification of NTLM and Kerberos relay chains and cross platform coercion.
✅Account and Group Management Anomalies Detection of hidden privilege escalation through group membership and access control modifications.
Each chapter explains the purpose of the detection area, provides the exact detection rule description, the MITRE mapping. This enables any SOC to deploy a consistent, production ready set of detections for Active Directory environments.
#windows #defensive
Post #8047
2.07K


- 👍 6
- ❤ 1