So far detection in this course lives on hosts and domain controllers: Event IDs, Sigma, Microsoft Defender for Identity. That is the right foundation, but it has two limits — a host can be turned off and logs can be cleared. The network layer sees differently: packets do not care whether the DC log is clean.
Related topics in this course
- Event IDs and Sigma cover DC detection; the network layer backs it up when logs are cleared.
- , and each leave distinct network traces (bursts of requests, replication from an unexpected host, odd hours).
- Defender for Identity complements : identity versus traffic, two independent sources.
What the network layer adds
- / AS-REP Roasting: from the network this is an anomalous profile — many requests (port 88) from one host to many services in a short window. FortiGate/ see the spike and help correlate, but precise detection (the RC4 anomaly) comes from 4769 plus Sigma/MDI. The network gives context, the host gives precision.
- and coercion (PetitPotam, PrinterBug): here the network is the first line — relay lives on SMB/RPC between hosts. FortiGate segmentation limits who a workstation may speak SMB with; catches LSASS dump attempts on the host.
- Credential dumping (mimikatz): is behavioural control — LSASS access from an unsigned process, injections, token creation. It complements rather than replacing it.
- East-west lateral movement: the network's strongest suit. FortiGate knows who ( group) and where (VLAN/segment) and can cut movement with rules like "Tier 2 hosts do not speak SMB/RDP/WinRM to Tier 0/1" — tiering enforced on the firewall.
- Endpoint management: is deployed via synced with (AD groups → FortiClient policies): who gets EDR, who gets VPN — by group membership.
Lab practice
Tier-based segmentation with groups. Create interfaces/VLANs: Workstations, Servers-T1, Infra-T0, then deny SMB/RDP/WinRM from workstations to servers and infrastructure:
Separate rules allow the required ports only from defined admin segments. Deploy via : Administration → Connectors → , a policy for CN=Workstations, and MSI installation through :
If is available, collect FortiGate traffic logs alongside FAC logs and build a " spikes (88/TCP-UDP) per host" report. Next to the 4769 report from the it gives the full picture.
Risks and detection
- The network cannot see inside encryption: is encrypted and FortiGate will not replace 4769 analysis. Do not promise a magic box — promise layers.
- in policy means dependence on : after a compromise the group map lies. Restrict sensitive segments by IP as well.
- is not : EDR reacts to behaviour, Credential Guard architecturally blocks hash reads. Both together is the right answer.
Mitigation
- Default policy between segments is deny; allow rules are surgical.
- Send FortiGate/FAC/ logs to one place (/) with correlation rules against the course Event IDs.
- Test policies regularly: "can the accounting workstation reach the DC over SMB?" — the answer must be deny.