Skip to main content
AD Academy
Incident Response
Intermediate16 minLast updated: Topic 1 of 1

IR Process in Active Directory

Stages of responding to a cyber incident in a Domain environment.

Not read

What you will learn here

  • The stages of incident response
  • What to do first after a breach
  • How to bring the domain back to a safe state

Incident Response in follows clear stages. The order matters: acting too early may alert the attacker and destroy evidence.

Process stages

  • Preparation — backups, centralized logs () and a plan prepared in advance.
  • Identification — detecting the incident via anomalous Event IDs and EDR alerts.
  • Containment — isolating infected computers and blocking compromised accounts.
  • Eradication — removing Persistence, resetting passwords and keys.
  • Recovery — restoring services to operation and increased monitoring.
  • Lessons Learned — documentation and tightening defenses.
Architecture and theory — Under the hood

IR (Incident Response) works according to the NIST cycle: Preparation → Detection → Containment → Eradication → Recovery → Lessons Learned. Any skipped step will come back to you in the next phase.

Practical configuration (PowerShell / GUI)
# Rapid Containment of a Suspected Account
Disable-ADAccount -Identity bad_user
Set-ADUser bad_user -Replace @{userAccountControl=514}
# Double password reset of krbtgt (with waiting!) after suspected Golden Ticket
# Collect Volatile Data before shutdown:
#   - Memory (winpmem, Magnet RAM Capture)
#   - Network connections (netstat -anob)
#   - Processes (Get-Process, Sysinternals Autoruns)
powershell
Real-world scenarios in the organization
  • Ransomware: Immediately disconnect from the network, do not shut down. Save a copy of the encrypted file + ransom note.
  • Suspected DC compromise: Assume full domain compromise, plan Reset of krbtgt and DSRM.
Troubleshooting
  • Timeline: Always build a timeline from Event Logs + Sysmon + firewall.
  • IOCs: hash, IP, domain, mutex — share with CERT/ISAC.
  • Chain of Custody: All evidence signed with hash and collector's signature.
Glossary and quick command line
  • IOC — Indicator of Compromise.
  • TTP — Tactics, Techniques, Procedures.
  • MTTR — Mean Time To Respond.
  • DFIR — Digital Forensics & IR.

Check yourself

Why is the krbtgt password reset twice after a breach?

Was this page helpful?