Privilege ladder
An attacker's path from bottom to top: from a regular user to the domain controller. Each step — why it's dangerous and how to spot it.
- 1
Authenticated user
Danger: Can read the whole domain: users, groups, GPOs — a map for attack
Detection: Mass enumeration (BloodHound): 4662, anomalous LDAP
- 2
Local admin
Danger: Steals hashes from memory — a step to the next machine
Detection: 4672, correlated 4624/4634, LSASS access
- 3
Domain Admins
Danger: Full domain control: any user, computer, GPO
Detection: 4728/4732/4756 (group membership), 4672 on DCs
- 4
Enterprise Admins
Danger: Control of the whole forest — every domain
Detection: 4728 in the EA group, site/replication changes
- 5
The DC itself
Danger: Access to NTDS.dit — every password in the domain
Detection: 4662 (replication), shadow copies on DC, odd backups