Active Directory PowerShell

Get Members of Active Directory Group and Export to CSV using PowerShell

Get Members of Active Directory Group and Export to CSV using PowerShell. The Windows PowerShell AD module is one of the most used modules for managing Active Directory (AD) domains and objects and retrieving data about users and computers. The AD module gathers several cmdlets used to control various objects, obtain AD group members, and […]

Active Directory Cybersecurity

How to Audit Active Directory for CIS / NIST Cyber Security Audit

Active Directory (AD) is the backbone of identity and access in most organizations. It is also one of the biggest targets for attackers. Weak or poorly monitored AD environments often lead to breaches, privilege escalation, and compliance failures. That’s why regular AD auditing is critical for maintaining security, detecting suspicious behavior, and aligning with cyber […]

Active Directory

Complete List of Windows Event IDs for Active Directory

Active Directory monitoring on Windows Domain Controllers involves tracking a wide range of events from the Security log (audit events such as logons and account management) and the Directory Service log (AD DS operational events like replication issues). Below, we provide tables of relevant Windows Event IDs, their provider/source, which Event Log they appear in, […]

Active Directory Cybersecurity

Kerberoasting Attack Detection – Prevention & Mitigation

Kerberoasting is a post-exploitation attack technique targeting the Kerberos authentication protocol in Active Directory. In a Kerberoasting attack, an adversary uses a valid (even low-privilege) domain user account to request service tickets for service accounts – accounts that have a Service Principal Name (SPN) registered. These service tickets (TGS tickets) are encrypted with the service […]

Active Directory Cybersecurity

How to Prevent a Cyber Attack Like Marks & Spencer Hack Guide

In April 2025, British retail giant Marks & Spencer (M&S) was hit by a devastating ransomware attack that disrupted operations, paused online orders, and caused widespread financial damage. Nearly £700 million was wiped from its market valuation, and customers experienced delays, store issues, and service outages. The group behind this attack? A sophisticated hacking gang […]

Active Directory Cybersecurity

Active Directory Security Assessment Checklist (Step by Step)

How to Perform an Active Directory Security Assessment. Active Directory is the backbone of identity and access management in most enterprise environments, making its security paramount. This guide empowers us to conduct a comprehensive security assessment of our AD environment, identifying vulnerabilities and ensuring robust protection. These meticulously crafted steps safeguard our infrastructure and fortify […]

Active Directory Cybersecurity

Emerging Cybersecurity Threats in Active Directory: Security & Mitigation

Emerging Cybersecurity Threats in Active Directory: Security & Mitigation. Compromising Active Directory gives attackers broad access to organization’s systems and sensitive data. Additionally, its deep integration into the IT environment means that weaknesses in Active Directory configurations expose the entire network to risks of lateral movement and privilege escalation, allowing attackers to gain administrative privileges […]