Practical Active Directory security resources.

Checklists, references, tools, and technical resources for administrators, consultants, and defenders working to secure Active Directory environments.

Start Here

Core resources

These resources are intended to help with Active Directory assessment, hardening, remediation planning, and defensive operations.

Reference Material

Useful references by topic

Curated reference areas for common Active Directory security topics. These sections can grow over time as new articles and resources are published.

01

Kerberos

Authentication flow, ticket behavior, delegation, roasting attacks, and defensive hardening.

02

NTLM

Legacy authentication risks, relay exposure, audit settings, restrictions, and migration considerations.

03

LDAP

LDAP signing, channel binding, directory queries, authentication behavior, and common hardening steps.

04

PKI / AD CS

Certificate services, certificate templates, enrollment permissions, ESC paths, and mapping controls.

05

Privileged Access

Tier 0, administrative groups, delegation, local admin control, service accounts, and privilege reduction.

06

Group Policy

Password policy, security baselines, local administrator controls, firewall settings, and audit policy.

PowerShell

PowerShell resources

Practical scripts and command examples for auditing Active Directory configuration, security posture, and common misconfigurations.

Find Stale User Accounts

Identify enabled users that have not authenticated within a defined period.

Coming soon

Find Stale Computer Accounts

Review computer objects that have not updated their password or authenticated recently.

Coming soon

Audit Delegation Settings

Identify unconstrained delegation, constrained delegation, and resource-based constrained delegation exposure.

Coming soon

Review Privileged Group Membership

Export and review membership of high-impact Active Directory administrative groups.

Coming soon

Recommended Tool Categories

Tools can help, but understanding the issue comes first.

Active Directory security tools can be useful for assessments, attack path analysis, monitoring, reporting, and remediation planning. Secure Active Directory will cover tools, with a focus on where each tool fits and what problem it is best suited to solve.

Assessment Tools

Tools that help identify misconfigurations, weak controls, and common security findings.

Attack Path Tools

Tools that help visualize privilege relationships and paths attackers may use to gain control.

Monitoring Tools

Tools that help detect suspicious identity activity, authentication abuse, and configuration changes.

Scroll to Top